TL;DR: C1.ai argues that identity governance should be measured by risk reduction, operational speed, and automation coverage, not just completed reviews or passed audits, because those activity metrics say little about whether identity exposure is actually falling across humans, non-human identities, and AI agents. Completion proves process motion; risk reduction proves the programme is governing access effectively.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “10 IGA Metrics Every Security Team Should Use to Measure Success”.
Key questions
Q: What should teams do first when access reviews are completed but identity risk is still high?
A: Start by separating process completion from security outcome.
Q: Why do completed identity workflows not always mean the programme is effective?
A: Because completion only proves that a task ran, not that access changed safely.
Q: What are the signs that an IGA programme is relying too much on manual effort?
A: Long campaign preparation, slow revocation, heavy reviewer load, and large numbers of tickets for routine access changes are all signs that manual work is doing the job automation should handle.
Practitioner guidance
- Track time to remove access after change events Measure the time from termination, role change, or contract end to full access removal, and treat long tail cleanup as a governance failure, not a workflow delay.
- Separate review completion from review quality Measure how many access decisions are automated, how many are exception-based, and how much reviewer effort is spent preparing campaigns versus making decisions.
- Baseline privileged access duration Record how long elevated access stays active by system and entitlement, then compare standing privilege against temporary access granted only when needed.
Bottom line: The core problem is not whether identity work gets done, but whether it reduces exposure in a measurable way.
What's in the full article
C1.ai's full blog post covers the operational measurement detail this post intentionally leaves for the source:
- The ten-metric breakdown for onboarding, offboarding, access requests, privileged access, and review execution
- Specific examples of what to measure for automation coverage, reviewer workload, and remediation speed
- The article's framing for turning identity metrics into risk and productivity evidence
- How the vendor recommends thinking about access governance across humans, non-human identities, and AI agents
👉 Read C1.ai's guide to IGA metrics that prove risk reduction, not completion →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Outcome metrics are now the only credible proof of identity governance maturity. Completion data can show that a process ran, but it cannot prove that access risk fell or that the programme became easier to operate. In mature identity governance, the meaningful question is whether risk trends, remediation speed, and automation coverage are improving together. Practitioners should treat activity as evidence of motion, not evidence of control.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: How should organisations measure whether identity governance is reducing blast radius?
A: Use measures that show whether risky access is shrinking over time, including standing privilege, orphaned accounts, and high-risk entitlements. If those numbers stay flat after campaigns and remediation, the programme is maintaining records rather than reducing exposure.
👉 Read our full editorial: IGA metrics that prove risk reduction, not just completion