The best approach is to treat feedback as input to design decisions, not as a request to remove guardrails. Teams should test workflows with real users, identify where friction slows adoption, and then refine navigation, language, and task flow. The goal is to preserve security controls while making the system easier to use in daily operations.
Turning customer feedback into better identity journeys
Customer feedback is most useful when it identifies where people hesitate, rework, or abandon a task. In identity security, those signals usually point to wording, navigation, step ordering, recovery paths, or unclear policy explanation. The right response is to redesign the experience around the same control objective, not to weaken the control itself.
Teams should separate complaints about inconvenience from evidence of real design friction. A user saying a control is “too hard” may mean the flow is confusing, the message is poorly timed, or the exception path is hidden. That is a UX problem. If the feedback is about a control preventing an unsafe action, that is a security signal, not a reason to remove the safeguard.
Good feedback loops focus on task completion, error recovery, and comprehension. For example, if users repeatedly fail at enrollment or approval steps, the issue may be that the workflow does not explain why a step exists or how to finish it cleanly. Small changes, such as clearer labels, better progressive disclosure, and fewer unnecessary branches, often improve adoption without changing the control model.
Where feedback helps, and where it should not overrule security design
Feedback is strongest when it helps teams reduce friction around secure behaviour: fewer confusing prompts, better sequencing, clearer recovery instructions, and less duplicate input. It is weaker when it is used to justify removing challenge steps, expanding standing access, or bypassing review gates simply because users prefer speed.
That distinction matters because identity controls often protect against misuse even when the user experience feels inconvenient. The right question is not whether the user likes the control, but whether the control still prevents unauthorised access, excessive privilege, or ambiguous accountability while remaining usable enough for daily work.
For teams managing high-volume identity workflows, scale changes the UX problem. A small annoyance becomes a repeated operational burden when thousands of users hit the same path. In those cases, the improvement target is usually consistency and clarity, not relaxation of policy. If the control itself is sound, optimise the journey around it rather than treating every usability complaint as a security defect.
Risk and Threat Considerations
When customer feedback is used incorrectly, the main risk is that usability pressure becomes a back door for control erosion. Over time, teams may remove checks that users find annoying even though those checks are the only barrier against unsafe access, weak recovery, or privilege creep.
Failure mechanism: Teams treat recurring friction as evidence that the security requirement is excessive, then simplify the flow by weakening approval, shortening verification, or broadening access. That can create silent exposure if the removed step was the control that prevented misuse at scale.
Impact: The result is usually higher policy bypass, weaker assurance, and more inconsistent access decisions, especially where the same workflow is reused across many users or systems. The organisation may gain short-term adoption while increasing the chance of unauthorised access or later governance cleanup.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-4 — Secure Configuration of Enterprise Assets and Software | Improving workflows without weakening guardrails is a secure configuration and control-tuning concern. |
| Recommendation — Tune secure workflows to reduce friction without removing enforced safeguards. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication, and Access Control | The question is about preserving access controls while improving usability. |
| Recommendation — Preserve access control strength while streamlining user journeys and recovery paths. | ||
| NIST Zero Trust (SP 800-207) | PL — Policy Decision Point and Policy Enforcement Point | UX changes should not weaken the decision and enforcement split that preserves control intent. |
| Recommendation — Keep policy decisions and enforcement intact while improving the user-facing flow. | ||
Practitioner Guidance
What to prioritise: Sort feedback into three buckets: confusion, delay, and resistance to the control itself. Confusion points to wording or navigation fixes; delay points to workflow sequencing; resistance to the control needs a security review before any change is made.
What to verify: Before changing a guardrail, confirm whether the complaint reflects a failed task design or a genuine control objection. If users can complete the action safely after better guidance, the issue is UX. If the control is blocking an unsafe pattern, preserve it and improve explanation instead.
Practitioner takeaway: The safest design changes are usually the ones that remove uncertainty, not protection. If a proposed “improvement” reduces friction by removing assurance, it is not a UX fix, it is a control downgrade.
Related resources from NHI Mgmt Group
- How should security teams use AI in identity governance without weakening controls?
- How should security teams use cyber insurance without weakening identity controls?
- How should security teams use AI to improve compliance in ERP systems without weakening internal controls?
- How do security teams improve admin usability without weakening identity security controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org