Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Continuous identity governance: are access reviews still enough?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Traditional IGA metrics still assume access is corrected at checkpoints, but modern identity states change continuously across people, projects, contracts, risk signals, and non-human identities, according to Fischer Identity. That makes delayed certification a control gap, not a governance model, because stale access can remain active long before review begins.

NHIMG editorial — based on content published by Fischer Identity: Continuous Identity Governance Is Not the Future. It Is the Standard

By the numbers:

Questions worth separating out

Q: How should organisations govern access when business conditions change continuously?

A: They should shift from periodic attestation to event-driven policy evaluation.

Q: Why do periodic access reviews fail as the main governance control?

A: Because they assume access can remain in place until the next review without creating meaningful risk.

Q: What breaks when device lifecycle management is not tied to identity governance?

A: When device lifecycle management is isolated from identity governance, organisations lose the ability to prove who used the device, what access it carried, and whether retirement actually removed trust.

Practitioner guidance

  • Map access to authoritative business events Identify which source events should trigger recalculation of access, including job changes, contract end dates, project closure, sponsorship lapse, and risk signals.
  • Measure governance lag end to end Break the control loop into source ingestion, identity correlation, policy evaluation, provisioning, target reconciliation, and evidence confirmation.
  • Separate certification from lifecycle enforcement Use access reviews to validate ownership, exceptions, and policy fit, but do not rely on them to discover routine changes that should already have been enforced.

What's in the full article

Fischer Identity's full article covers the operational detail this post intentionally leaves for the source:

  • The source article walks through the continuous control-loop model from authoritative event to reconciliation.
  • It explains how policy-driven lifecycle management differs from campaign-centric certification in day-to-day operation.
  • It outlines how organisations can classify access as birthright, exception, dynamic, or orphaned in practical governance terms.
  • It gives a programme-level view of how continuous governance applies to people, contractors, and non-human identities.

👉 Read Fischer Identity's analysis of continuous identity governance and lifecycle control →

Continuous identity governance: are access reviews still enough?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Checkpoint-oriented IGA is a lagging control, not a governance model. The article correctly exposes the assumption that access can be granted once and safely revisited later. That assumption was designed for slower identity change and batch-oriented systems, not for continuous business events. The implication is that governance programmes must stop treating certification as the primary control for access correctness.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which helps explain why lifecycle drift persists even when governance teams believe controls are working.

A question worth separating out:

Q: How should teams use certification if continuous governance is already in place?

A: Use certification to validate policy ownership, confirm exceptions, and provide human judgment where rules are incomplete. Do not use it as the engine for routine lifecycle change. If the platform is healthy, certification should explain exceptions, not discover every basic access change.

👉 Read our full editorial: Continuous identity governance is the new IGA standard



   
ReplyQuote
Share: