TL;DR: IAM programmes are still buckling under approval fatigue, privilege creep, and fragmented governance, while policy-based access control and just-in-time access offer two complementary ways to reduce standing privilege and improve auditability, according to Cerbos. The deeper issue is that access decisions must remain deterministic and explainable, even as AI is used around them, not inside them.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “Automating IAM for compliance, security, and business agility”.
Key questions
Q: What breaks when IAM still depends on approval queues for every access request?
A: Approval queues turn IAM into a throughput problem, so teams start rubber-stamping access, privilege creep accelerates, and audit evidence becomes weak.
Q: Why do standing privileges create more risk than temporary elevated access?
A: Standing privileges leave high-risk permissions available even when no task is underway, which expands the window for misuse, compromise, and accidental damage.
Q: How do you know whether policy-based access control is working?
A: Policy-based access control is working when access outcomes are consistent across platforms, policy changes are traceable, and exceptions are rare enough to review manually.
Practitioner guidance
- Prioritise JIT for standing privilege paths Target admin access, break-glass use cases, and other high-risk roles where continuous access is the main exposure.
- Externalise authorization for high-value applications Move core access rules out of application code and into a versioned policy layer when you need consistent decisions across APIs, services, and queues.
- Feed context into policy decisions Connect directory, device posture, HR, and application signals so policies can evaluate role, device state, time, and business context at request time.
Bottom line: Approval-heavy IAM creates friction, weakens governance, and encourages over-permissioning when teams cannot evaluate every request in context.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Approval fatigue is now a governance failure, not a workflow inconvenience. When security teams normalize rubber-stamped requests, they turn IAM into a queue-management exercise instead of a control system. The article captures the practical result: privilege creep, unaudited SaaS access, and users seeking shortcuts around friction. The discipline shift is from asking who can approve faster to asking which access should exist at all.
A question worth separating out:
Q: What is the difference between just-in-time access and role-based access control?
A: Role-based access control assigns permissions in advance based on a role, while just-in-time access grants elevated permissions only for a specific task and a limited time. RBAC is useful for baseline access. JIT is better for high-risk privilege because it reduces the duration and scope of exposure.
👉 Read our full editorial: Beyond approvals: policy-based IAM and JIT for compliance