Join our Newsletter — 33% off our NHI Course

Cloud management platforms and identity governance: what’s missing?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Cloud management platforms centralize orchestration, cost, monitoring, and security controls across hybrid environments, but the source article shows that identity, governance, and compliance remain only one part of the stack according to Zluri. The practical issue is that cloud control planes can simplify operations without solving who or what should hold access, how that access is reviewed, or when it should be revoked.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “14 Best Cloud Management Platforms in 2026”.

Key questions

Q: What breaks when cloud identities are not centrally governed?

A: Shadow accounts, orphaned credentials and inconsistent role definitions emerge because no single process can see the whole access picture.

Q: Why do cloud management platforms still leave access risk in place?

A: Because automation changes how quickly access is created, but not who is accountable for it.

Q: How can security teams know if cloud identity governance is actually working?

A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review.

Practitioner guidance

  • Define the governance boundary for CMPs Document which access decisions belong to the cloud management platform and which must remain in IAM or IGA, especially for provisioning, approvals, and revocation.
  • Tie cloud provisioning to lifecycle ownership Require every automated resource or entitlement flow to map to an owner, a business purpose, and a revocation trigger so access does not outlive the work.
  • Separate audit evidence from governance Use CMP logs and compliance reports as evidence sources, but keep access review, exception handling, and offboarding in a governance process that can certify entitlements.

Bottom line: Cloud management platforms help consolidate cloud operations, but they do not by themselves resolve who should hold access or when that access should end.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Cloud management platforms create a control plane, not an identity authority. The article shows how these platforms concentrate monitoring, orchestration, and security operations, but that concentration should not be mistaken for governance maturity. Identity decisions still need a separate source of truth for ownership, review, and revocation. The practitioner lesson is to distinguish operational centralization from access governance.

A few things that frame the scale:

A question worth separating out:

Q: How should organisations divide responsibility between CMPs and IGA?

A: CMPs should handle operational orchestration and evidence collection, while IGA should own identity policy, access certification, and lifecycle decisions. That split avoids overloading the cloud platform with governance responsibilities it was not designed to carry. It also keeps human, NHI, and workload access under one governance model even when the cloud estate is distributed.

👉 Read our full editorial: Cloud management platforms still leave identity governance fragmented


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.