Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should state and local governments govern access…
Governance, Ownership & Risk

How should state and local governments govern access in multi-cloud and hybrid work environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

State and local governments should use an identity-centric governance model that spans applications, systems, data, cloud services, endpoint, and remote work. The practical goal is to enforce consistent access controls, monitor usage, and remove excess privilege as work patterns change. This helps reduce blind spots created by cloud adoption, bring-your-own-device programs, and work from anywhere operations.

Why This Matters for Security Teams

State and local governments are managing more identities than ever, but the real risk is not volume alone. It is the spread of access across cloud services, agency applications, remote endpoints, and shared operational tooling without a single governance model. That creates blind spots in approval, review, and revocation, especially when staff move between offices, home networks, contractors, and temporary projects.

NHI Management Group’s 2024 Non-Human Identity Security Report found that 35.6% of organisations cite consistent access across hybrid and multi-cloud environments as their top NHI challenge. That aligns with broader guidance in the NIST Cybersecurity Framework 2.0, which emphasizes governance, asset visibility, and access accountability as continuous activities rather than periodic checks. For public sector environments, the issue is not just preventing unauthorized access. It is proving that access remains appropriate as missions, vendors, and work locations change.

In practice, many security teams encounter excessive privilege only after an audit finding, a compromised account, or a cloud misconfiguration has already exposed sensitive systems.

How It Works in Practice

An effective model starts with identity as the control plane. That means every access decision should be tied to who or what is requesting access, from where, for what purpose, and under what conditions. For state and local governments, that usually requires consistent policy across on-premises systems, SaaS, IaaS, VPN-less remote access, and endpoint-managed workstations. The goal is not one tool everywhere. The goal is one policy standard everywhere.

Current guidance suggests combining least privilege, strong authentication, and continuous review with lifecycle-based access governance. The OWASP Non-Human Identity Top 10 is useful here because many public sector environments now rely on service accounts, automation tokens, and API keys that outlive the work they were created for. The right operational pattern is to issue access only when needed, scope it narrowly, and revoke it automatically when the task ends.

  • Use a single identity source of truth for employees, contractors, service accounts, and privileged admins.
  • Apply role-based access only as a baseline, then layer context such as device health, network location, and sensitivity of the request.
  • Review standing privilege regularly and remove access that no longer matches job function, project assignment, or agency need.
  • Log and correlate access across cloud, endpoint, and application layers so reviewers can see actual use, not just granted entitlement.

NHI Management Group’s Lifecycle Processes for Managing NHIs research supports this lifecycle approach because standing access in multi-cloud environments tends to expand quietly over time. Public sector teams should treat identity governance as an operational control, not a quarterly cleanup exercise. These controls tend to break down when agencies rely on separate cloud teams, shared admin credentials, or exception-heavy remote work arrangements because no single owner can see the full access path.

Common Variations and Edge Cases

Tighter access control often increases administrative overhead, requiring organisations to balance tighter least-privilege enforcement against staffing limits, procurement delays, and legacy application constraints. That tradeoff is especially visible in local government, where older systems may not support modern federation, and in emergency operations, where rapid access may be needed for a short period.

Best practice is evolving for these edge cases. Some agencies use break-glass access for urgent scenarios, but it should be time-bound, heavily logged, and reviewed after use. Others need to keep legacy service accounts alive while they transition to modern identity federation, but those accounts should be isolated, monitored, and rotated. The Top 10 NHI Issues page is a useful reminder that secrets sprawl, weak lifecycle controls, and inconsistent ownership often matter more than the front-end access policy itself.

For hybrid work, a common failure mode is over-trusting managed devices while underestimating shared networks, contractor endpoints, and local administrator privileges. Public sector teams should also avoid treating cloud security groups as a substitute for identity governance. That can work for a narrow technical control, but it does not answer who should have access, why they have it, or when it should end. The model is strongest when agencies can connect policy, review, and revocation across every environment they operate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity governance across hybrid access maps to access control and accountability.
NIST SP 800-53 Rev 5AC-2Account management is core to provisioning, reviewing, and removing excess access.
OWASP Non-Human Identity Top 10NHI-01Hybrid and multi-cloud access depends on securing non-human identities and secrets.
CSA MAESTROMAESTRO addresses governance for agentic and distributed workloads in cloud environments.
NIST AI RMFAI RMF supports governance decisions when automated systems influence access paths.

Centralize identity governance and enforce least privilege across cloud, endpoint, and remote access paths.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org