Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Continuous identity governance: what changes for IAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Periodic access reviews, nightly feeds, and manual exceptions cannot keep pace with constantly changing roles and entitlements, according to Fischer Identity. The control model now has to recompute identity state, enforce policy outcomes, and preserve audit evidence as conditions change, not after the fact.

NHIMG editorial — based on content published by Fischer Identity: Continuous Identity Isn’t A Buzzword. It’s The Only Way Governance Keeps Up

By the numbers:

Questions worth separating out

Q: How should organisations move from periodic access reviews to continuous identity governance?

A: Start by treating certification campaigns as validation, not detection.

Q: Why do nightly feeds and scheduled reconciliations fail in modern IAM programmes?

A: They fail because they observe change after it has already created risk.

Q: What signals show that an identity programme is continuous rather than just automated?

A: Look for three signals: policy recomputation at the moment of change, direct enforcement that alters access without manual intervention, and audit evidence that explains the decision path.

Practitioner guidance

  • Rebuild governance around lifecycle-triggered recalculation Map mover, leaver, affiliation, and source-record correction events to automatic entitlement recomputation instead of waiting for the next access review cycle.
  • Separate streaming from continuous enforcement Test whether your platform only ingests identity changes or actually changes access, workflow outcomes, and exceptions when policy state changes.
  • Make audit evidence part of the workflow Require each entitlement change to record what changed, why it changed, and which policy produced the action so evidence is generated at the point of enforcement.

What's in the full article

Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article expands the five capability areas that distinguish streaming from true continuous governance, including signal ingestion and continuous enforcement.
  • It gives concrete lifecycle scenarios for movers, leavers, and source-record corrections that show how policy recomputation should behave.
  • It explains why no-code configuration matters for long-term sustainability when identity sources and organisational structures keep changing.
  • It describes the author’s position on Continuous Identity as a durable operating model rather than a rebranding of periodic IGA.

👉 Read Fischer Identity's perspective on continuous identity governance and policy-driven lifecycle control →

Continuous identity governance: what changes for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Continuous Identity is a control model, not a faster feed. The article is right to separate frequent ingestion from actual governance. A platform that only moves data faster can still leave entitlement decisions stale, while a continuous model recomputes identity posture and enforces outcomes in step with change. For IAM and IGA teams, the practical conclusion is that refresh speed alone is not a governance metric.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.

A question worth separating out:

Q: Who is accountable when identity governance is still based on manual exceptions and delayed reviews?

A: Accountability stays with the organisation that allowed the control gap to persist, because delayed review is a governance design choice, not an unavoidable limitation. In regulated environments, control owners, IAM leaders, and business approvers all need to accept that stale entitlement state is a programme failure, not an administrative inconvenience.

👉 Read our full editorial: Continuous identity governance is replacing periodic IGA models



   
ReplyQuote
Share: