Join our Newsletter — 33% off our NHI Course

AI-first identity governance: what IAM teams need to change

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: As AI adoption expands machine identities, orphaned entitlements, and shadow IT, traditional IGA tools built around static HR directories can no longer answer who has access to what, according to Zluri. Static certification and rigid access models are giving way to visibility-led governance that is driven by actual usage rather than assumptions.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Manifesto for a New Era: Identity Governance for an AI-First World”.

By the numbers:

  • Machine identities now outnumber human identities by 20:1 in 2025, according to Zluri.
  • Over 60% of IT resources in a typical organization now exist as either unmanaged or shadow IT, according to Zluri.

Key questions

Q: How should IAM teams evaluate modern IGA platforms?

A: IAM teams should evaluate IGA platforms on governance coverage, evidence quality, and how well they handle different identity types.

Q: Why do legacy access certifications fail in cloud and SaaS environments?

A: They fail because reviewers are asked to approve or revoke access without the context needed to judge business need.

Q: What breaks when identity governance stops at the primary directory?

A: Governance becomes partial because authentication is visible while effective permissions remain hidden inside non-native applications.

Practitioner guidance

  • Build usage-led access reviews Add last-access, frequency, and peer-usage context to recertification so reviewers can decide whether access is still needed.
  • Continuously discover identities and applications Expand inventory controls beyond HR directories to include shadow IT, SaaS sprawl, and machine identities that live outside traditional records.
  • Rebuild role models from activity evidence Use observed usage patterns to refine access roles and reduce inherited entitlements that no longer match how teams actually work.

Bottom line: Legacy IGA is struggling because static identity records cannot explain access in estates dominated by machine identities, AI tools, and shadow IT.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

AI-first governance exposes a visibility debt, not just a tooling gap. The problem is not that legacy IGA lacks features in the abstract. It is that the control model was designed for slower-moving identity estates, while machine identities, shadow IT, and short-lived AI applications now change faster than static governance can absorb. The implication is that governance must be anchored in live identity and application discovery, or it will certify an outdated picture of access.

A few things that frame the scale:

A question worth separating out:

Q: How do teams know whether usage-based governance is actually working?

A: They should look for shrinking dormant access, fewer blanket approvals, and more reviews that end with evidence-based revocation or re-scoping. If certifications still approve most access without examining activity, the governance model has not moved beyond the old assumption-driven pattern.

👉 Read our full editorial: AI-first identity governance exposes the limits of legacy IGA


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.