Organisations should connect request, approval, provisioning, and review steps into one governed workflow so access moves consistently from ticket to entitlement. The goal is to reduce manual handoffs, improve visibility, and keep fulfilment aligned with policy. Strong integrations also support faster decisions, clearer audit trails, and fewer orphaned or overprovisioned accounts.
Why This Matters for Security Teams
Identity lifecycle management breaks down when request, approval, provisioning, and review live in separate tools with separate owners. That fragmentation creates delays, inconsistent approvals, and entitlement drift, especially when service accounts, API keys, and other NHIs need fast movement through OWASP Non-Human Identity Top 10 guidance. NHI Mgmt Group’s NHI Lifecycle Management Guide shows that lifecycle discipline is not just an audit issue; it is a control for preventing orphaned access, stale approvals, and overprovisioned accounts.
Security teams often get the policy right but fail at execution. A ticket is approved, yet the entitlement lands late, lands with the wrong scope, or is never reviewed after the business need changes. That is where ITSM to IGA integration matters: it links request context to the actual entitlement, preserves evidence, and makes revocation part of the same operating rhythm. In practice, many security teams discover lifecycle gaps only after an access review, a failed offboarding, or a leaked credential has already exposed the mismatch between process and reality.
How It Works in Practice
The strongest operating model treats ITSM as the system of request and business context, and IGA as the system of entitlement truth. The workflow should pass a complete identity record across both systems: who requested access, why it is needed, which asset or application is in scope, what approval path was used, and how long the access should exist. That is especially important for NHIs, because the control objective is not just assignment, but lifecycle closure from issuance to rotation to revocation. NHI Mgmt Group’s Ultimate Guide to NHIs notes that many organisations still lack full visibility into service accounts, which makes disconnected workflows a structural risk.
A practical implementation usually includes:
- Request capture in ITSM with mandatory business justification, owner, system, and expiry date.
- Policy check at approval time, using role, attribute, or entitlement rules before any provisioning occurs.
- Automated fulfilment in IGA or downstream connectors so the ticket does not become the control itself.
- Scheduled recertification that returns entitlement status to the same governance record.
- Revocation triggers for transfers, terminations, expired approvals, and application decommissioning.
Current guidance suggests the workflow should also record evidence in a form auditors can trace without manual reconstruction. That means avoiding duplicate entry between ITSM and IGA whenever possible, and using a shared identity object or event stream to keep systems in sync. For broader control alignment, the NIST Cybersecurity Framework 2.0 supports this kind of coordinated governance across access, asset, and monitoring functions. These controls tend to break down when organisations rely on custom integrations across highly federated application estates because ownership, connector health, and entitlement mapping quickly become inconsistent.
Common Variations and Edge Cases
Tighter workflow integration often increases change-management overhead, so organisations must balance faster fulfilment against the risk of automating a bad approval model. Not every entitlement should follow the same path. Low-risk standard access can be fully automated, while privileged access, shared credentials, and externally exposed NHIs may require stronger verification, separate approval chains, or time-bound issuance. Best practice is evolving here, and there is no universal standard for how much should be automated without human review.
Edge cases usually appear in environments with multiple HR sources, mergers, legacy directories, or application owners who insist on local admin control. In those settings, lifecycle automation should prioritise authoritative sources, not convenience. If an ITSM request creates an entitlement but no downstream ownership record exists in IGA, the process is incomplete. If recertification happens only in IGA but the original ticket lacks business context, the audit trail is weakened. The most common failure pattern is not missing technology but inconsistent identity data, which leads to duplicate records, stale approvals, and revocation delays. That is why the lifecycle model should be tested against offboarding, contractor expiry, and application retirement before it is declared operationally mature.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Lifecycle controls are central to preventing orphaned and overexposed NHI access. |
| CSA MAESTRO | Agent and workload governance depends on integrated identity lifecycle controls. | |
| NIST AI RMF | Lifecycle oversight supports accountable, traceable AI and workload governance. | |
| NIST CSF 2.0 | PR.AC-1 | Access control requires coordinated request, approval, and provisioning flows. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management directly covers joiner, mover, leaver lifecycle execution. |
Treat workflow integration as a governance requirement for all autonomous workload identities.
Related resources from NHI Mgmt Group
- How should healthcare organisations improve identity and access management for frontline and clinical users across shared devices and mobile workflows?
- What is the difference between runtime protection and NHI lifecycle management?
- How should organisations govern access when identity controls are spread across IGA, AM, and PAM?
- How should organisations automate identity lifecycle management without losing control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org