TL;DR: Traditional IAM still makes one-time decisions about onboarding, authentication, authorization, and review even as identities, devices, and risks change continuously, according to SGNL. Point-in-time governance leaves stale access and weak context across human, NHI, and agentic workflows, so continuous identity becomes an operational requirement rather than an architectural preference.
Editorial analysis by NHI Mgmt Group, based on content published by SGNL: “Stale access, stale risk: is Continuous Identity the answer?”.
Key questions
Q: What breaks when IAM decisions are only made at onboarding or login?
A: Access quickly becomes stale because the identity state used for the decision no longer matches the current user, device, role, or threat context.
Q: Why does point-in-time IAM increase business and security risk?
A: Because the longer identity state remains unchanged, the more opportunity there is for stale entitlements, delayed revocation, and misaligned assurance to persist.
Q: What are the signs that identity governance is not working in practice?
A: Common warning signs are repeated access workarounds, ignored approval workflows, super admins holding too much power, and teams bypassing the process because it is too slow or hard to use.
Practitioner guidance
- Rebuild identity governance around continuous state changes Move from single event decisions to identity state that updates as attributes, risk, device posture, and role context change across the lifecycle.
- Shorten the gap between change and enforcement Review where provisioning, access approval, and policy enforcement lag behind business or security events, then remove manual handoffs that create stale access.
- Tie recertification to live risk signals Use current device, location, threat, and application context so access reviews can reflect what the identity is doing now rather than what it was doing last quarter.
Bottom line: Traditional IAM decisions become unreliable when identity, device, and business context change faster than provisioning and review cycles can update.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Point-in-time IAM is a control model built for slower business tempo. It presumes that onboarding, authentication, authorization, and review can each capture a stable truth about identity, then reuse that truth safely later. The article shows why that premise no longer holds in dynamic enterprises, where roles, devices, and risk signals shift continuously. Practitioner implication: identity governance has to move from event checkpoints to ongoing state management.
A question worth separating out:
Q: How should teams reduce identity hygiene risk across human and non-human accounts?
A: Start by cleaning the identity foundation before expanding controls. Remove stale groups, assign clear ownership to every account, and make reviews broad enough to cover the access users and systems actually use. Identity hygiene fails when governance is fragmented, so the best programmes treat human and non-human access as one lifecycle discipline.
👉 Read our full editorial: Continuous identity exposes the limits of point-in-time IAM