Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

IGA best practices are established, but are teams following them?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Identity governance does not lack standards, according to Fischer Identity; the real problem is that many programmes drift from authoritative data, lifecycle automation, least-privilege policy, and auditability, which turns governance into fragile custom work instead of repeatable control. Proven frameworks matter because the gap is execution discipline, not conceptual invention.

NHIMG editorial — based on content published by Fischer Identity: Making Sense of the Latest IGA Guidance, The Myth of “No Best Practices” in IGA

By the numbers:

Questions worth separating out

Q: How should teams build an IGA programme that survives scale and audits?

A: Anchor governance in authoritative source data, policy-driven access rules, and repeatable certification.

Q: Why do identity governance programmes break when teams rely on flexibility?

A: Flexibility often means exceptions, local overrides, and code paths that nobody fully owns.

Q: What do teams get wrong about access certification?

A: Teams often treat certification as proof that access is safe, when it is really only a decision process.

Practitioner guidance

  • Standardise authoritative sources Declare which upstream systems own identity truth for employees, students, contractors, service accounts, and other governed populations.
  • Remove custom code from governance paths Move access rules, workflow branching, and connector logic into configuration wherever possible so upgrades do not break hidden dependencies or audit evidence.
  • Shorten certification latency Tie access reviews to changes in role, entitlement, or employment state so reviewers assess current identity state rather than stale snapshots from a quarterly cycle.

What's in the full article

Fischer Identity's full blog covers the operational detail this post intentionally leaves for the source:

  • The article expands on configuration-first design choices that reduce custom code in identity workflows.
  • It outlines how the vendor maps authoritative sources to governance rules across HR, SIS, ERP, and CRM systems.
  • It shows how policy-based access models such as RBAC, ABAC, and PBAC are expressed in the platform.
  • It describes the vendor's implementation claims around fixed-fee deployments and auditability at scale.

👉 Read Fischer Identity's blog on why IGA best practices already exist →

IGA best practices are established, but are teams following them?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

IGA best practices are real, but programme discipline is the differentiator. The article is correct to reject the idea that identity governance is a blank-slate discipline. NIST, ISO, and community guidance have already established the core control pattern: authoritative data, policy-based access, attestation, and auditability. The failure is rarely conceptual. It is operational, where teams allow flexibility, custom code, or local exceptions to override the control model. Practitioners should treat maturity as adherence to proven governance mechanics, not as invention.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: How do human and non-human identity governance models differ in practice?

A: The core control logic is similar, but non-human identities change faster, scale more widely, and are easier to overlook. That means lifecycle automation, visibility, and revocation discipline must be tighter for service accounts, API keys, and workload identities. Treating them as an exception class creates governance blind spots.

👉 Read our full editorial: IGA best practices are established, but often ignored



   
ReplyQuote
Share: