Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

IAM interoperability and access reviews: what changes for practitioners?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: IAM progress depends on three linked areas: interoperability, quantification, and access reviews, according to Nexis research, with findings on SCIM extensions, 43 IAM metrics, and usability-driven review improvements that make governance more measurable and operationally useful. Access reviews that still assume human-scale decision-making are already misaligned with distributed identity estates and emerging non-human identities.

NHIMG editorial — based on content published by Nexis: IAM From Research to Practice: Advancing Identity and Access Management at Nexis

By the numbers:

Questions worth separating out

Q: How should IAM teams govern access reviews across multiple systems?

A: They should define one accountable review owner, one evidence standard, and one remediation path that applies across every connected directory, SaaS platform, and on-prem system.

Q: Why does interoperability matter so much in modern IAM?

A: Because governance fails when the same identity data means different things in different systems.

Q: What do IAM teams get wrong about metrics?

A: They often measure activity instead of control quality.

Practitioner guidance

  • Map IAM data sources to a shared identity model Inventory directories, access tools, application logs, and review systems, then define one canonical model for identities, entitlements, and review outcomes so systems can exchange consistent meaning instead of just records.
  • Tie IAM metrics to governance decisions Limit reporting to measures that can change prioritisation, remediation, or review outcomes, and review them against security, compliance, and operating goals rather than raw activity counts.
  • Redesign access reviews around reviewer decision quality Use defaults, grouping, and entitlement context to reduce decision fatigue, then cap review scope so reviewers can complete accurate decisions without excessive cognitive load.

What's in the full article

Nexis' full article covers the research detail this post intentionally leaves for the source:

  • The SCIM extension and API design principles behind the interoperability work, including where transaction logs fit as an analytical data source.
  • The 43 IAM metrics mapped to goals and stakeholders, which is useful if you are building a measurement model.
  • The access review experiments around identity grids, choice defaults, and threshold-based detection of low-quality reviews.
  • The real-world case studies that validated the dissertation's design artifacts in practice.

👉 Read Nexis' article on IAM interoperability, metrics, and access review research →

IAM interoperability and access reviews: what changes for practitioners?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

Interoperability is now a governance control, not just an integration problem. IAM programmes that treat system-to-system connectivity as plumbing miss the point. When access data is scattered across directories, logs, and application-specific policy stores, the organisation cannot maintain a consistent identity truth. That affects governance, auditability, and lifecycle accuracy at the same time. Practitioners should treat shared identity semantics as a control objective in its own right.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly remediation can lag behind exposure.

A question worth separating out:

Q: Why do non-human identities complicate IAM governance?

A: Non-human identities complicate IAM governance because they do not behave like people. They authenticate without interactive sessions, persist across deployments, and can be shared or embedded in code. That means the controls that work for users, such as MFA and periodic review cadences, often miss the real NHI risk, which is secret exposure and privilege drift.

👉 Read our full editorial: IAM research shows interoperability, metrics, and reviews need rework



   
ReplyQuote
Share: