TL;DR: IT change management software is being used to coordinate approvals, requests, and workflow visibility during organisational change, but its identity value comes from how it governs access transitions rather than how it tracks tickets, according to Zluri. The key issue is that change tooling often speeds execution without proving that access, role changes, and offboarding controls are actually aligned.
At a glance
What this is: This article argues that IT change management software helps coordinate operational change, but it does not by itself close the identity governance gap around access transitions, role changes, and offboarding.
Why it matters: IAM and lifecycle teams should treat change tooling as an orchestration layer, not proof that entitlements, approvals, and revocation are aligned across human and non-human identities.
Context
IT change management software is designed to coordinate requests, approvals, workflows, and visibility when an organisation changes systems, processes, or access requirements. In identity terms, the real test is whether those changes also keep access aligned with role moves, app requests, and leaver actions.
The article uses a promotion and application access scenario to show why change execution can be faster than identity governance. That distinction matters because process visibility is not the same as entitlement control, and speed does not confirm that access has been approved, granted, and later removed correctly.
Key questions
Q: How do IT teams stop change tickets from becoming access governance gaps?
A: Treat the ticket as a record of motion, not proof of control. Each access-related change should resolve to a verified entitlement outcome, including who approved it, what access was granted, and whether the permission was later removed when the business need ended.
Q: Why do change management workflows still leave identity risk behind?
A: Because routing requests faster does not guarantee that entitlements, roles, and offboarding actions changed in sync. The risk appears when operational status is updated in one system while access persists in another, creating entitlement drift and unclear accountability.
Q: What are the warning signs that change management is not governing access properly?
A: Look for duplicate approvals, app requests that bypass lifecycle records, closed tickets with unchanged permissions, and high-risk applications visible in self-service portals without strict policy filters. Those symptoms show that the workflow is active but identity governance is not.
Q: Should organisations use IT change management software for access control decisions?
A: Only as part of a governed identity process, not as the decision engine itself. Change tools can coordinate requests and visibility, but access decisions should remain tied to identity lifecycle rules, role definitions, and revocation controls.
Technical breakdown
Change workflows do not equal entitlement governance
IT change management tools centralise requests, approvals, and notifications, which helps teams coordinate operational work. But entitlement governance requires more than ticket movement: it needs a clear link between the change event, the identity subject, the target application, and the eventual access outcome. Without that linkage, a workflow can close while the identity state remains ambiguous. The article's example of a promotion and app request shows the difference between processing a change and proving that access has been authorised and applied correctly.
Practical implication: verify that every access-related change produces an auditable entitlement outcome, not only a closed ticket.
Midlife access changes need lifecycle controls, not just service desk routing
The article's midlife change example is really a joiner-mover-leaver problem in disguise. A promotion, department change, or new app request is a lifecycle event that should update identity records, app access, and approval logic together. If IT change management software only routes requests and not identity state, organisations can end up with delays, duplicate approvals, or stale permissions. This is where access governance and lifecycle management become the control layer underneath the workflow layer.
Practical implication: connect change requests to lifecycle records so role changes trigger entitlement review and revocation where needed.
Centralised visibility is useful, but it does not prove least privilege
The article emphasises dashboards, notifications, and centralised request handling. Those are useful operational controls, but they do not automatically establish least privilege, policy alignment, or clean offboarding. Identity governance depends on knowing who should have access, why they have it, and when it should expire. A central queue can improve throughput without reducing entitlement sprawl if app access decisions are not tied to role, risk, and lifecycle status.
Practical implication: measure whether centralised change handling is reducing entitlement drift across the application estate.
NHI Mgmt Group analysis
IT change management software exposes a governance gap when teams confuse workflow control with identity control. The article shows how organisations can automate requests and approvals while still leaving the access model unresolved. That is a familiar failure mode in IAM programmes: the ticket closes, but the entitlement story does not. Practitioners should treat change tooling as a coordination layer, not as evidence of governed access.
Access transitions are the real control point, not the change ticket itself. Promotion, app request, and department move scenarios all depend on the same underlying question: did the identity state change in lockstep with the business event? If the answer is no, then the organisation has process visibility without lifecycle assurance. That is why identity governance must sit downstream of workflow automation.
Change management becomes an identity problem when it starts approving software access. At that point, the discipline crosses from service management into entitlement governance, and the operating model has to reflect that. The useful lens is not whether the platform can move requests faster, but whether it can preserve policy consistency across joiner, mover, and leaver events. Practitioners should separate operational routing from access authority.
Entitlement drift is the named concept that best captures this article's risk. Changes move through the organisation, but access often lags behind, accumulates, or remains after the original need has passed. That is especially problematic when app requests, procurement, and HR events are handled in different systems. The implication is straightforward: identity governance must verify the access result of change, not just the administrative motion around it.
What this signals
Entitlement drift: change tooling can accelerate the administrative path, but identity programmes still need a separate control that proves access changed in line with the business event. That distinction matters most when promotions, app onboarding, and leaver actions move through different systems.
Lifecycle governance is the missing layer in many IT change programmes. When a platform can route requests but cannot confirm the resulting identity state, teams should expect inconsistencies between the approved change and the permissions that remain in the application estate.
For practitioners
- Map change events to identity outcomes Define which change types must update role assignments, application entitlements, and offboarding status, then validate that each event produces a matching identity record change.
- Separate request routing from access authority Use the change platform to route work, but keep entitlement approval rules, policy checks, and revocation decisions under identity governance controls.
- Test promotion and mover workflows end to end Run sample HR and application-change scenarios to confirm that access is granted only after the right approvals and is removed when the need ends.
- Audit app visibility rules in request portals Check which applications are exposed for self-service requests, who can see them, and whether high-risk apps are excluded from broad request paths.
- Measure entitlement drift after change closure Compare closed change tickets with actual application entitlements to find cases where access remained active beyond the approved business change.
Key takeaways
- The article's core risk is a false sense of governance, where faster change execution is mistaken for controlled access transitions.
- Its main evidence is the repeated focus on promotions, app requests, approvals, and centralised visibility, which are workflow capabilities rather than entitlement proof.
- Practitioners should tie change events to identity lifecycle records so access is verified, revised, or removed as part of the change outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Offboarding gaps are central when change workflows do not remove access after role changes. |
| NHI-05 — Overprivileged NHI | The article's concern is that access can outlive the change that justified it. | |
| NHI-10 — Human Use of NHI | Human-driven requests and approvals still govern machine access outcomes in the scenarios described. | |
| Recommendation — Tie leaver and mover events to NHI offboarding checks so residual access is revoked when the business need ends. Review access grants after change closure and remove any permissions that exceed the new role scope. Use human approval workflows to validate NHI-related requests, but keep entitlement authority separate from request routing. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about whether access decisions stay aligned with organisational change. |
| Recommendation — Apply entitlement controls to confirm permissions remain appropriate after each approved business change. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article highlights account and access changes that must follow business events. |
| Recommendation — Standardise account lifecycle handling so access changes are recorded, approved, and revoked consistently. | ||
Key terms
- Change Management: Change management is the controlled process used to manage role shifts, service changes, and operational updates. In identity governance, it is the trigger point where access should be added, reduced, or removed based on a new business need. If change handling is weak, privilege creep becomes normal.
- Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
- Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.
- Access Authority: The control point that determines who can grant, change, or remove access. In this article's context, request routing and notification are not the same as access authority, which must remain tied to policy, identity state, and approval logic.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org