By NHI Mgmt Group Editorial TeamBased on JumpCloud: “The Three IT Automation Levels to Secure, Simplify, and Scale” (October 16, 2025)

TL;DR: As organisations grow, manual user, device, and access workflows become bottlenecks, while JumpCloud frames a three-stage path from foundational automation to intelligent orchestration and notes that 69% of daily managerial work is forecast to be fully automated. The governance lesson is that scalable IT now depends on identity lifecycle, policy enforcement, and connected systems that reduce human handling of repetitive access tasks.


At a glance

What this is: This is a maturity model for IT automation that argues growth exposes the limits of manual workflows and that identity governance has to move from task automation to connected and orchestrated controls.

Why it matters: It matters because IAM, NHI, and human access programmes all fail when lifecycle and policy decisions stay trapped in emails, spreadsheets, and disconnected systems.


Context

IT automation maturity is the point at which repetitive operational work stops being a human coordination problem and becomes a governed system. In identity programmes, that shift matters because joiner, mover, leaver handling, device setup, and policy enforcement all depend on timely, consistent execution.

JumpCloud's article argues that the real constraint is not whether teams can automate isolated tasks, but whether they can connect identity, device, and access processes into a single operational model. That is the governance gap this piece addresses: scaling access decisions without scaling manual handling.

For IAM leads, the important question is no longer whether to automate, but which controls still rely on humans to move data between systems. Once growth outpaces those handoffs, access quality, consistency, and revocation speed all start to degrade.


Key questions

Q: How should IAM teams automate joiner, mover, and leaver workflows?

A: IAM teams should standardise role-based workflows for provisioning, change management, and revocation, then require audit evidence at each step. The goal is not just speed. It is consistent entitlement state, reduced manual error, and clear proof that access matched the person’s lifecycle stage throughout the change.

Q: Why do configurable HR workflows create risk for identity lifecycle automation?

A: Configurable HR workflows can create risk because IAM tools depend on stable, structured source data to make access decisions. If a job change temporarily removes a role, or a new hire appears before approval is complete, automation can misread the state and either revoke access too early or grant it too soon. That misalignment weakens governance and creates avoidable security gaps.

Q: What are the signs that identity security processes are becoming too manual?

A: Common signs include long onboarding cycles, repeated approval bottlenecks, overprovisioned users, and privileged sessions that nobody has time to review. Another warning sign is when teams skip security checks to keep projects moving. Those symptoms usually mean the process has outgrown manual administration and needs automation, better integration, and policy-driven controls.

Q: How do access policies adapt when device posture or behaviour changes?

A: They use contextual signals to change access decisions at runtime rather than relying only on static role assignment. That can mean tightening permissions when a device falls out of compliance or when behaviour looks unusual, then restoring access when conditions improve. The important part is that policy reacts to conditions, not just to scheduled reviews.


Technical breakdown

Foundational automation for identity lifecycle tasks

Foundational automation targets high-frequency, low-complexity work such as account creation, device setup, and baseline policy application. In identity terms, this is where HRIS-driven provisioning, zero-touch deployment, and automated policy enforcement remove the slowest manual steps from the joiner and mover flow. The key mechanism is not sophistication but repeatability: the same trigger should produce the same access and device outcome every time. That lowers human error and narrows the window between a business event and the corresponding identity action.

Practical implication: automate the lifecycle steps that are still being handled by email, chat, or ticket queues.

Connected IAM and HRIS processes reduce access drift

The second maturity stage is about connecting systems that still work in silos. When IAM and HRIS are linked, a promotion, transfer, or departure can drive access changes without manual reconciliation across downstream applications. This is where identity governance becomes a data consistency problem as much as an access problem: if the source of truth and the enforcement point are disconnected, entitlement drift grows quietly. Connected processes also improve visibility because the same event record can inform provisioning, revocation, and audit evidence.

Practical implication: join identity and HR data flows so changes in employment status automatically update access across connected systems.

Intelligent orchestration makes access decisions context-aware

Intelligent orchestration uses business events, device posture, location, and behavioural signals to trigger coordinated responses. In this model, access is no longer a static grant attached to a user record. It becomes a conditional decision that can change when context changes, which aligns with Zero Trust logic and supports faster containment when risk appears. The architectural difference is important: orchestration ties policy, telemetry, and response together so access can adapt without waiting for a person to notice and intervene.

Practical implication: design access workflows that can change in response to posture or risk signals, not just employment status.


NHI Mgmt Group analysis

Manual identity handling does not scale because it encodes a governance bottleneck, not just an operations problem. When user onboarding, device setup, and policy enforcement depend on individual human actions, the control plane inherits the same latency and inconsistency as the queue. That is why growth exposes governance failure before it exposes technical failure. For identity teams, the lesson is that manual handling is itself a control risk, not simply an efficiency issue.

