TL;DR: Student identity shows why rigid workforce and CIAM categories break down when one person moves through multiple relationships, access states, and governance models over time, according to Fischer Identity. The real control problem is relationship-aware identity, not isolated account administration.
NHIMG editorial — based on content published by Fischer Identity: The Student Identity Problem Proves the Market Is Wrong
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should organisations govern identity when one person moves through multiple relationship states?
A: They should govern access from the current relationship state, not from a single static identity label.
Q: Why do workforce IAM and CIAM both fail for student-style identity lifecycles?
A: Because each model assumes a narrower operating context than the real lifecycle requires.
Q: What breaks when access reviews are built around static identity categories?
A: Reviews become blind to overlapping states, temporary affiliations, and delegated access that outlive the reason they were granted.
Practitioner guidance
- Model relationship state explicitly Define the authoritative relationship states that drive access for each population, such as prospect, enrolled student, student worker, alumni, contractor, or guest.
- Connect lifecycle events across systems Map enrolment, HR, alumni, and sponsorship events into a single governance flow so status changes propagate before access drift accumulates.
- Review delegated and third-party access separately Treat parent access, partner access, and service account access as governed relationships with distinct revocation rules.
What's in the full article
Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:
- How the platform maps relationship changes across student, employee, alumni, and guest states in connected identity flows
- Examples of how access governance can follow enrolment, employment, and sponsorship transitions without manual rework
- Why configuration-based identity automation matters when one person must move cleanly across multiple lifecycle paths
- How the article frames higher education as a model for other industries with overlapping identity relationships
👉 Read Fischer Identity's analysis of relationship-aware identity and student lifecycles →
Student identity lifecycles: what IAM teams are missing?
Explore further
Relationship-aware identity is the category that modern IAM has been missing. The article correctly shows that people do not move through a single fixed identity state. They move through overlapping relationships with different systems, owners, and obligations. That is why workforce IAM and CIAM both solve only part of the lifecycle problem, while governance breaks when the programme treats the person as static.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how quickly relationship sprawl turns into governance blind spots.
A question worth separating out:
Q: How can security teams reduce orphaned access in complex identity programmes?
A: They should pair lifecycle triggers with ownership and offboarding rules across all identity types, including service accounts and delegated accounts. Orphaned access usually appears when systems disagree about who owns the relationship or when a state change is not propagated to every connected platform. Continuous reconciliation is the control that closes that gap.
👉 Read our full editorial: Relationship-aware identity is the real lesson from student lifecycles