TL;DR: Identity governance projects often spiral because manual data discovery, harmonisation, access review handling, and maintenance are still embedded in the operating model, according to Oleria Security. As enterprises add SaaS, cloud, and machine identities, the real test is whether governance can work without service-heavy dependency and quarterly guesswork.
At a glance
What this is: The article argues that many IGA deployments fail on operating model friction, not feature gaps, because manual work dominates discovery, reviews, approvals, and ongoing maintenance.
Why it matters: That matters because IAM teams are now governing humans, NHIs, and AI-enabled workflows at the same time, and manual governance scales poorly across all three.
By the numbers:
- Professional services accounted for 69.9% of total IGA market revenue in 2022.
- Professional services accounted for 57% of total IGA market revenue in 2024.
👉 Read Oleria Security's analysis of why identity governance projects spiral
Context
Identity governance breaks down when the operating model depends on manual reconciliation, human approval queues, and repeated connector maintenance. In practice, that means the programme is absorbing the complexity of the environment instead of reducing it, which is why IGA projects often become longer and more expensive than planned.
The article's core point is not that governance is unnecessary. It is that governance tools that require extensive services to work are exposing a structural problem for IAM teams, especially as non-human identities and AI-driven processes increase the number and speed of access decisions.
For teams trying to govern humans and NHIs through the same control plane, the issue is context. If the system cannot automatically discover, normalise, and act on identity data, the review process becomes a compliance ritual rather than a control.
Key questions
Q: How should security teams evaluate IGA tools before buying them?
A: Start with the operating model, not the feature list. Ask how identity data is discovered, how entitlements are normalised, how long implementation takes, and what portion of the programme depends on external services. If the answer requires heavy consulting to work at all, the governance model is not self-sustaining.
Q: Why do identity governance programmes spiral into long, expensive projects?
A: They spiral when manual discovery, schema mapping, review handling, and connector maintenance are treated as normal work rather than implementation debt. That creates a programme that consumes time and people just to stay functional, which is especially problematic when access decisions are increasing across cloud, SaaS, and non-human identities.
Q: What breaks when access reviews are the primary identity control?
A: The control breaks because access can change, be abused, and disappear between review cycles. Review-based governance produces documentation, but not continuous enforcement. In practice, that means investigators can find clean records even when the environment had excessive access at the exact moment the incident occurred.
Q: Who should own governance when IGA depends on heavy services support?
A: The security and identity team still owns the risk, even if a vendor or integrator performs much of the setup. If governance only works while external specialists keep it running, the organisation has outsourced operating complexity, not transferred accountability. Ownership must remain internal even when delivery is shared.
Technical breakdown
Why manual identity data discovery becomes the first bottleneck
Identity governance starts with discovering where identity and access data lives, then modeling it into a usable schema. When that step is manual, every new application, SaaS integration, or cloud service creates more work before the programme can even begin to enforce policy. The result is a control plane that is always behind the estate it is meant to govern. For NHIs, that lag is worse because service accounts, API keys, and tokens are often created outside standard joiner-mover-leaver workflows.
Practical implication: Treat discovery coverage as a control objective and measure how much identity data still depends on manual intake.
Why access reviews fail when context is incomplete
Access reviews depend on reviewers understanding whether access is still necessary, appropriate, and proportionate. If the review engine lacks usage data, ownership context, or clean entitlement mapping, approvers default to rubber-stamped decisions. That is not governance maturity. It is a weak decision surface. The same problem intensifies for NHIs and AI-enabled workflows because the relevant owner may not be a manager in the human sense, and the access may be task-scoped rather than role-scoped.
Practical implication: Do not run access certification until entitlement, usage, and ownership context are available in the review workflow.
How service-heavy IGA models create recurring operational debt
A tool that needs constant professional services to stay functional is not simply expensive. It externalises the work of normalising schemas, maintaining connectors, and patching broken integrations into an ongoing dependency. That dependency becomes part of the security model because governance coverage now relies on a third party's continued effort. For modern identity programmes, especially where NHI volumes keep expanding, this creates an operating constraint that software alone was supposed to remove.
Practical implication: Assess whether recurring services are a temporary implementation aid or a permanent condition of governance.
NHI Mgmt Group analysis
Manual governance debt is now an identity security risk, not an implementation inconvenience. The article shows that many IGA deployments still depend on human stitching across discovery, review, and maintenance. That model may limp along in low-change environments, but it becomes a governance failure when access decisions multiply across SaaS, cloud, and non-human identities. Practitioners should treat manual dependency as a control gap in its own right.
Identity governance built on quarterly review cadences cannot keep pace with machine-speed access creation. The article's argument lands hardest when applied to NHIs and agentic workflows, where accounts and credentials can be created, used, and retired faster than legacy certification cycles can observe. That is a structural mismatch between governance rhythm and identity behaviour. Practitioners need a control model that assumes faster lifecycles, not just better reporting.
Service revenue concentration is a useful proxy for product dependency in IGA decisions. If the vendor's economics depend on keeping customers in implementation and maintenance mode, the buyer inherits a governance model that never truly reaches steady state. That matters for security architects because product architecture and commercial incentives are often linked. Procurement teams should test whether the platform reduces governance work or merely relocates it.
Adaptive identity control is becoming the baseline requirement for mixed human and non-human estates. The article points toward a model where identity data is discovered, harmonised, and acted on continuously rather than patched together after deployment. That direction aligns with the real operational shape of modern IAM, where human access, service accounts, and AI-enabled processes now coexist. Practitioners should re-evaluate whether their current programme can operate without manual reassembly.
From our research:
- Professional services accounted for 69.9% of total IGA market revenue in 2022, according to The 2024 ESG Report: Managing Non-Human Identities.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
- The Ultimate Guide to NHIs frames lifecycle control as a governance discipline, not a deployment task.
What this signals
With 1.5 out of 10 organisations highly confident in securing NHIs, the governance gap is not limited to visibility. It extends into the operational design of identity controls, where manual review cycles and brittle integrations struggle to keep pace with machine identities and the growth of the Ultimate Guide to NHIs.
Governance debt: when identity controls require continuous human intervention to stay functional, the programme is carrying a hidden security liability. That pattern affects human IAM, NHI lifecycle management, and any future agentic control plane that depends on rapid state changes.
Teams should expect procurement scrutiny to shift from feature checklists to implementation physics. The practical question is whether identity governance can operate with durable coverage, or whether every expansion in scope simply adds another layer of manual work and service dependence.
For practitioners
- Quantify three-year IGA dependency cost Model licensing, professional services, integrator fees, internal FTE time, and ongoing maintenance as one operating cost, then compare that against the value of the governance outcomes delivered.
- Test discovery coverage before certification design Map every identity and access source that still requires manual collection, then prioritise the systems that create the largest blind spots for NHIs, SaaS, and cloud entitlements.
- Require usage-aware review context Make access review workflows depend on current entitlement, usage, and ownership data so approvers are not forced to certify access without context.
- Separate temporary implementation help from permanent service dependence Ask whether professional services are a short-term onboarding aid or a structural requirement to keep connectors, schemas, and workflows functioning after go-live.
Key takeaways
- IGA projects spiral when manual discovery, review, and maintenance are treated as normal operating conditions rather than delivery debt.
- The evidence points to a market that still relies heavily on services to make governance software usable, which is a warning sign for security teams.
- Identity programmes now need controls that can scale across human identities, NHIs, and AI-enabled workflows without constant manual reassembly.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity access control is undermined by manual governance and weak context. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management depends on accurate lifecycle governance and timely offboarding. |
| NIST Zero Trust (SP 800-207) | Zero trust depends on continuous verification, not quarterly review rituals. |
Map IGA workflows to PR.AC-1 and verify identity data is complete before certification.
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Identity data harmonisation: Identity data harmonisation is the process of making disparate identity, entitlement, and role schemas usable within one governance model. It is what turns fragmented source systems into a coherent control plane, but it can become a hidden cost center when every integration must be manually normalized.
- Operational dependency: Operational dependency is the condition where a security control only functions because external services, specialist labour, or repeated manual intervention keep it alive. In identity governance, that usually means the tool exists, but the control effect depends on ongoing human effort rather than durable design.
What's in the full article
Oleria Security's full blog covers the operational detail this post intentionally leaves for the source:
- Three-year total cost of ownership questions you can use in vendor evaluation and procurement.
- A fuller breakdown of manual deployment tasks, including data modeling and connector configuration.
- The article's five buyer questions for understanding implementation effort and service dependence.
- The vendor's perspective on adaptive and autonomous identity governance workflows.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org