By NHI Mgmt Group Editorial TeamBased on RSA Security: “Why Traditional IGA Breaks in Modern Environments—And How a More Focused Approach Can Fix It” (May 13, 2026)

TL;DR: Traditional IGA programs fail when they try to govern cloud, SaaS, contractors, and machine access through one large transformation, because static roles and manual reviews age faster than the environment they are meant to control, according to RSA Security. The practical answer is phased governance focused on the highest-risk access first, not a single enterprise-wide redesign.


At a glance

What this is: This article argues that traditional identity governance and administration loses effectiveness in modern environments because static, large-scale programmes cannot keep pace with frequent access change across cloud, SaaS, and mixed identity populations.

Why it matters: It matters because IAM, IGA, and PAM teams need governance models that deliver risk reduction incrementally, not only after years of transformation that may already be out of date.


Context

Traditional identity governance and administration was built for slower environments with stable roles, fewer application changes, and periodic access reviews. That model breaks when organisations must govern cloud, SaaS, contractors, partners, and machine access at the same time.

The governance gap is not a lack of intent. It is a mismatch between programme design and operational tempo, where access changes faster than static roles, manual reviews, and all-at-once transformation programmes can absorb it.

For IAM and IGA teams, the question is no longer whether governance matters, but whether the operating model can produce risk reduction before the environment changes again.


Key questions

Q: What breaks when traditional IGA is forced to cover too much at once?

A: The programme usually breaks at the point where design ambition outruns operational change. Roles age out, access reviews become too large to be meaningful, and the organisation spends time coordinating governance rather than reducing risk. The practical failure is not governance itself, but the attempt to solve every access problem in one transformation.

Q: Why do static IGA models lose value in cloud and SaaS environments?

A: Because the access environment changes faster than the model can be kept current. Cloud services, SaaS adoption, contractor access, and machine identities all create faster entitlement churn than traditional role structures were built to absorb. Once that happens, the model becomes descriptive rather than controlling.

Q: When should organisations prioritise phased IGA over a full redesign?

A: When the estate is changing faster than the governance programme can stabilise. If the organisation already has high-risk access, frequent entitlement change, or limited reviewer context, phased rollout will usually produce control value sooner than a broad redesign. The key is to prove governance on one risk area first.

Q: How do teams know if automated access reviews are actually working?

A: Automated reviews are working when exception rates fall, reviewer overrides become rare, and access decisions are grounded in clean role definitions rather than ad hoc exceptions. If certifications keep surfacing the same noisy entitlements, the problem is usually role design, not reviewer effort. Effective automation should reduce ambiguity, not scale it.


Background and context

Why big-bang IGA programmes stall

Traditional IGA programmes often assume the organisation can define roles, onboard applications, and implement controls in one coordinated transformation. That assumption works poorly when the application estate keeps expanding and business contexts change faster than the governance model can be finalised. The result is a control design that is technically correct on paper but outdated by the time it is delivered. In practice, the longer the programme takes to complete, the more access drift accumulates outside its intended scope.

Practical implication: Break large governance programmes into deliverable scopes tied to specific risk or application clusters.

How static roles and manual reviews lose control value

Static roles are only useful when job patterns and entitlements remain stable. In modern environments, cloud services, SaaS adoption, contractor access, and machine credentials change too often for fixed role models to stay current for long. Manual access reviews also degrade because reviewers lack context, face large decision volumes, and can end up completing the exercise rather than reducing exposure. The technical failure is not review existence, but review fidelity and timeliness.

Practical implication: Prioritise access that changes frequently or carries high business impact, rather than reviewing everything equally.

Why phased governance works better than full redesign

A phased IGA model creates value by governing one use case, one application set, or one risk class first, then expanding from there. That approach shortens feedback loops, produces visible outcomes earlier, and gives governance teams better data on where controls are actually needed. It also reduces the architectural trap of over-designing for a future state that may never stabilise. In modern identity programmes, the control architecture should evolve with the environment instead of waiting for a perfect end state.

Practical implication: Use staged rollout to build governance capability where risk and operational readiness already align.


NHI Mgmt Group analysis

Big-bang IGA is a governance assumption failure, not just a delivery problem. The model assumes the estate will stay stable long enough for design, build, and rollout to finish before risk changes materially. In cloud, SaaS, and mixed human-plus-machine environments, that assumption fails because access patterns shift continuously. The implication is that identity governance must be designed for ongoing adaptation, not one-time completion.

Static role design becomes brittle when the access population is no longer static. Traditional role engineering was optimised for employees in predictable organisational structures. Once contractors, partners, and machines share the same governance surface, role boundaries change more often than annual or quarterly review cycles can absorb. Practitioners should treat role stability as a hypothesis to test, not a premise to trust.

Manual certification at scale often measures completion, not control. Large review campaigns can create activity without creating meaningful risk reduction when reviewers lack context and entitlement sets are too broad. That is why the real governance problem is not review volume alone, but whether the process can surface decisions that are still valid by the time they are made. The practical conclusion is to move from universal review ambition to risk-weighted certification.

Phased governance is the only model that matches modern identity entropy. Identity environments now expand across applications, deployment models, and actor types faster than any single programme can normalise them. A phased approach does not lower ambition; it aligns governance scope to operational reality. The field needs more programmes that prove control value early and then scale from evidence, not from aspiration.

Deployment flexibility is now part of governance resilience. Organisations do not stay cloud-only or on-prem-only forever, and governance models that assume one deployment path can create future lock-in. The practical lesson is that identity governance architecture should preserve continuity across changes in hosting, operating model, and regulatory constraint. Teams should evaluate whether their governance design can move with the business without forcing a restart.

From our research library:

What this signals

Identity governance now needs a control architecture that can shrink scope before it tries to expand coverage. The article reinforces a practical lesson for programmes across human, contractor, and machine access: a smaller governed surface with clear risk ownership is more sustainable than a perfect enterprise model that never finishes. Teams should expect phased delivery to outperform all-at-once transformation when the environment keeps changing.

Governance maturity is increasingly measured by selection, not volume. Modern IGA teams need to show that they can identify which access matters most, move quickly on that subset, and avoid letting low-risk entitlements consume the operating budget. That shifts the programme conversation from universal review coverage to risk-weighted governance decisions.


For practitioners

  • Define one high-risk governance use case Start with a single application, entitlement set, or review problem where exposure is obvious and success can be measured quickly. Avoid designing the full enterprise target state before proving that the operating model works.
  • Prioritise the riskiest access first Rank accounts and entitlements by business impact, privilege level, and change frequency, then govern the top slice before expanding coverage. This prevents low-value review effort from consuming the programme.
  • Replace static role assumptions with living access data Use current access evidence to validate whether roles still reflect how people, contractors, and machines actually work. If a role no longer maps cleanly to reality, treat it as a governance defect rather than a modelling issue.
  • Build phased governance milestones Sequence visibility, governance, and lifecycle capability in stages so each phase produces usable control outcomes before the next begins. That lets teams deliver value without waiting for a full redesign to finish.
  • Keep deployment options open Check whether your identity governance architecture can operate in cloud, on-premises, or hybrid modes without losing control continuity. Flexibility matters when business, regulatory, or hosting priorities change.

Key takeaways

  • Traditional IGA fails when it is treated as a single transformation programme for a moving environment.
  • The core issue is not lack of governance intent, but that static roles and large manual reviews age too slowly for modern access change.
  • Phased governance focused on the riskiest access first creates earlier control value and a more realistic operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe article is about right-sizing governance to changing identity risk.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe post focuses on how access decisions and entitlement control fail at scale.
Recommendation — Align IGA scope to risk management strategy and prioritise control coverage by business impact. Review entitlements based on current access evidence and reduce overly broad permissions first.
CIS Controls v8CIS-5 — Account ManagementThe article centres on governing accounts and access as environments change.
Recommendation — Use account management processes to phase in governance for high-risk identities before broad rollout.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast privilege is undermined when static roles outlive the environment they govern.
Recommendation — Apply least privilege to the most volatile access paths before expanding programme scope.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article explicitly extends governance to machine access and over-assigned entitlements.
Recommendation — Identify overprivileged non-human identities and bring them into phased governance first.

Key terms

  • Big-Bang IGA: A large identity governance programme that attempts to onboard every application, role, and review process in one transformation. In practice, it often lags the environment it is meant to control, so the initial design ages before the programme finishes delivering value.
  • Phased Governance: An incremental approach to identity governance that starts with a limited set of high-risk access problems and expands in steps. This model is better suited to modern environments because it creates control value earlier and avoids betting everything on a single enterprise-wide redesign.
  • Static Role Model: A governance model where access is assigned through fixed roles and entitlements that are assumed to remain stable over time. It is effective only when job patterns and system relationships change slowly, which is increasingly rare in cloud, SaaS, and mixed-identity environments.
  • Access Fidelity: Access fidelity is the degree to which a security tool can reproduce the same protected access path that a real user or attacker would follow. High fidelity means login, session continuity, and authorization context are preserved well enough for findings to reflect the true attack surface.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 2, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org