They should treat access as layered rather than one-dimensional. Start with narrow birthright access, keep role access lean, use peer behavior to inform recommendations, and isolate individual exceptions so they can be reviewed and removed when the need ends. That model is more adaptable than static labels.
How to design identity governance for work that changes day to day
identity governance for dynamic work has to assume that people, teams, projects, and system relationships will change faster than static job labels can. The practical goal is not to precompute every eventual permission. It is to give people enough access to start, constrain what they can do by default, and make it easy to tighten, review, or remove access as the work changes.
A useful design starts with birthright access that is narrow and predictable, then adds role access only where the role is stable enough to justify it. Dynamic work usually needs layered access, not a single entitlement model. That means routine access lives in the role layer, temporary or context-specific access is isolated, and exceptions are treated as separate governed objects rather than informal one-off grants.
That approach is more resilient than trying to force every worker into a fixed entitlement profile. It also creates clearer control points for review and recertification, because the organisation can see which access is standard, which access is conditional, and which access should expire when the task, project, or engagement ends. For a broader operating model, NHIMG’s IAM and IGA Basics is a good reference point for the relationship between access management, governance, and entitlement control.
Why layered access works better than static labels
Dynamic work changes the normal failure mode of identity governance. The main risk is not only excessive access at onboarding, but access that lingers after someone changes teams, picks up a short-term project, or finishes a temporary duty. Static labels tend to overgrant or undergrant because they assume one job family can fully represent actual work. Layered access lets the organisation separate stable access from situational access.
The most useful pattern is to treat role access as the steady state, then add short-duration exceptions when needed. Those exceptions should be explicit, time-bounded, and visible enough to be reviewed independently. This is where a clean entitlement model matters: if temporary access is mixed into the role itself, you lose the ability to tell whether the role is still correct or whether the exception has become permanent drift. NHIMG’s Role Mining and Role Design Guide is useful here because it focuses on keeping roles manageable rather than letting role explosion hide governance problems.
Peer behavior can also help governance teams improve recommendations, but it should be used as decision support, not as an automatic grant mechanism. If comparable users consistently need the same access to do the same work, that is a signal to improve the baseline role or birthright package. If only one person needs it, that points more naturally to an exception or a narrowly scoped entitlement. For ongoing review discipline, NHIMG’s Access Reviews and Certification Guide shows how to keep review campaigns focused on removing access rather than merely confirming it.
What to govern continuously as work shifts
Dynamic work governance should focus on the lifecycle of access, not just the initial grant. The critical control moments are joiner, mover, temporary assignee, and leaver events, because each one can invalidate earlier assumptions about need. If those transitions are not captured quickly, the organisation accumulates stale access, duplicate access paths, and unowned exceptions that no one feels responsible for cleaning up.
That is why exception handling has to be its own governed process. Every exception should have an owner, a reason, an expiry or review point, and a clear rule for removal once the need ends. The practical standard is simple: if access exists because of a temporary work context, it should not survive that context without a new approval. NHIMG’s Joiner-Mover-Leaver (JML) Guide is relevant because dynamic work is really a moving-target lifecycle problem, not just an onboarding problem.
Good governance also needs visibility into whether access patterns are drifting faster than the model can absorb. If teams are constantly requesting exceptions for the same kind of work, the governance model is probably too rigid. If exceptions are rarely removed, the organisation is probably using temporary access as a substitute for role maintenance. NHIMG’s Identity Security Programme Guide helps frame this as an operating-model issue: ownership, process, and review cadence matter as much as the tooling.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Layered access and narrow birthright access depend on least-privilege assignment. |
| AC-2 — Account Management | Dynamic work needs lifecycle control over moving and temporary access changes. | |
| IA-5 — Authenticator Management | Temporary access still relies on controlled credentials, tokens, and other authenticators. | |
| Recommendation — Apply AC-6 to keep default access minimal and grant exceptions only when justified. Use AC-2 to manage provisioning, changes, and revocation across the access lifecycle. Use IA-5 to control issuance, rotation, and revocation of authenticators tied to access. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Proofing, Authentication, and Authorization | Dynamic access governance still needs controlled authorization decisions and revalidation. |
| Recommendation — Apply PR.AA-05 to ensure access decisions stay bounded by verified identity and authorization. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Layered access and exception review map directly to the management of access rights. |
| Recommendation — Use A.5.18 to review, adjust, and remove access rights when work context changes. | ||
Practitioner Guidance
What to prioritise: Separate standard access from temporary access at design time. If a permission is needed regularly enough to appear in multiple exceptions, move it into the role model or birthright set instead of normalising repeated manual grants.
What to verify: Every exception should have an approver, an expiry, and a removal path. If your governance process cannot answer who owns the exception and when it will be rechecked, the control is incomplete.
Decision rule: If the access is stable across the same type of work, govern it as a role. If it is task-bound, time-bound, or person-specific, govern it as an exception with tighter review and a shorter lifespan.
Practitioner takeaway: Dynamic work is easiest to govern when access is designed to decay naturally, because the organisation is controlling change instead of trying to freeze it.
Related resources from NHI Mgmt Group
- Why is it important to integrate identity and data governance?
- Should organisations prioritise external exposure or internal credential governance first?
- Why does hybrid work create more identity governance risk than fully remote work in some organisations?
- How should organisations implement identity and access governance in cloud and remote work environments?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org