Join our Newsletter — 33% off our NHI Course

ITSM tools and access requests: where governance breaks down

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: ITSM tools can route tickets and automate service workflows, but they still do not understand access scope, license fit, policy conflicts, or expiry, so organisations end up approving requests without real governance according to Zluri. That gap matters because access management is a control problem, not a ticketing problem.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 14 IT Service Management Tools (ITSM Tools) in 2026”.

Key questions

Q: How should security teams handle access requests when ITSM tools are already in place?

A: Use ITSM as the intake and routing layer, but move entitlement decisions into a policy-controlled access governance process.

Q: Why do access requests in ITSM create over-permissioning risk?

A: Because a ticket workflow treats each request as a separate event, while real identity risk accumulates across many requests and systems.

Q: What breaks when access requests are handled like ordinary support tickets?

A: What breaks is accountability.

Practitioner guidance

  • Separate request handling from entitlement decisioning Keep ITSM responsible for intake, routing, and audit trail, but require a governed access layer to decide what entitlement is issued, at what scope, and for how long.
  • Map requests to specific roles and license tiers Replace generic application approvals with policy rules that assign the exact role, license level, and permission scope tied to the requester’s function.
  • Add expiry to every non-permanent entitlement Make project, contractor, and exception-based access expire automatically so request closure does not become a substitute for revocation.

Bottom line: ITSM tools can handle request routing, but they do not decide whether a specific entitlement is appropriate or policy-compliant.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

ITSM ticketing is not an access control model. The article describes a common governance error: assuming that a managed request queue is the same thing as a managed entitlement decision. That assumption fails because ticket workflows do not evaluate licence scope, policy conflict, or segregation of duties. The implication is that identity teams must treat access approval as a control problem, not a service desk process.

A few things that frame the scale:

  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
  • That same survey found that 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.

A question worth separating out:

Q: What is the difference between ITSM for requests and identity governance for access?

A: ITSM manages the service process, while identity governance decides whether, how much, and for how long access should exist. A ticket can confirm that someone asked for access, but it does not prove that the entitlement was appropriate. Governance is the control layer that closes that gap.

👉 Read our full editorial: ITSM tools do not solve access governance in 2026



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

ITSM-based access approval creates a governance illusion: the process looks controlled because every request has a ticket, but the entitlement itself is still being decided without access intelligence. That separation matters because governance is about the quality of the access decision, not the existence of workflow metadata. The practitioner conclusion is simple: ticketing evidence is not entitlement evidence.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations use ITSM or IGA for access governance?

A: Use both, but for different jobs. ITSM should route and record the request, while IGA should determine whether the entitlement should exist, what level it should have, and when it should expire or be removed.

👉 Read our full editorial: ITSM tools do not solve access governance in 2026


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.