TL;DR: Adding IT headcount quickly hits diminishing returns, with productivity gains falling from 16.59% in early growth to 3.19% at larger admin teams, while mixed operating-system fleets can drive the Productivity Factor negative, according to JumpCloud’s analysis of product usage data from over 5,000 organisations. The finding reinforces that identity and device complexity now outpace linear staffing, forcing more secure automation and tighter governance.
At a glance
What this is: This is a research-driven analysis of how tool sprawl, mixed device fleets, and dual identity-provider environments flatten IT productivity as organisations scale.
Why it matters: It matters because IAM, NHI, and device governance teams cannot solve growing identity complexity by adding more people; they need tighter controls, automation, and fewer duplicated administration paths.
By the numbers:
- JumpCloud analyzed global product usage data from over 5,000 organisations.
- Each new IT admin brings an efficiency gain of up to 16.59% in early growth stages.
- At Commercial scale, that productivity gain falls to an average of just 7.27%.
- For larger teams of 10 to 20 admins, productivity crashes to a functionally non-existent 3.19%.
Context
Tool sprawl is what happens when too many administration paths, consoles, and identity stores have to be managed in parallel. The article argues that once these environments become mixed and duplicated, the work of keeping access, devices, and policies aligned begins to consume the same capacity that hiring was meant to expand.
For IAM and device governance teams, the core issue is not staffing volume but control fragmentation. Mixed operating-system fleets, split identity providers, and overlapping tooling create more policy surfaces to secure, review, and reconcile than linear headcount can absorb.
The article’s central claim is that scale changes the productivity curve itself. That is why the same operational model that works in a smaller environment becomes a drag in larger ones, especially when identity and endpoint management are handled through disconnected workflows.
Key questions
Q: What breaks when IT environments rely on mixed device fleets and duplicated identity systems?
A: Control coverage becomes inconsistent across operating systems and directories, so teams spend more time reconciling exceptions than improving governance. The result is that adding staff produces less value because each new administrator inherits more fragmentation, not a cleaner operating model.
Q: Why do mixed fleets and dual identity providers reduce productivity as teams scale?
A: Because each additional platform introduces its own policy model, lifecycle path, and troubleshooting burden. When those paths are duplicated across tools, the work expands faster than staffing, so the marginal value of each new hire declines instead of rising.
Q: What are the signs that identity and device governance is becoming fragmented?
A: Look for duplicated policies, repeated exception handling, inconsistent offboarding paths, and growing manual reconciliation between directories and endpoint tools. Those symptoms show that governance is being maintained through effort rather than through a coherent control plane.
Q: What should teams do when tool sprawl starts to absorb admin capacity?
A: Rationalise overlapping tools, remove duplicated administration paths, and automate repetitive lifecycle tasks before adding more headcount. If the environment cannot be governed consistently, extra staff will mostly absorb complexity instead of reducing it.
Technical breakdown
Why mixed fleets change the productivity curve
Mixed Windows, macOS, and Linux fleets do more than add device variety. They multiply the number of policy branches, management workflows, and exception paths that IT has to maintain. Every additional operating system introduces different enrollment logic, patching behaviour, configuration states, and support workflows, so the operational burden rises faster than headcount alone. That is why productivity can turn negative even when staffing increases. The issue is not merely device count. It is the administrative overhead created when a single team has to govern multiple endpoint models with different control surfaces and inconsistent automation coverage.
Practical implication: measure fleet complexity as a governance input, not just a support statistic, and treat OS diversity as an access and management control issue.
How dual identity providers multiply control duplication
Running Microsoft Entra and Google Workspace together creates a duplicated policy layer. IT teams end up re-creating security rules, access logic, and lifecycle actions across separate directories, which increases the chance of drift and inconsistency. In identity terms, this is not just federation complexity. It is a governance duplication problem, because the same identity outcome must be enforced in two places with different policy models and administrative paths. As the number of entry points grows, the risk shifts from isolated misconfiguration to systemic control incoherence. That is what flattens productivity and expands the attack surface at the same time.
Practical implication: map every duplicated identity control to its second implementation path and remove any rule that cannot be governed consistently across directories.
Why headcount stops scaling security operations linearly
The article’s productivity inflection points show that operational capacity does not grow in a straight line with staffing. Early hires may absorb demand efficiently, but beyond a certain point they spend more time reconciling tools than reducing risk. That creates a structural ceiling where new administrators add coordination cost instead of control value. In practice, identity and device teams reach a point where manual work absorbs the margin that should have funded security improvement. This is the same failure mode seen in fragmented IAM programmes: more operators, more systems, and less time for preventive governance.
Practical implication: redesign work around automation and standard control planes before adding more administrators to a fragmented operating model.
Breaches seen in the wild
- Millions of Misconfigured Git Servers Leaking Secrets: Nearly 5 million misconfigured Git servers expose sensitive secrets and credentials online.
- Massive Docker Hub Secrets Leak: 10,000+ Docker Hub container images expose hardcoded secrets and authentication keys.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Tool sprawl is now an identity governance problem, not just an operations problem. Once identity stores, endpoint fleets, and admin consoles multiply, the real issue becomes control duplication. Every duplicated workflow increases drift risk, review burden, and policy inconsistency, which means the governance model itself has to be simplified before scale can be improved.
Mixed device fleets create a hidden productivity tax because control coverage is never uniform. Windows, macOS, and Linux rarely share the same management depth, so teams compensate with exceptions and manual workarounds. That creates a permanently uneven security baseline, and the more uneven the baseline becomes, the more IT capacity gets consumed by reconciliation instead of prevention.
Dual identity-provider environments are a signal that access governance has become fragmented across directories. When Microsoft Entra and Google Workspace coexist, organisations often duplicate rule sets instead of governing one authoritative access model. The result is more places for policy drift, over-entitlement, and delayed offboarding to emerge, which is why directory sprawl often outpaces staffing growth.
Linear hiring cannot absorb compound complexity because identity work does not scale by headcount alone. The productivity curve described in the article is what happens when people are added to manage a broken operating model. The better metric is not how many admins exist, but how much of the environment can be governed through a small number of consistent control planes.
Identity blast radius expands when each additional tool introduces its own access model. That named concept matters because the risk is not merely more administration, but more distinct paths through which entitlements, credentials, and policy exceptions can accumulate. The practitioner conclusion is simple: reduce the number of independent control surfaces before expecting staffing to improve security outcomes.
What this signals
Identity blast radius is the right lens for mixed-fleet governance. Every new tool and directory expands the number of places where policy drift can appear, so the practical question is how many control surfaces a team can still govern consistently. The answer is rarely “all of them” once admin workflows become fragmented.
Organisations that want productivity gains from identity work should focus on control consolidation before headcount expansion. When access, device, and lifecycle work are split across too many systems, automation has to reduce reconciliation effort first or it will never free capacity for higher-value work.
For practitioners
- Standardise on fewer control planes Reduce the number of independent identity and device administration paths so that policy, lifecycle, and access decisions are enforced in one place as much as possible.
- Inventory duplicated identity rules Document every access, enrollment, and lifecycle rule that must be maintained in both Microsoft Entra and Google Workspace, then remove rules that cannot be governed consistently.
- Treat OS diversity as a governance metric Track Windows, macOS, and Linux coverage separately for enrollment, configuration, and remediation because mixed fleet support changes the real cost of control.
- Automate repetitive IT workflows Move routine joiner-mover-leaver, endpoint policy, and access reconciliation tasks into automated workflows before adding more administrators to an already fragmented environment.
- Measure productivity by control coverage Use operational metrics that show how much of the environment is governed through repeatable workflows rather than how many staff are assigned to the team.
Key takeaways
- Tool sprawl and mixed fleets do not just slow operations, they change the economics of identity governance by making every additional admin less productive.
- The article’s data shows a steep drop in marginal productivity as teams scale, which signals that fragmentation is the primary bottleneck.
- The practical response is to consolidate control planes, reduce duplicated identity work, and automate repetitive lifecycle tasks before expanding staff.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Duplicated identity rules and multiple admin paths increase excess access risk. |
| NHI-08 — Environment Isolation | Mixed fleets and split directories create weak separation between operational control domains. | |
| Recommendation — Reduce duplicated entitlement paths and enforce least-privilege administration across identity systems. Separate management domains cleanly so endpoint and identity controls do not drift across environments. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about governing access and administration across fractured identity estates. |
| Recommendation — Consolidate entitlement governance so duplicated identity rules do not diverge across platforms. | ||
| CIS Controls v8 | CIS-5 — Account Management | Scale failures stem from increasingly manual account and admin lifecycle work. |
| Recommendation — Centralise account management and automate lifecycle actions to cut admin overhead as environments grow. | ||
Key terms
- Tool Sprawl: Tool sprawl is the accumulation of overlapping systems that each solve part of the same identity or operations problem. In practice, it creates duplicate workflows, inconsistent policy enforcement, and more manual reconciliation, which weakens confidence in access decisions and slows down secure scaling.
- Mixed Device Fleet: A mixed device fleet includes multiple operating systems managed under one programme, such as Windows, macOS, and Linux. The governance challenge is that each platform can require different controls, exception paths, and remediation steps, which makes consistent identity and posture enforcement harder to maintain.
- Dual Identity-Provider Environment: A dual identity-provider environment is one where two primary directory or access platforms must be governed in parallel, often with duplicated rules and lifecycle actions. It creates policy replication risk because the same entitlement outcome has to be maintained in separate administrative models.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org