TL;DR: Identity programmes can process millions of accounts and still leave critical applications, entitlements and non-human identities outside effective governance, according to SafePaaS. The real measure of scale is time to governance coverage across business boundaries, because administration that outpaces policy is not control.
NHIMG editorial — based on content published by SafePaaS: Identity scale is a governance problem, not a headcount problem
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams measure identity scale in complex enterprises?
A: They should measure how much material access is governed, not how many identities a platform stores.
Q: Why do non-human identities make identity governance harder to measure?
A: Non-human identities multiply faster than human accounts, often across teams and platforms that do not share a single source of accountability.
Q: What breaks when governance only covers the systems already connected to IGA?
A: The programme appears complete while critical applications, entitlements and acquired systems remain outside policy.
Practitioner guidance
- Measure governance coverage, not identity volume Track the percentage of material applications, entitlements and identity types that are actually governed today.
- Map policy by business boundary Test whether access decisions can differ across legal entities, operating units, ledgers and regions even when the role name is the same.
- Bring non-human identities into the same control model Include service accounts, integration users, bots, API credentials and AI agents in ownership, review and lifecycle processes.
What's in the full article
SafePaaS's full article covers the operational detail this post intentionally leaves for the source:
- A federated governance model for extending policy across ERP, SaaS and legacy applications without replacing existing identity tooling.
- Concrete examples of how entitlement-level reviews and context-aware SoD checks work across legal entities and operating units.
- Case study results showing how one enterprise expanded governed applications, reduced review effort and shortened fulfilment time.
- The compliance mechanics for SOX, ITGC and continuous monitoring when non-human identities can affect financial reporting and sensitive access.
👉 Read SafePaaS's analysis of identity scale and governance coverage →
Identity scale and governance coverage: what IAM teams miss?
Explore further
Identity scale without governance coverage is a false success metric. A platform that can ingest more users, more systems or more entitlements is only scaling administration if it cannot evaluate effective access across the business. The decisive question is whether material access is governed at the entitlement level across humans and non-humans. Practitioners should treat raw identity counts as secondary to governed coverage.
A few things that frame the scale:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which shows how thin the operational margin still is.
A question worth separating out:
Q: Who is accountable when acquired systems stay outside identity governance?
A: IAM, IGA and compliance owners are accountable for the gap until the acquired estate is brought under policy and evidence controls. If governance lags behind business change, the organisation inherits access risk, control exceptions and audit exposure at the same time.
👉 Read our full editorial: Identity scale is a governance problem, not a headcount problem