Join our Newsletter — 33% off our NHI Course

Identity maturity in 2026: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: C1.ai argues that identity maturity is no longer a destination but an operating model, because access decisions now happen continuously across people, systems, and AI agents. Static roles, manual reviews, and privilege that lingers between tasks no longer scale once identity becomes the control plane for modern work.

Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Identity Maturity in 2026: How the Best Teams Move Forward”.

Key questions

Q: What breaks when identity programmes rely only on periodic governance reviews?

A: Periodic reviews often miss the state of access between certification cycles.

Q: Why do stale accounts create more risk than teams expect?

A: Stale accounts create risk because they preserve a working path into production systems even when nobody is actively monitoring the identity anymore.

Q: How do identity teams measure whether maturity is really improving?

A: Look at operational outcomes rather than tool adoption.

Practitioner guidance

  • Inventory every identity type Build a single inventory that covers employees, vendors, service accounts, and AI agents, then map where each identity can authenticate and receive privilege.
  • Remove stale privilege and unused accounts Clean up zombie accounts, unused permissions, and role sprawl before you rely on automation or automated approvals.
  • Tie approvals to contextual risk Shift access decisions away from hierarchy alone and toward sensitivity, separation of duties, and current risk signals.

Bottom line: Identity maturity fails when teams treat it as a destination and not as a continuously managed operating model.

What's in the full article

C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:

  • The stage-by-stage identity maturity model from zero visibility through autonomous identity
  • The article's success metrics for discovery, hygiene, and just-in-time privilege
  • The discussion of how AI agents change entitlement cadence and governance expectations
  • The narrative examples of teams that start from spreadsheets, audit pressure, or a close call

👉 Read C1.ai's analysis of identity maturity as an operating model in 2026 →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Identity maturity is now an operating model, not a destination. The article correctly frames maturity as continuous progression rather than a final state. That matters because access risk now emerges from drift, stale assumptions, and identity sprawl across people, vendors, service accounts, and AI agents. Programmes that still think in project phases will keep confusing activity with control.

A question worth separating out:

Q: Should organisations prioritise just-in-time access over broad access reviews?

A: Yes, when the objective is to reduce active exposure rather than just document it. Access reviews tell you what exists, but just-in-time access changes how long privilege exists in the first place. For high-risk permissions, reducing standing access usually delivers faster risk reduction than another review cycle.

👉 Read our full editorial: Identity maturity in 2026 is becoming an operating model


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.