Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Every identity is a relationship: what does that change for IAM?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Accounts, roles, and credentials are only the mechanics of identity, while the real governance unit is the relationship that justifies access across employees, contractors, vendors, service accounts, and AI agents, according to Fischer Identity. That shift makes ownership, lifecycle change, and review context central to IAM, not optional metadata.

NHIMG editorial — based on content published by Fischer Identity: Every Identity Is a Relationship

By the numbers:

Questions worth separating out

Q: How should organisations govern identity when one person moves through multiple relationship states?

A: They should govern access from the current relationship state, not from a single static identity label.

Q: Why do accounts alone fail as a governance model?

A: Accounts show that access exists, but they do not explain why it exists, who owns it, or when it should end.

Q: What do security teams get wrong about identity lifecycle management?

A: They often treat lifecycle management as an onboarding task instead of an ongoing access discipline.

Practitioner guidance

  • Define relationship type as a governance field Add relationship type, source of authority, owner, sponsor, start date, and end date to identity records so access can be justified by context rather than by group membership alone.
  • Tie every non-human identity to an accountable owner Require a named owner for service accounts, integrations, and AI agents before access is approved, and block orphaned identities from renewal or exception workflows.
  • Split lifecycle decisions by relationship state Build offboarding and recertification logic so one relationship ending does not over-revoke a second valid relationship, especially for vendors, contractors, and dual-role users.

What's in the full article

Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:

  • Examples of how relationship-aware identity can be modelled across employees, contractors, vendors, students, service accounts, and AI agents
  • A practical list of governance fields to configure, including owner, sponsor, lifecycle state, start and end dates, and deprovisioning actions
  • How continuous identity control differs from point-in-time access administration in complex enterprise environments
  • The article’s own reasoning on why relationship context improves reviews, renewal decisions, and accountability

👉 Read Fischer Identity’s blog post on relationship-aware identity governance →

Every identity is a relationship: what does that change for IAM?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Relationship-aware identity is the right abstraction for modern governance. The article correctly rejects the idea that account, role, or credential data is sufficient to explain access. Identity programmes need the relationship that created the entitlement, because that is what determines who owns it, how long it should last, and what review means in context. For practitioners, that shifts identity governance from record management to lifecycle accountability.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • A separate NHI Mgmt Group finding shows that 97% of NHIs carry excessive privileges, which broadens the attack surface even when identities are partially known.

A question worth separating out:

Q: How can security teams make ownership enforceable in IAM?

A: They should require every identity relationship to have a named owner or sponsor before access is granted, and they should link that owner to review, renewal, and retirement workflows. If ownership is missing, the access should be treated as unresolved governance risk.

👉 Read our full editorial: Relationship-aware identity is the real governance shift



   
ReplyQuote
Share: