TL;DR: ITSM tools can route tickets and automate service workflows, but they still do not understand access scope, license fit, policy conflicts, or expiry, so organisations end up approving requests without real governance according to Zluri. That gap matters because access management is a control problem, not a ticketing problem.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 14 IT Service Management Tools (ITSM Tools) in 2026”.
Key questions
Q: How should security teams handle access requests when ITSM tools are already in place?
A: Use ITSM as the intake and routing layer, but move entitlement decisions into a policy-controlled access governance process.
Q: Why do access requests in ITSM create over-permissioning risk?
A: Because a ticket workflow treats each request as a separate event, while real identity risk accumulates across many requests and systems.
Q: What breaks when access requests are handled like ordinary support tickets?
A: What breaks is accountability.
Practitioner guidance
- Separate request handling from entitlement decisioning Keep ITSM responsible for intake, routing, and audit trail, but require a governed access layer to decide what entitlement is issued, at what scope, and for how long.
- Map requests to specific roles and license tiers Replace generic application approvals with policy rules that assign the exact role, license level, and permission scope tied to the requester’s function.
- Add expiry to every non-permanent entitlement Make project, contractor, and exception-based access expire automatically so request closure does not become a substitute for revocation.
Bottom line: ITSM tools can handle request routing, but they do not decide whether a specific entitlement is appropriate or policy-compliant.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
ITSM ticketing is not an access control model. The article describes a common governance error: assuming that a managed request queue is the same thing as a managed entitlement decision. That assumption fails because ticket workflows do not evaluate licence scope, policy conflict, or segregation of duties. The implication is that identity teams must treat access approval as a control problem, not a service desk process.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
- That same survey found that 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
A question worth separating out:
Q: What is the difference between ITSM for requests and identity governance for access?
A: ITSM manages the service process, while identity governance decides whether, how much, and for how long access should exist. A ticket can confirm that someone asked for access, but it does not prove that the entitlement was appropriate. Governance is the control layer that closes that gap.
👉 Read our full editorial: ITSM tools do not solve access governance in 2026
ITSM-based access approval creates a governance illusion: the process looks controlled because every request has a ticket, but the entitlement itself is still being decided without access intelligence. That separation matters because governance is about the quality of the access decision, not the existence of workflow metadata. The practitioner conclusion is simple: ticketing evidence is not entitlement evidence.
A few things that frame the scale:
- Gartner predicts that AI systems will initiate 50% of all service requests by 2030, driven largely by agentic AI.
A question worth separating out:
Q: Should organisations use ITSM or IGA for access governance?
A: Use both, but for different jobs. ITSM should route and record the request, while IGA should determine whether the entitlement should exist, what level it should have, and when it should expire or be removed.
👉 Read our full editorial: ITSM tools do not solve access governance in 2026