TL;DR: Identity governance fails when organisations rely on ad hoc processes, spreadsheets, and partial automation that cannot keep pace with access changes, according to Axiad. Manual remediation, weak provisioning oversight, and poor cross-system coordination leave users over-privileged and make compliance harder to sustain.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “5 Current Challenges of Identity Governance and Administration”.
Key questions
Q: What breaks when fraud investigations depend on spreadsheets and ad hoc team pings?
A: The main failure is latency.
Q: Why do inherited permissions create so much identity risk?
A: Inherited permissions are risky because they transfer trust from one identity to another without proving that the new subject needs the same access.
Q: What are the signs that access governance is failing in practice?
A: The clearest signs are slow remediation, repeated rubber stamp access reviews, and missed permissions outside traditional HR linked systems.
Practitioner guidance
- Replace spreadsheet-led access reviews Move certification, revocation, and exception handling into an identity governance workflow tied to authoritative account and entitlement data.
- Bind access changes to lifecycle events Connect joiner, mover, and leaver events to provisioning and deprovisioning so inherited permissions are reassessed whenever a role or contract changes.
- Audit inherited and copied access Look for accounts created by cloning existing users, then compare those entitlements to business role requirements and remove access that has no current justification.
Bottom line: Manual identity governance breaks down because fragmented workflows cannot maintain a current view of access or evidence of control.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Manual governance is the control failure, not just a process inconvenience: This article shows that spreadsheet-led access administration and ad hoc approvals do not scale into real identity governance. When the operating model is fragmented, certification is retrospective, revocation is delayed, and no team has a reliable view of effective access. The practitioner conclusion is that governance must be treated as a control system, not a document workflow.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: How can IAM teams reduce manual work without weakening controls?
A: They should automate lifecycle events, connect access decisions to authoritative data, and measure actual remediation rather than ticket closure. The goal is not fewer controls, but fewer manual handoffs that delay provisioning and revocation. Strong automation should shorten exposure windows while preserving traceability.
👉 Read our full editorial: Identity governance still breaks down under manual access control