TL;DR: IT operations management best practices are framed around CMDBs, automation, planning, alignment, tooling, and continuous improvement, with Zluri positioning its SaaS operations platform as an execution layer for onboarding, offboarding, approvals, and usage visibility. For identity teams, the real issue is that operational efficiency claims only matter when lifecycle governance, access revocation, and entitlement control stay intact.
At a glance
What this is: Zluri’s ITOM article frames operations management as a governance problem as much as an efficiency problem, with CMDBs, automation and monitoring only working when access, approvals and offboarding stay controlled.
Why it matters: IAM, IGA and PAM teams should read this as a reminder that operational tooling can speed delivery while still widening access risk if lifecycle controls are not enforced across users, apps and third parties.
Context
IT operations management is the discipline of keeping infrastructure, services, and operational workflows aligned so the business can run reliably. In this article, the identity angle is not the central theme of ITOM, but it is the control layer that determines whether automation, approvals, and service visibility produce better governance or simply faster drift.
The article’s practical message is that ITOM best practices only hold if access decisions, change handling, and asset oversight remain tied to named ownership and repeatable processes. That makes the post relevant to IAM, IGA, PAM, and NHI governance teams even though the source is written from an IT operations perspective.
Key questions
Q: What breaks when access automation is treated as governance?
A: What breaks is control quality. Automation can standardise approvals while still allowing weak policy logic, broad exceptions, and poor visibility into what was granted. A fast workflow is not a secure workflow unless it narrows access scope, preserves ownership, and leaves an auditable decision trail.
Q: Why does a CMDB improve IT operations without automatically improving identity control?
A: A CMDB improves visibility into assets and relationships, but it does not by itself decide who should approve access, when access should be revoked, or which identities are out of scope. Identity control only improves when the CMDB is connected to ownership, lifecycle data, and review workflows that can act on what the inventory shows.
Q: What are the signs that ITOM automation is creating entitlement risk?
A: Common signs include approvals that complete without a named owner, offboarding steps that do not remove all linked app access, and SaaS usage reports that show inactive tools still assigned to users. Those are symptoms that operations and governance are no longer operating from the same record of authority.
Q: How should teams govern SaaS access when ITOM tools handle provisioning and deprovisioning?
A: Teams should define the access policy first, then make the ITOM workflow enforce it consistently across onboarding, approvals, renewals, and offboarding. That means no workflow should create persistent access without an accountable owner, and no offboarding should close until linked SaaS access and service credentials are removed.
Technical breakdown
Why CMDB-driven operations need identity-aware governance
A centralized configuration management database gives IT teams a shared inventory of assets, relationships, and service dependencies. That matters operationally because change, release, and incident workflows are only as reliable as the records behind them. But a CMDB by itself does not govern who can approve access, revoke access, or own a service account. If the inventory omits identity relationships, the organization can know what exists without knowing who or what can act on it. In practice, CMDB value stops at visibility unless it is paired with lifecycle control over the identities attached to those assets.
Practical implication: tie configuration records to ownership, access, and offboarding data so operational change does not outrun identity governance.
How automation changes access control risk in ITOM
Automation reduces manual effort in provisioning, deprovisioning, backups, ticketing, and software deployment, but it also concentrates authority in workflows that execute quickly and repeatedly. The security issue is not automation itself. It is that automated ITOM often handles identity-changing actions such as app approvals, user creation, and access removal at machine speed, which makes weak approval logic or missing revocation paths harder to spot. Where workflows become the control plane, the governance question shifts from who clicks the button to whether the workflow encodes the correct entitlement boundary and offboarding outcome.
Practical implication: review automated onboarding and offboarding flows as governance controls, not just efficiency features.
Why usage visibility matters for entitlement decisions
Real-time software usage visibility helps IT teams decide what to retain, renew, or remove. In identity terms, this is a control against entitlement stagnation, where accounts or app access remain active long after the business need has disappeared. Usage data is useful only when it feeds access review, licence rationalisation, and removal decisions that affect human users and any service identities tied to those tools. Without that loop, visibility becomes reporting rather than governance, and unused access can persist simply because no one translated telemetry into action.
Practical implication: connect usage telemetry to access reviews and deprovisioning so dormant access is actually removed.
Breaches seen in the wild
- New York Times GitHub breach 2024: An exposed GitHub token gave an attacker The New York Times' repositories; the 270GB leak held 4,875 unique secrets.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
ITOM best practice becomes an identity governance problem once operational speed changes access state faster than humans can review it. The article treats automation, approvals, and monitoring as operational efficiency levers, but each of those levers can also move entitlement state. When access is created, approved, or removed inside IT workflows, IAM and IGA controls determine whether the outcome is governed change or unmanaged drift. The practitioner conclusion is that ITOM maturity must be measured partly by how well it preserves access accountability under speed.
