Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Left of ATO in federal programmes: what changes for IAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Federal ATO delays can stretch from days to years and, in one panel example, a single ATO can cost about $1 million per workload per year, according to Island. Moving left of ATO shifts security, collaboration, and evidence generation into the build process, making authorization a governance problem rather than a paperwork problem.

NHIMG editorial — based on content published by Island: What It Really Means to Move Left of ATO

Questions worth separating out

Q: How should federal teams move left of ATO without weakening assurance?

A: Start by converting control evidence into pipeline outputs, not manual documents.

Q: Why does clean core matter for identity and access governance?

A: Clean core matters because it changes where controls can live.

Q: What goes wrong when every federal workload gets the same review burden?

A: Backlogs grow, reviewers spend time on low-risk controls, and teams lose the ability to focus on the systems that matter most.

Practitioner guidance

  • Embed authorization evidence in delivery pipelines Map control checks, artifact generation, and validation steps into CI/CD so evidence is created continuously rather than assembled for a review packet.
  • Tier workloads by mission and data risk Create a formal classification model for workloads so low-risk systems follow a lighter review path while high-risk systems retain deeper authorization scrutiny.
  • Standardize evidence formats across stakeholders Require developers, assessors, security leads, and program owners to consume the same telemetry and control artifacts to reduce translation delays.

What's in the full article

Island's full blog post covers the operational detail this analysis intentionally leaves for the source:

  • The Billington panel context and the federal programme examples that shaped the article's recommendations.
  • The practical discussion of workload 'shirt sizing' and how teams decide what qualifies as low-risk versus high-risk.
  • The implementation angle on using infrastructure as code, inherited cloud controls, and CI/CD-integrated evidence.
  • The cultural change argument about bringing developers, assessors, and mission owners into the same process.

👉 Read Island's analysis of left of ATO and federal mission readiness →

Left of ATO in federal programmes: what changes for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Left of ATO is really a control design problem, not a speed problem. The article correctly frames delay as the symptom, but the deeper issue is that federal authorization still treats security evidence as something to be assembled after development work is done. That model forces security, compliance, and delivery teams into serial handoffs. Practitioners should read left of ATO as a redesign of control flow, not a request to approve faster.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

A question worth separating out:

Q: Who should own authorization decisions in a left-of-ATO model?

A: Ownership should be shared across developers, security teams, assessors, and program managers, but the evidence must be standardized so each group is working from the same control state. Without that common basis, accountability fragments and approval cycles become negotiation cycles instead of governance decisions.

👉 Read our full editorial: Left of ATO reframes federal security as governance and mission readiness



   
ReplyQuote
Share: