Join our Newsletter — 33% off our NHI Course

ITSM access requests: where service desks stop and governance starts

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: ITSM tools can route and log access requests, but they do not evaluate entitlement scope, license fit, SoD conflicts, or time-bound access, according to Zluri’s comparison of ITSM workflows and policy-driven provisioning. The governance gap is structural: ticketing speed is not the same thing as access control, especially when over-permissioning and orphaned access are the real risk.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 14 IT Service Management Tools (ITSM Tools) in 2026”.

Key questions

Q: What breaks when ITSM tools are used as the only access request control?

A: The workflow still records requests, but it cannot judge entitlement scope, license fit, time limits, or SoD conflicts.

Q: Why do inherited access approvals create governance risk?

A: Because copied access often carries hidden excess privilege into the new account.

Q: How can security teams tell whether provisioning governance is working?

A: Look for evidence that access changes are being removed as reliably as they are granted.

Practitioner guidance

  • Separate access approvals from service-desk routing Define which requests belong in ITSM and which require policy-driven entitlement decisions.
  • Encode license and role rules before provisioning Build request policies that distinguish between an application request and the correct license tier, permission set, and business role.
  • Automate expiry for time-bound access Treat project-based or temporary access as a lifecycle event with a built-in end date.

Bottom line: ITSM platforms are useful for logging and routing, but they do not replace access governance because they cannot evaluate whether a request is justified, scoped correctly, or time-limited.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

ITSM is a request system, not an access-governance system. That distinction is not semantic, it is structural. Ticketing platforms are designed to move work through queues, while access governance is designed to decide whether entitlement should exist at all, at what scope, and for how long. When organisations collapse those two jobs into one workflow, they end up measuring service efficiency while losing control precision.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations keep ITSM in the access request process?

A: Yes, but only as the intake and traceability layer. ITSM is useful for routing, status visibility, and audit history, but it should not be the system that decides entitlement scope, license fit, or time-bound revocation. Those decisions belong in the access governance layer, where policy can be enforced consistently.

👉 Read our full editorial: ITSM tools are not identity governance tools for access requests


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.