By NHI Mgmt Group Editorial TeamBased on SafePaaS: “Identity Governance and Administration Software: Top Capabilities, Benefits, and How to Select the Best Solution” (October 7, 2025)

TL;DR: As organisations scale SaaS, remote work, and contractor access, manual identity governance breaks down and leaves stale access, overprovisioned accounts, and weak auditability exposed, according to SafePaaS. The central issue is not tooling convenience but whether governance can keep pace with changing identities before risk becomes an incident.


At a glance

What this is: This is SafePaaS’s case that policy-based identity governance and administration software now sits at the centre of access control because manual processes cannot keep pace with modern identity change.

Why it matters: IAM and IGA teams need to treat lifecycle automation, certifications, and entitlement governance as core controls, not administrative overhead, because access drift now accumulates faster than manual review cycles can correct it.


Context

Policy-based identity governance and administration software is the control layer that determines who should have access, what they can request, when access should end, and how reviewers prove those decisions. The article argues that manual spreadsheets, email chains, and isolated access lists no longer hold up once SaaS sprawl, contractor growth, and organisational change accelerate identity churn.

The governance gap is not just operational inefficiency. When access changes faster than certification, offboarding, and entitlement review, organisations lose the ability to prove that access remains right-sized, approved, and current. For IAM and IGA practitioners, the problem is that stale access becomes a structural condition, not an occasional exception.


Key questions

Q: What breaks when identity governance relies on spreadsheets and email approvals?

A: Access decisions lose traceability, version control, and reliable ownership. Spreadsheets can document entitlement data, but they cannot enforce review timing, prove revocation, or keep pace with cross-system change. The result is stale access, slow remediation, and weak audit evidence across the identity lifecycle.

Q: Why do policy-based access controls matter when identities change constantly?

A: They matter because access decisions must reflect current identity state, not a snapshot taken during onboarding. When roles, contractors, and applications change continuously, policy-based controls reduce the delay between business change and access correction, which is where most entitlement drift starts.

Q: How do organisations know if access certification is actually working?

A: Look for shrinking numbers of standing privileges, faster revocation after review decisions, and fewer orphaned or overprivileged accounts over time. If campaigns finish but access sprawl remains unchanged, the programme is producing documentation rather than governance. Working certification changes the entitlement baseline, not just the audit record.

Q: What is the difference between role management and entitlement management in IGA?

A: Role management groups access around business function, while entitlement management tracks the actual permissions attached to systems and applications. Roles help simplify access design, but entitlements reveal where conflicting, excessive, or legacy permissions remain. Teams need both, but entitlement governance is usually where risk becomes visible first.


Technical breakdown

Why manual access governance breaks at SaaS scale

Manual access governance depends on people noticing every joiner, mover, leaver, entitlement change, and approval exception. That model fails when identities span employees, contractors, partners, and non-HR-managed profiles across many SaaS and cloud applications. Spreadsheets can record a decision, but they cannot reliably enforce lifecycle state, map entitlements to ownership, or keep certification evidence aligned with the current access posture. Once the number of applications and access paths grows, the control problem is not visibility alone but decision latency. The organisation may know access existed at some point, yet still fail to prove whether it should exist now.

Practical implication: automate lifecycle events and entitlement updates so access decisions are tied to current identity state, not stale records.

How policy-based certification and SoD controls reduce entitlement drift

Policy-based governance works by combining entitlement cataloguing, access certification, and segregation of duties checks into one decision flow. Entitlement catalogues provide the context reviewers need, such as ownership, description, and risk rating, while certification processes force a current approval or revocation decision. SoD rules stop conflicting access from accumulating in the same identity, especially in finance, ERP, and multi-system environments. The deeper value is not simply cleaner reporting. It is that governance becomes executable, so access is continuously assessed against policy rather than periodically checked as a paperwork exercise.

Practical implication: centralise entitlement metadata and policy rules so reviewers can remove risky access without rebuilding context each cycle.

Why contextual access integration matters for modern identity governance

Identity governance increasingly needs to exchange policy context with access enforcement systems. That means role, device, location, and risk signals can influence access decisions at the time of request, not only during later review. In practice, this closes the gap between governance intent and operational enforcement. Without that link, governance can certify access that downstream controls still treat too loosely, or miss changes that should trigger immediate restriction. The article’s core point is that IGA is no longer a back-office record-keeping layer. It is part of the access control path itself.

Practical implication: connect IGA policy decisions to authorization workflows so real-time access reflects governance decisions immediately.


Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Policy-based governance has become the access control layer for modern enterprises. The article is right to move IGA out of the compliance corner and into the control plane for access. When identities change across SaaS, mergers, contractors, and internal moves, the distinction between governance and enforcement narrows fast. Practitioners should treat policy-based IGA as the place where access becomes either defensible or unmanaged.

Manual review is no longer a trustworthy control boundary. Spreadsheets and email approvals can document intent, but they do not maintain state across a live identity estate. That creates a governance delay that exposes orphaned access, toxic entitlement combinations, and stale admin rights. The practitioner conclusion is straightforward: if the review loop cannot keep up with identity churn, it is already behind the risk.

Entitlement context is the missing control multiplier. Certification without ownership, description, and risk context is weak governance dressed up as process. The named concept here is entitlement drift pressure: the longer access lives without enriched context, the more likely reviewers are to approve it by default. The implication for teams is to make entitlement data part of the governance record, not an afterthought.

Closed-loop governance matters more than isolated provisioning. The article correctly links joiner-mover-leaver workflows, access requests, certifications, and analytics into one operating model. That is the only way to keep access aligned with business change rather than episodic review dates. For IAM and IGA leaders, the real decision is whether governance is informing access decisions in real time or merely recording them after the fact.

Policy-based identity governance is now an operating requirement, not a programme enhancement. As environments become more distributed and more identity types fall outside HR systems, the old assumption that access can be managed in batches collapses. The field should stop treating IGA as a reporting layer and start treating it as the system that defines whether access is still justified. Practitioners need governance models that can survive constant identity motion.

From our research library:

What this signals

Entitlement drift pressure: when identities move faster than certification and offboarding cycles, governance stops being periodic oversight and becomes a real-time control problem. Teams should expect more value from shortening approval paths and enriching entitlement context than from simply increasing review frequency.

Policy-based governance is strongest when it sits between lifecycle events and authorization decisions. That is where access can be corrected before stale privileges, orphaned accounts, or toxic combinations become audit findings or incident paths.


For practitioners

  • Map every identity lifecycle path Inventory employees, contractors, vendors, and non-HR-managed identities together, then tie each to onboarding, mover, and leaver triggers so no access path depends on manual follow-up.
  • Enrich entitlements before the next certification cycle Add ownership, business purpose, and risk context to entitlements so reviewers can make revocation decisions without guessing what each permission does.
  • Turn SoD rules into enforceable policy Define conflicting access combinations at the entitlement level, not just the role level, and block approvals that create toxic access pairs across ERP and SaaS systems.
  • Close the loop between governance and authorization Feed approved policy decisions into downstream access enforcement so role, device, and risk changes can alter access without waiting for the next review cycle.
  • Use analytics to prioritise risky access first Focus certification effort on dormant, privileged, and unexplained entitlements so reviewers spend time where access drift is most likely to create audit findings.

Key takeaways

  • Manual governance breaks down when access changes faster than people can review it, which is why spreadsheets and email approvals no longer provide reliable control.
  • The article’s strongest operational message is that entitlement context, certification, and SoD checks must work together if reviewers are expected to make defensible decisions.
  • Identity governance teams should focus on closing the loop between lifecycle events and enforcement so access stays aligned with current business need.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementThe article focuses on managing joiners, movers, leavers, and privileged access at scale.
Recommendation — Centralise account lifecycle governance and revoke stale access as identities change.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPolicy-based governance is about keeping entitlements aligned with current business need.
Recommendation — Define and review access permissions so entitlements stay justified and current.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article’s core control objective is to prevent overprovisioned access and toxic entitlements.
Recommendation — Apply least privilege to reduce excess access and limit entitlement creep.
ISO/IEC 27001:2022A.8.2 — Privileged Access RightsThe article highlights unchecked admin rights and the need to control elevated access.
Recommendation — Govern privileged access rights with policy, review, and revocation discipline.

Key terms

  • Purpose-based Identity Governance: A governance approach that ties each identity to a clear business purpose, defined access scope, and a review or expiry point. It prevents permissions from drifting beyond the work they were created to support, which is essential when non-human identities can persist after a project ends.
  • Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org