TL;DR: C1.ai says modern identity governance has shifted from static approvals and quarterly checkpoints to continuous, time-bound workflows, with customers saving nearly 3,000 hours in 2025 through policy, automation, and review improvements. The underlying control problem is no longer access approval alone; it is making governance observable, service-oriented, and operational at the speed work now moves.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “January 2026 Product Updates: Modern Identity at Scale”.
Key questions
Q: How can identity teams keep pace with access changes in modern environments?
A: Identity teams should connect policy enforcement to live events such as role changes, new integrations, and unexpected privilege grants.
Q: What breaks when access reviews stay quarterly in a fast-moving environment?
A: Quarterly reviews can miss entitlement drift, delay remediation, and leave teams working from stale access context.
Q: What are the signs that identity governance is not working in practice?
A: Common warning signs are repeated access workarounds, ignored approval workflows, super admins holding too much power, and teams bypassing the process because it is too slow or hard to use.
Practitioner guidance
- Define the governed workflow boundary Treat requestable automations, onboarding, offboarding, and scoped admin tasks as governed services with policy checks, structured intake, and audit trails instead of ad hoc admin actions.
- Instrument review operations for timing signals Track submission timing, expiring grants, extension requests, and response-time percentiles so you can see where access review work is stalling or repeatedly requiring intervention.
- Test exception handling under deprovisioning Validate what happens to extensions, fallback paths, and review continuity when accounts are removed automatically or reviewers are unavailable, then fix the workflow before it becomes a gap.
Bottom line: Modern identity governance is moving toward continuous control because access now changes faster than static approval cycles can absorb.
What's in the full article
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- Weekly release note context behind the January product changes and how they fit the 2026 roadmap
- Details on batch submission for access reviews, including how reviewers can submit decisions incrementally
- Examples of the new dashboard metrics for expiring grants, extension requests, and response-time analysis
- More information on the CEL logic improvements, fallback handling, and accessibility changes
👉 Read C1.ai's January product updates on modern identity governance at scale →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Continuous governance is becoming the operating model for modern identity programmes: static approvals and quarterly checkpoints do not map to environments where access changes continuously across infrastructure, SaaS, and operations. The stronger pattern is governance that follows the workflow, not the calendar. That shift matters for human IAM, NHI governance, and delegated admin flows because the control has to stay aligned with actual access movement.
A question worth separating out:
Q: Should organisations centralise approvals or decentralise self-service for identity workflows?
A: The better pattern is governed self-service for routine work and tighter approval control for high-risk actions. That keeps operational speed where the risk is low while preserving explicit oversight where standing privilege or sensitive change would otherwise expand exposure.
👉 Read our full editorial: Modern identity at scale means governance must become continuous