CMDB completeness is not the same thing as governance completeness. A configuration record can tell you what assets and services exist, yet still say nothing about who can act on them, which identities are tied to them, or which third parties retain access. That leaves a structural gap between inventory and authority. The practitioner conclusion is that CMDB design should be judged by whether it supports lifecycle decisions, not only by whether it supports service mapping.
Operational automation creates entitlement blast radius when approval logic is treated as workflow design instead of policy design. The article’s onboarding, offboarding, and app-request examples show that ITOM tools increasingly mediate access decisions. That makes workflow design a governance concern, because a fast workflow can distribute access more widely than the business intended. The practitioner conclusion is that automated ITOM should be evaluated through entitlement scope, not just ticket closure speed.
Real-time usage insight creates value only when it drives removal, not just observation. Visibility into SaaS usage, app adoption, and underused software can expose dormant access and unnecessary spend, but the control outcome depends on whether the signal feeds reviews and deprovisioning. This is where identity, operations, and financial discipline converge. The practitioner conclusion is that usage analytics should be wired into access governance, not left as passive reporting.
Identity-aware ITOM is now a prerequisite for third-party and SaaS control, not an add-on. The article explicitly links CMDB value to contracted third-party services and SaaS operations, which is exactly where lifecycle ownership gets blurred in many organisations. As more operational activity is mediated by external platforms and service relationships, offboarding and approval governance must extend beyond the internal user base. The practitioner conclusion is that ITOM and identity teams need a shared control model for external access and service ownership.
What this signals
Identity-aware ITOM: the useful boundary is no longer between service management and access management, but between workflows that move entitlement state and workflows that merely report on it. Teams should assume every provisioning, approval, and offboarding path is an identity control until proven otherwise.
As SaaS and outsourced services absorb more of the operational workload, lifecycle governance has to follow the service, not just the employee. That means app ownership, third-party access, and revocation responsibilities belong in the same operational model as incident response and change control.
For practitioners
- Map ITOM workflows to identity state changes Catalogue where onboarding, offboarding, app approval, and software deployment workflows create, modify, or remove access, then assign an owner for each step and each exception path.
- Bind CMDB records to access ownership Add named owners, approvers, and service-account relationships to configuration records so the inventory can support revocation, recertification, and change approval decisions.
- Treat automation as a policy surface Review automated provisioning and deprovisioning rules for hidden entitlement expansions, missing approval gates, and workflows that can complete without a matching offboarding path.
- Use usage telemetry to trigger removal Connect real-time SaaS usage and adoption data to periodic access reviews so inactive applications, stale entitlements, and unused licences move into removal queues.
- Extend offboarding to third-party services Verify that vendor-managed apps, outsourced services, and other external dependencies have explicit revocation steps in ITOM playbooks rather than relying on informal handoffs.
Key takeaways
- IT operations best practices only remain safe when the processes that speed delivery also preserve ownership, approval integrity, and revocation discipline.
- CMDBs and automation improve visibility and efficiency, but they do not govern access on their own.
- IAM, IGA, and PAM teams should treat ITOM workflows as control surfaces and wire them to lifecycle enforcement.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article repeatedly centres on onboarding and offboarding workflows that can leave access behind. |
| NHI-05 — Overprivileged NHI | Automation and approvals can expand access faster than governance if entitlement scope is not constrained. | |
| Recommendation — Audit offboarding workflows for every SaaS and service credential they should revoke, then close gaps before the workflow exits. Limit automated provisioning rules to the minimum entitlement set required for each role and service path. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | ITOM approvals and lifecycle workflows should enforce least privilege across user and service access. |
| Recommendation — Apply least privilege to ITOM approval and provisioning paths so no workflow grants more access than the task requires. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article’s identity lens is fundamentally about permissions and entitlements inside operational workflows. |
| Recommendation — Review entitlement workflows against PR.AA-05 so access changes remain governed as part of operations. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article’s onboarding, offboarding, and app access examples map directly to account lifecycle management. |
| Recommendation — Use account management controls to keep provisioning, deprovisioning, and review steps aligned with operational change. | ||
Key terms
- Configuration management database: A system of record that stores relationships between assets, services, and dependencies. Its value depends on freshness and integration, because a CMDB that is not continuously updated can mislead teams about ownership, status, and operational impact.
- Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
- Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.
- Identity-Aware Security Operations: Identity-aware security operations connect detection and response to IAM, PAM, and NHI controls. The goal is to treat credentials, sessions, tokens, and privileges as first-class operational objects during incident handling, because they are often the fastest route to containment.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org