Single-task automation is only a partial answer unless identity and lifecycle systems are connected. Automating one step without the surrounding joiner, mover, leaver chain leaves revocation gaps, duplicate work, and audit fragmentation in place. The article's core point is that scale comes from continuity between systems, not from automating isolated tickets. Practitioners should treat disconnected automation as an intermediate state, not an end state.

Identity governance at scale increasingly depends on event-driven decisions rather than periodic human review. The moment access, device state, and policy enforcement become reactive to business events, the programme stops relying on people to notice change and starts using system signals to execute change. That is the direction identity operations are taking across human IAM and adjacent machine workflows. Teams should plan for policy that moves with context, not policy that waits for a queue.

Adaptive access control is the named concept this article points toward. Access decisions that shift with device security posture, location, and behaviour turn governance into a dynamic control loop. That does not replace lifecycle discipline, but it changes where the decisive control lives, from manual review to runtime enforcement. The implication for practitioners is that static entitlements cannot remain the primary governance model as automation maturity rises.

The automation maturity curve is now an identity maturity curve. Foundational automation, connected processes, and intelligent orchestration describe a progression that identity leaders should recognise in their own programmes. Each stage changes the balance between human handling and system enforcement, and each stage demands cleaner source data and tighter policy logic. The practical conclusion is that IAM teams should measure maturity by how much access work still requires human relay.

What this signals

Identity teams should read this as a warning that automation maturity is now inseparable from governance maturity. If access, device, and policy workflows remain split across separate tools, the organisation will keep paying the hidden cost of manual reconciliation even when individual tasks are automated.

Adaptive access control: the useful shift is not merely faster provisioning, but policy that can respond to live context such as posture, location, and behavioural signals. That changes access from a static entitlement problem into a runtime governance problem.

For practitioners, the practical target is a shorter distance between business event and identity action. The more systems can share the same event and state data, the less the programme depends on human relay to keep access aligned with reality.


For practitioners

  • Automate joiner and leaver lifecycle steps Sync the identity provider with HRIS so new hires receive baseline access on day one and departures trigger immediate revocation across connected applications.
  • Replace ticket-based device setup Use zero-touch deployment to apply standard settings, software, and security policies without manual IT handling of each device.
  • Connect IAM and HR data flows Map promotion and department transfer events to access changes so entitlement updates happen from a shared source of truth instead of manual reconciliation.
  • Use contextual access decisions Define policies that can respond to device posture, location, and behaviour so access can tighten or expand as conditions change.

Key takeaways

  • Manual IT workflows do not scale cleanly because they turn identity governance into a queue management problem.
  • The article's maturity model shows that connected systems matter as much as individual automations, because lifecycle events only improve governance when they flow end to end.
  • The real payoff comes when access decisions become contextual and event-driven, not when teams simply automate more tickets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about automating access and entitlement decisions as organisations scale.
Recommendation — Automate entitlement changes so access permissions stay aligned to business events and current need.
CIS Controls v8CIS-5 — Account ManagementUser lifecycle automation and revocation are central to the article's governance model.
Recommendation — Centralise account lifecycle handling so provisioning and revocation are consistent across systems.
NIST Zero Trust (SP 800-207)Policy decision and enforcement based on contextThe article's adaptive access section maps directly to context-aware access decisions.
Recommendation — Use contextual policy enforcement so access can change when device posture or risk changes.
NIST SP 800-53 Rev 5AC-2 — Account ManagementThe article focuses on creating, modifying, and removing accounts as part of scaled automation.
Recommendation — Apply account management controls to automate account creation, changes, and removal from source events.

Key terms

  • Identity lifecycle automation: The orchestration of joiner, mover, and leaver events so access is granted, adjusted, and removed without manual gaps. For mixed identity estates, it matters because revocation and review must keep pace with identities that do not follow human employment timelines.
  • Connected processes: Connected processes are integrated workflows where one system's state change automatically informs another system's action. In identity governance, this means HR, IAM, device management, and policy systems share status so access decisions follow the same source of truth.
  • Intelligent Orchestration: Intelligent orchestration is event-driven automation that coordinates multiple systems using live signals, rules, and analytics. In identity and access programmes, it goes beyond task automation by linking business events, policy decisions, and enforcement actions into one controlled workflow.
  • Adaptive Access: A risk-based access model that changes authentication requirements based on context such as device trust, location, behaviour, and session risk. It is most useful where users move between environments quickly, because the policy can stay strict without making every login equally heavy.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org