Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity governance anxiety disorder: what access sprawl is doing to teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Overprovisioning, manual access grants, and audit stress are framed as “Identity Governance Anxiety Disorder” in a satirical description, according to C1.ai. The real issue is not the joke, it is that legacy governance processes still assume access is slow, stable, and human-paced, while a modern identity automation model is needed for humans, AI agents, and NHIs.

NHIMG editorial — based on content published by C1.ai: The Cure for IGAD: Identity Governance Anxiety Disorder

By the numbers:

Questions worth separating out

Q: How should security teams reduce risk in manual identity governance processes?

A: Security teams should remove repeatable approval work from email and spreadsheet handling, then tie each access decision to identity context, entitlement state, and ownership.

Q: Why do overprivileged identities keep showing up in mature programmes?

A: Overprivilege persists because access is usually easier to grant than to remove, and lifecycle ownership is often unclear.

Q: What do security teams get wrong about access reviews?

A: Teams often treat access reviews as proof of control, when they are really only a point-in-time check.

Practitioner guidance

  • Automate high-volume provisioning paths Remove manual approval loops from repeatable joiner, mover, and leaver tasks for humans and NHIs where policy is already deterministic.
  • Replace screenshot evidence with system logs Build access review evidence from authoritative event logs showing who approved, what changed, and when revocation or rotation occurred.
  • Separate human and NHI lifecycle workflows Keep one governance model, but do not force identical operational steps on all identity types.

What's in the full article

C1.ai's full blog post covers the satire and product framing this analysis intentionally leaves aside:

  • The original humour-driven symptom list and the way it maps to day-to-day identity operations
  • The vendor's own description of its identity automation positioning for humans, AI agents, and NHIs
  • The product messaging and customer-facing language that sits behind the IGAD joke
  • The full context around the access review pain points that inspired the post

👉 Read C1.ai's blog post on identity governance anxiety and access sprawl →

Identity governance anxiety disorder: what access sprawl is doing to teams?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Identity governance anxiety is a symptom of lifecycle mismatch, not a user-experience problem. The post satirises the burden of provisioning and access review, but the underlying issue is that governance processes have not kept pace with the number and velocity of identities in play. When NHIs, agents, and human users are managed through the same slow control loop, anxiety is a rational outcome. The practitioner takeaway is to treat delay, rework, and evidence churn as control failures, not staff resilience issues.

A few things that frame the scale:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
  • 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.

A question worth separating out:

Q: Who should own audit evidence for human and non-human access?

A: Ownership should sit with the governance process, not with ad hoc administrators collecting screenshots. The evidence must come from authoritative systems that record approval, provisioning, rotation, and revocation. That makes accountability easier to prove and removes the weakest link in the audit chain.

👉 Read our full editorial: Identity governance anxiety is a symptom of access sprawl



   
ReplyQuote
Share: