TL;DR: Higher education IAM platforms are being judged on operational lifecycle automation, delegated governance, and the ability to manage decentralized identity ownership under constant churn, according to Fischer Identity’s analysis of Tambellini’s StarChart™ 2025 for IAM Platforms. The real test is not feature volume but whether identity governance stays auditable as institutions absorb complexity and change.
NHIMG editorial — based on content published by Fischer Identity: Fischer Identity Named a “Commander” in The Tambellini Group’s StarChart™ 2025 for IAM Platforms
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
Questions worth separating out
Q: How should higher education teams govern identity when ownership is decentralised?
A: Use policy-based delegation with clear authority boundaries, not ad hoc local administration.
Q: Why does lifecycle automation matter more than manual IAM workflows in complex institutions?
A: Because identity state changes constantly in environments with students, staff, faculty, contractors, and affiliates.
Q: How do attribute-based controls help reduce role sprawl?
A: They let access decisions follow current identity and resource attributes rather than forcing every scenario into a new role.
Practitioner guidance
- Map lifecycle events to policy outcomes Document how joiner, mover, and leaver events become access decisions, and verify that each path is auditable from source system to entitlement removal.
- Set delegation boundaries in writing Define which local teams may administer identities, which attributes they can change, and which records remain outside their authority.
- Reduce role sprawl with attribute quality checks Review the attribute sources feeding access decisions and remove fields that are stale, duplicated, or ambiguous.
What's in the full article
Fischer Identity's full post covers the operational detail this analysis intentionally leaves for the source:
- How the StarChart™ assessment defines the Commander category in practice for IAM platforms
- The specific higher-education lifecycle and delegated administration scenarios Fischer says it handles
- The vendor's explanation of why institutions should evaluate IAM against decentralised ownership and high-churn populations
- The broader Tambellini StarChart™ context for understanding where Fischer sits in the IAM market
👉 Read Fischer Identity's commentary on Tambellini's 2025 IAM Platforms StarChart™ recognition →
Higher education IAM governance: what lifecycle automation changes?
Explore further
Lifecycle automation is the real governance test in higher education IAM. Static identity models fail when enrolment, employment, and affiliation change too quickly for manual review cycles to keep up. The issue is not just speed, but whether the platform can produce auditable identity state as relationships change. Institutions should treat lifecycle automation as a control plane, not an efficiency feature.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: What should IAM teams check before relying on delegated administration?
A: Teams should verify who can administer what, which changes are allowed, and whether local admins can see or touch identities outside their remit. Delegation is safe only when the boundary is explicit and enforced. If the boundary is vague, delegated access becomes a governance gap.
👉 Read our full editorial: IAM governance in higher education is still won on lifecycle automation