Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should election agencies implement identity management to…
Governance, Ownership & Risk

How should election agencies implement identity management to improve transparency and accountability during voting operations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Governance, Ownership & Risk

Election agencies should centralize authentication, auditing, and reporting in a single identity platform so they can see who accessed what, when they logged in, and how systems exchanged data. That approach improves public accountability, reduces fragmentation, and makes it easier to track both user and device identities across voting systems and related applications.

Identity management as an accountability mechanism in voting operations

Election agencies use identity management for more than login control. In voting operations, it becomes the record of who is allowed to act, which systems they touched, and whether those actions can be traced back to a named person or trusted device. That matters because transparency is not only about public reporting after an election. It also depends on whether internal access, configuration changes, and data exchanges can be attributed and reviewed without gaps. The NIST Cybersecurity Framework 2.0 is relevant here because identity governance supports the broader functions of governance, protect, and detect across election technology. In practice, many election agencies discover accountability weaknesses only after multiple systems, vendors, and temporary staff have already been operating under inconsistent access rules.

What strong identity controls look like during elections

A practical election identity model should link people, roles, devices, and privileged actions into one auditable chain. That means central authentication for staff and contractors, unique accounts rather than shared logins, step-up controls for sensitive functions, and immutable logs that show access, approvals, and system-to-system activity. Agencies should be able to answer basic questions quickly: who changed a ballot definition, who approved a transport task, who exported data, and which device was used. The goal is not just stronger authentication. It is reliable attribution across the whole voting workflow, including election management systems, poll worker tools, reporting applications, and any external service that supports them.

The other design choice is role discipline. Voting operations often involve temporary workers, local administrators, and overlapping responsibilities, so role-based access needs to be narrow and time-bound. When identity records are clean, agencies can separate routine administration from privileged tasks and preserve an audit trail that supports internal review, public confidence, and incident investigation. The NIST SP 800-53 Rev 5 Security and Privacy Controls is a useful reference because it ties identity, auditability, and access enforcement together rather than treating them as separate concerns.

For agencies, the operational test is simple: if a system action cannot be traced to a specific identity with a valid role and timestamp, the control model is too weak for election use. Where agencies rely on shared credentials, manual spreadsheets, or inconsistent vendor access records, accountability becomes partial and evidence collection becomes slow.

Where election identity programs become fragile

Tighter identity control often increases administrative overhead, so agencies have to balance traceability against the reality of frequent staffing changes, seasonal operations, and offline contingencies. The most common failure is over-centralization without lifecycle discipline: agencies build a single platform but do not keep role assignments, device trust, and revocation processes current. That creates the appearance of control without dependable attribution.

There is also a governance edge case around contracted support and local jurisdictions. Shared operational responsibility can blur who owns account approval, who reviews logs, and who certifies that access was removed after an event. Guidance here is not fully uniform across the sector, but the safest approach is to treat every privileged election function as personally accountable and time-bounded. Agencies should also plan for degraded conditions, because if identity services are unavailable during a live event, the fallback process must preserve traceability instead of bypassing it.

Another overlooked issue is public accountability versus operational secrecy. Transparency does not mean exposing sensitive access details publicly; it means the agency can evidence control internally and explain it externally without revealing security-sensitive implementation specifics. When identity evidence is scattered across teams or tools, that balance becomes hard to sustain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-03 — Mission Objectives and StakeholdersElection accountability depends on clear roles and traceable governance outcomes.
PR.AA-01 — Identities and Credentials Are ManagedCentral identity management is the core mechanism for named, auditable access.
DE.CM-08 — Monitoring for Unauthorized ActivityAuditability during voting operations depends on monitoring access and system exchanges.
Recommendation — Define accountable election roles and align identity controls to the agency's transparency objectives. Manage identities and credentials centrally so every election action is attributable to a specific account. Monitor identity events and privileged actions to spot unauthorized election activity quickly.
CIS Controls v85 — Account ManagementElection agencies need controlled account lifecycle and unique identity assignment.
6 — Access Control ManagementLeast-privilege access is essential for election system accountability and role separation.
8 — Audit Log ManagementTransparency during voting operations requires reliable logs for review and investigation.
Recommendation — Enforce unique, timely managed accounts for staff, contractors, and temporary poll workers. Restrict election access by role and review privileged permissions before each voting cycle. Collect and protect audit logs so access and configuration changes remain reviewable end to end.
NIST SP 800-63IAL2 — Identity Assurance Level 2Election staff identity assurance should be stronger than basic self-asserted accounts.
AAL2 — Authenticator Assurance Level 2Stronger authentication reduces the risk of impersonation in sensitive election workflows.
Recommendation — Use verified identities for election personnel whose actions affect voting operations. Require phishing-resistant or strong multi-factor authentication for privileged election access.

Practitioner Guidance

What to prioritise: Start with privileged and high-impact election functions, not with generic user onboarding. If a role can alter results, reporting, device trust, or data movement, it should be in the first control set.

What to verify: Confirm that every privileged action produces an attributable log entry, that revocation is timely after events or staffing changes, and that vendor access is reviewed on the same cycle as internal access. If any of those cannot be evidenced, accountability is still incomplete.

Practitioner takeaway: In election environments, identity management succeeds only when it can support attribution under real operational pressure, not just secure routine logins.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org