Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity as the control plane: are IAM teams ready for AI governance?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Identity has moved from administrative plumbing to the enterprise control plane, with permissions metadata, authorization paths, and micro-certifications now defining where risk lives and how AI governance must scale, according to Veza. Incremental IAM, PAM, and IGA tuning is no longer enough; the governing assumption that access can be understood through directories and periodic reviews has collapsed.

NHIMG editorial — based on content published by Veza: identity as the enterprise control plane for AI governance

By the numbers:

Questions worth separating out

Q: How should security teams govern access when permissions and usage do not match?

A: Treat the mismatch as a risk signal, not a reporting issue.

Q: Why do periodic access reviews struggle in AI-heavy environments?

A: Because risk changes faster than the review cycle.

Q: What do IAM teams get wrong about visibility into non-human identities?

A: They often stop at discovery.

Practitioner guidance

  • Build an authorization inventory, not just an account inventory Map who can do what across systems, then classify inherited, delegated, and chained permissions separately from directory objects.
  • Shift recertification toward micro-certification Apply shorter, context-bound access justification to sensitive entitlements and high-blast-radius permissions.
  • Use graph context to find hidden exposure Model access relationships so teams can see how one permission opens another across systems.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • How Veza frames canonical authorization data as the foundation for identity transformation
  • The operational logic behind micro-certifications and why they differ from periodic access reviews
  • Why graph architectures matter for exposing chained permissions and hidden risk paths
  • How the article links identity governance to AI governance without reducing either to login-centric controls

👉 Read Veza's analysis of identity as the enterprise control plane for AI governance →

Identity as the control plane: are IAM teams ready for AI governance?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Identity has become the enterprise control plane, not a support function. The article is right to reject the old assumption that identity is mainly about directories and login events. Modern risk lives in permissions metadata, authorization paths, and contextual trust decisions, which means IAM, PAM, and IGA have to operate as one control system rather than separate silos. The practitioner implication is clear: if you cannot govern authorization, you cannot claim to govern identity.

A few things that frame the scale:

A question worth separating out:

Q: How do PAM and IGA need to change in the agentic AI era?

A: They need a shared authorization model that treats agent access as governed entitlement, not a special-case exception. PAM should control the highest-risk paths, while IGA should certify the underlying permissions graph that makes those paths possible. Without that alignment, the controls will describe different versions of the same risk.

👉 Read our full editorial: Identity as the enterprise control plane for AI governance



   
ReplyQuote
Share: