TL;DR: Manual access reviews, spreadsheet-driven approvals, and delayed joiner-mover-leaver updates no longer scale across hybrid estates, and the article argues that AI and automation can reduce review cycles, surface anomalies, and keep governance closer to real time, according to SecurEnds. The deeper issue is that governance models built for quarterly checkpoints now collide with continuously changing identities and entitlements, so the control assumption itself is outdated.
Editorial analysis by NHI Mgmt Group, based on content published by SecurEnds: “The Future of Identity Governance: AI and Automation in IGA”.
Key questions
Q: What breaks when governance relies only on quarterly access reviews?
A: Quarterly reviews miss the day-to-day drift that accumulates between certification cycles.
Q: How do organisations know whether AI-driven IGA is actually improving control?
A: They should measure whether access changes are converging faster, whether exceptions are shrinking, and whether review queues are limited to truly risky cases.
Q: What do organisations get wrong about automating identity governance?
A: They often automate the workflow without hardening the policy.
Practitioner guidance
- Define the access state you will govern continuously Identify which applications, roles, and user populations change too quickly for quarterly review to remain credible.
- Replace spreadsheet certifications with risk-prioritised reviews Use automated scoring to push routine approvals through and surface only exceptions that need human judgment.
- Automate deprovisioning for stale and temporary access Tie joiner-mover-leaver events to entitlement removal so departing users, contractors, and short-term project accounts do not linger with unused access after role changes or offboarding.
Bottom line: Manual IGA breaks down when review cycles lag behind identity and entitlement change across hybrid estates.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Quarterly governance is the wrong unit of control for hybrid identity estates. The article describes an access environment where users, vendors, bots, and temporary accounts change faster than review cycles can close. That is not a tooling problem alone, it is a governance timing problem. Identity governance now has to operate against live entitlement drift, not a static attestation calendar.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
A: Start with the highest-volume access workflows, then standardise request forms, approval routing, and lifecycle events for joiners, movers, and leavers. Keep business owners in the approval chain, automate reminders, and track remediation to closure. The goal is to reduce tickets while preserving evidence for every access decision, removal, and exception.
👉 Read our full editorial: AI-driven identity governance exposes the limits of manual IGA