TL;DR: Identity categories still help buyers and vendors, but modern enterprises operate through fluid relationships that cross workforce, customer, partner, service account, and AI agent boundaries, according to Fischer Identity. The governance shift is from account-centric administration to lifecycle-aware control of every relationship, because access now changes as the relationship changes.
NHIMG editorial — based on content published by Fischer Identity: Why Workforce IAM and CIAM Are No Longer Enough
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should organisations govern identity when one person moves through multiple relationship states?
A: They should govern access from the current relationship state, not from a single static identity label.
Q: Why do separate workforce and CIAM systems create identity risk?
A: Because they split the enterprise view of access across different populations and rulesets.
Q: What breaks when lifecycle logic is buried in scripts and custom workflows?
A: The organisation loses consistency, auditability, and scale.
Practitioner guidance
- Map access to relationship state Inventory the active relationships that justify each access grant, then tie entitlement reviews to relationship changes instead of account types.
- Unify lifecycle ownership across identity populations Assign a clear sponsor, expiry expectation, and review trigger for employees, customers, vendors, service accounts, and AI agents.
- Replace brittle lifecycle scripts with governed policy Move provisioning, deprovisioning, and access modification rules out of custom scripts and into a governed control plane that can enforce them consistently across systems.
What's in the full article
Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:
- Examples of how relationship-aware identity applies across higher education, healthcare, manufacturing, and government.
- Operational guidance on reducing identity fragmentation when workforce, customer, partner, and NHI systems overlap.
- Details on configurable, code-free lifecycle automation for identity relationship changes and governance enforcement.
- Additional context on continuous identity control and how the vendor positions its platform for complex environments.
Relationship-aware identity: what IAM teams need to change now?
Explore further
Relationship-aware identity is now the right unit of governance. The old split between workforce IAM and CIAM describes product categories, not operating reality. Modern organisations need to govern the relationship that justifies access, because access rights change as the relationship changes. That means identity architecture has to be built around lifecycle state, ownership, and current purpose, not around static labels.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: What is the difference between managing accounts and managing relationships?
A: Account management focuses on the object in the system. Relationship management focuses on the business reason the object exists, who owns it, how long it should persist, and what should happen when the underlying relationship changes. For modern IAM, relationship management is the stronger model because it preserves context across lifecycle transitions.
👉 Read our full editorial: Why workforce IAM and CIAM no longer cover identity relationships