TL;DR: Fortune 500 IAM leaders say fragmented identity data, manual certification work, and services-heavy deployments are overwhelming programmes and leaving controls partially implemented, according to Hydden. The deeper problem is that governance models still assume clean, centralised identity data and sustainable manual oversight, even as AI and regulatory pressure increase.
NHIMG editorial — based on content published by Hydden: the case for a new foundation in identity management
Questions worth separating out
Q: Where do IAM programmes fail when identity data is fragmented across many systems?
A: They fail where review, provisioning, and audit decisions depend on inconsistent identity state.
Q: When should organisations stop treating manual IAM work as acceptable?
A: They should stop when manual work becomes the default mechanism for validating entitlements, reconciling records, or approving access.
Q: What do security teams get wrong about IAM platform consolidation?
A: They often assume more catalog breadth means better governance.
Practitioner guidance
- Map the authoritative identity record Document which system owns each identity attribute, entitlement, and status field across HRIS, directory, cloud, SaaS, and PAM sources.
- Measure manual reconciliation effort Track how many certification, provisioning, and audit tasks still rely on spreadsheet exports, email approvals, or contractor cleanup.
- Test control ownership without external services Ask whether the internal team can run, modify, and recover the IAM control without a consultant on call.
What's in the full article
Hydden's full article covers the operational detail this post intentionally leaves for the source:
- Specific examples of how identity data fragmentation shows up across enterprise systems and why it slows governance.
- The vendor's explanation of why manual IAM processes keep reappearing even after platform investments.
- A deeper account of the services dependency cycle and how it affects deployment economics.
- The article's rationale for a different identity-data-first operating model.
👉 Read Hydden's analysis of fragmented identity data and manual IAM operations →
Identity data fragmentation and manual IAM: what teams are missing?
Explore further