Join our Newsletter — 33% off our NHI Course

GSI tax in IAM budgets: what changes when AI handles integration work?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Identity governance implementations still absorb 30 to 60 percent of year-one spend in services, while fewer than 7 percent of enterprise applications support SCIM and more than half of IGA deployments are distressed, according to Opnova and Gartner. AI changes the economics underneath the iceberg, but the governance model still needs to separate strategic architecture from connector toil.

Editorial analysis by NHI Mgmt Group, based on content published by Opnova: “The GSI Tax: What's Underneath Your IAM Budget”.

By the numbers:

  • Implementation services account for 30 to 60 percent of year-one spend in verified IGA purchases, according to Opnova.

Key questions

Q: What breaks in identity governance when integration is treated as a one-time project?

A: The programme starts to accumulate connector debt, because applications keep changing after go-live while the operating model assumes stability.

Q: Why do IGA programmes become so expensive to operate over time?

A: They become expensive when most of the work is custom integration, exception handling, and connector maintenance rather than durable governance architecture.

Q: How can security teams tell whether their identity budget is stuck on the connector treadmill?

A: Look for a growing onboarding queue, older items that never clear, and a rising share of budget spent on maintaining existing integrations.

Practitioner guidance

  • Budget separately for strategic design and connector maintenance Split identity governance spend into architecture, compliance mapping, and integration upkeep so the programme does not hide recurring toil inside implementation line items.
  • Measure the onboarding queue as an operating risk Track the number of applications waiting for integration, the age of the oldest item, and the pace at which old connectors break versus new ones are delivered.
  • Audit where custom connectors are carrying the programme Identify integrations built for applications without SCIM or stable APIs, then classify which ones are strategic and which are pure maintenance drag.

Bottom line: Identity governance programmes often spend more on implementation labour than on the software itself, which is why the GSI tax persists.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

AI is changing the economics of identity governance, not the need for governance. The article is right to draw a line between strategic architecture and repetitive connector toil. Program design, compliance mapping, and lifecycle governance still require human judgment, but the cost structure underneath them can now be reduced materially when integration work is no longer hand-built for every disconnected application. The implication is that IAM leaders should reprice the programme around work type, not software category.

A question worth separating out:

Q: Should organisations use AI for identity governance before they clean up data and policies?

A: No. AI should not be asked to decide access when identity records, entitlement labels, and policy rules are inconsistent. The better sequence is to normalise data, standardise approval criteria, and then apply AI to assist with scale, because automation amplifies the quality of the inputs it receives.

👉 Read our full editorial: AI changes the economics of the identity governance iceberg


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.