By NHI Mgmt Group Editorial TeamDomain: Best PracticesSource: SemgrepPublished July 31, 2026

TL;DR: Security champion programmes should be judged on engagement, issue reporting, bug reduction, and team impact rather than vanity clicks, according to Semgrep, because those signals show whether the programme changes behaviour and improves outcomes. The practical lesson for identity teams is that useful metrics must prove governance value, not just activity.


At a glance

What this is: This is a metrics-focused article on how to measure a security champion programme, with the key finding that clicks and other vanity metrics can hide whether the programme is actually improving security outcomes.

Why it matters: It matters to IAM practitioners because identity programmes also need outcome-based measures, not just participation counts, if they want to prove value, secure funding, and understand whether governance controls are changing behaviour.

By the numbers:

👉 Read Semgrep's article on security champion metrics that matter


Context

Security champion programmes fail when teams count activity instead of impact. A programme can generate traffic, attendance, and chatter while leaving bug classes unresolved and developer behaviour unchanged. In identity governance terms, the same mistake appears when teams report access review completion rates or policy acknowledgements without showing whether access sprawl, stale entitlements, or secret exposure are actually falling.

The article is useful because it separates vanity metrics from operational ones. That distinction matters for NHI, IAM, and lifecycle governance: if the measure does not reflect reduced risk, better reporting, or earlier detection, it is not telling you whether the programme is working. Outcome-based measurement is what turns a champion effort into a governance control.

For identity teams, the lesson is broader than security champions. The same discipline should be applied to privileged access reviews, service account ownership, and AI agent oversight: measure what changed, not just what was done. That is the difference between administrative motion and real control.


Key questions

Q: How do security and data teams know whether governance controls are actually working?

A: They should test whether metadata changes, ownership updates and discovery signals are reflected consistently across both the governance platform and the cloud environment. If current state cannot be reconstructed from both sources, the control is not functioning as intended.

Q: Why are engagement metrics often misleading in security programmes?

A: Because engagement only proves that people showed up, clicked, or attended. It does not prove that defects were fixed, access was reduced, or secrets were protected. A useful metric must connect activity to a control result, otherwise leadership can mistake motion for security improvement.

Q: What metrics should identity teams track beyond completion rates?

A: Track issue recurrence, entitlement reduction, stale account cleanup, ownership coverage, and time to remediation. Those measures show whether access governance is getting better, not just whether a review happened. In NHI and IAM work, the quality of the outcome matters more than the count of completed tasks.

Q: How do organisations avoid vanity metrics in access governance?

A: Start with the security outcome you want, then choose metrics that prove whether the control changed reality. For example, measure revoked access, reduced exceptions, and repeated finding rates instead of only counting reviews completed. That approach gives leadership evidence they can use and tells the team where the programme still fails.


Technical breakdown

Vanity metrics versus outcome metrics in security programmes

Vanity metrics measure volume, not value. A large number of clicks, attendees, or completed reviews can still leave the underlying risk untouched if the programme does not change behaviour, reduce defects, or shorten remediation time. Outcome metrics tie activity to a control objective, such as fewer repeated bugs, faster issue closure, better reporting quality, or reduced exception volume. In identity governance, that means measuring whether reviews, ownership, rotation, and offboarding actually improve the state of entitlements and secrets rather than simply producing completed forms.

Practical implication: define programme success by control effect, not by participation counts.

Feedback loops that show whether behaviour changed

The strongest programme metrics create a feedback loop. They tell you whether people surfaced issues earlier, whether the same bug class reappeared, and whether the intervention changed how teams work. That is why issue-reporting volume alone is weak, but reporting coupled with fix rate, recurrence rate, and time to resolution is useful. For NHI and IAM programmes, the same logic applies to access reviews and secret management: the signal is not that the review happened, but that risky access disappeared and stayed gone.

Practical implication: track before-and-after control behaviour, not just the number of control events.

Why identity programmes need evidence of reduced risk

Identity programmes often overcount governance activity because it is easy to measure. Yet useful security measurement should answer whether privilege is tighter, secrets are better controlled, and review processes are surfacing the right problems. NIST Cybersecurity Framework 2.0 aligns well here because it emphasises govern, identify, protect, detect, respond, and recover outcomes rather than isolated tasks. That framing helps teams separate reporting that satisfies management from reporting that proves risk reduction.

Practical implication: align identity reporting to measurable risk outcomes and NIST CSF 2.0 functions.


NHI Mgmt Group analysis

Security measurement fails when teams confuse visibility with control. This article makes the classic point that activity is not proof of effectiveness. In identity programmes, the same mistake appears when teams celebrate review completion or audit closure without checking whether privilege sprawl, stale access, or secret exposure actually improved. The practitioner conclusion is simple: if the metric cannot show change in the control state, it should not drive decisions.

Outcome metrics are the only credible way to justify programme investment. Champion programmes, like NHI and IAM governance programmes, need evidence that they reduce noise, surface real issues, and improve remediation speed. Reporting on engagement alone does not support resource requests. What matters is whether the programme changes the work system, because that is what leadership funds and auditors ultimately care about.

Access review completion is a weak proxy for governance health. A completed review tells you an administrative step happened, not that access was correct. That matters for human IAM, but it is even more pronounced for NHI governance where service accounts, tokens, and API keys can remain operational long after the original owner has moved on. The practitioner conclusion is to measure entitlement removal, exception closure, and ownership integrity instead of ceremony.

Champion programmes should be measured like identity controls, not marketing campaigns. The useful questions are whether defects fell, whether reporting improved, and whether the same problem recurred after intervention. This article is a reminder that identity teams should treat metrics as evidence of risk movement, not as proof that people were merely busy. The practitioner conclusion is to report control effect, not programme theatre.

From our research:

What this signals

The programme lesson for identity teams is that metrics must prove change in the control state, not just record participation. When governance reporting focuses on completions alone, teams can miss stale access, repeated exceptions, and weak ownership until those problems become operational debt.

Governance signal debt: a metric set that looks healthy while the underlying identity risk remains unchanged. For NHI, IAM, and lifecycle programmes, that means reporting must show whether access, secrets, and ownership actually improved, not just whether the workflow closed.

If your identity programme cannot demonstrate reduced recurrence or faster correction, it is not yet a governance signal. It is administration with a dashboard.


For practitioners

  • Replace activity counts with control-effect metrics Track whether the programme reduced repeated findings, shortened remediation time, and lowered exception volume. Use the same logic for access reviews, secret rotation, and ownership cleanup so leaders can see whether governance changed outcomes.
  • Measure recurrence, not just participation Count how often the same issue reappears after a champion intervention or identity review. If the same access or secret problem returns, the control is not sticking and the metric should show that.
  • Tie reports to a specific risk class Choose one bug or identity risk class and monitor how often it is found, fixed, and reintroduced. That gives you a defensible story for budget, resourcing, and prioritisation.
  • Use governance metrics that leadership can act on Report issue closure rates, stale entitlement reduction, and ownership coverage alongside engagement data. Those signals support resource requests because they show whether the programme is changing the control environment.

Key takeaways

  • The article shows that security programmes should be judged on outcomes, not on vanity metrics that merely prove activity.
  • For identity teams, the equivalent test is whether reviews, rotation, and ownership cleanup actually reduce risk or just generate reports.
  • The most credible metrics are the ones leadership can use to see fewer repeated issues, faster remediation, and better control state.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01The article is about measuring governance outcomes, not activity alone.
OWASP Non-Human Identity Top 10NHI-08The post's identity angle is strongest where metrics reveal weak lifecycle and governance control.

Use identity metrics that show whether stale access, ownership gaps, and uncontrolled secrets are shrinking.


Key terms

  • Vanity Metric: A vanity metric is a number that looks good but does not prove that a control, programme, or process improved security. In identity governance, it often measures activity such as attendance or completion rather than whether access, secrets, or ownership actually changed.
  • Outcome Metric: An outcome metric measures whether a security or identity programme changed the real-world state it was meant to influence. For NHI and IAM work, that means reduced exceptions, fewer repeated findings, faster remediation, or lower exposure, not just more completed tasks.
  • Security Champions Programme: A security champions programme is a model for embedding security advocates inside business or engineering teams. Champions are not replacements for the security team. They help translate guidance, surface issues early, and improve adoption by using trust and context that central security groups often lack.
  • Control Effectiveness: The degree to which a control actually works in real operating conditions, not just on paper. Auditors assess whether the control is designed well, executed consistently, and supported by evidence that shows it reduced the intended risk.

What's in the full article

Semgrep's full article covers the practical metric ideas this post intentionally leaves at a higher level:

  • Examples of security champion KPIs that map to real engineering outcomes rather than traffic.
  • Ways to use bug tracker data to show whether a specific bug class is actually declining.
  • The distinction between useful reporting for management and misleading vanity metrics.
  • Story-based reporting techniques that help translate programme impact for leadership.

👉 Semgrep's full post includes practical examples for separating useful programme signals from vanity measures.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org