They need both, but identity governance should own the enforcement path. Privacy teams define the lawful basis and user-facing choices, while IAM and CIAM teams ensure those choices propagate into access, sharing, and retention controls. Separate ownership without shared policy logic usually creates gaps.
Why This Matters for Security Teams
Preference centers look like a privacy feature, but they become a security control the moment a user choice affects who can access data, which systems can share it, or how long it is retained. That is why ownership split cleanly between policy intent and enforcement path is the real question. Privacy teams usually define lawful basis, consent language, and user experience, while identity governance and IAM teams must ensure those choices propagate into entitlements, API calls, and downstream retention rules.
When the policy logic lives in one place and enforcement lives in another, drift is common. A user may opt out in a privacy portal while service accounts, marketing automations, or agentic workflows continue using stale permission state. That gap is exactly where breaches and compliance failures start. NHI governance research shows why this matters: the 2024 ESG Report: Managing Non-Human Identities found 72% of organisations have experienced or suspect a breach involving non-human identities. Current guidance from the NIST Cybersecurity Framework 2.0 also points toward shared accountability across governance, protection, and monitoring.
In practice, many security teams only discover preference-center drift after a data subject request, audit finding, or unauthorized sharing event has already occurred.
How It Works in Practice
The most defensible operating model is split ownership with one shared policy layer. Privacy operations should own the lawful basis, notice content, consent language, and jurisdiction-specific rules. Identity governance should own the control plane that turns those decisions into enforceable actions across IAM, CIAM, SaaS, data platforms, and non-human identities. That means the preference center cannot be treated as a standalone web form. It must feed a policy engine that updates access decisions, communication rights, token scopes, data-sharing rules, and retention workflows in near real time.
Practically, this works best when every change is translated into machine-readable policy and then enforced at the point of use. For example, a marketing opt-out should suppress campaign tooling, revoke related API permissions, and prevent downstream workflow automation from reusing the individual’s data. The same principle applies to NHIs and agents that act on behalf of users or business processes. If a preference changes, the related workload identity, secrets, and delegation chain need to be re-evaluated. The 2026 Infrastructure Identity Survey shows why this is urgent: 69% of security leaders say identity management must fundamentally shift for agentic AI systems, and 67% still rely heavily on static credentials despite the risk.
- Define consent, legal basis, and user-choice rules in privacy operations.
- Translate those rules into enforceable identity and access policy.
- Propagate changes into CIAM, IAM, PAM, data-sharing, and retention systems.
- Log every state transition so auditors can trace intent to enforcement.
The NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it treats privacy and security as coordinated control objectives, not isolated functions. These controls tend to break down when preference changes are managed manually across disconnected systems because revocation latency creates a window where old choices remain active.
Common Variations and Edge Cases
Tighter preference enforcement often increases operational overhead, requiring organisations to balance user trust and compliance against integration complexity and change-management cost. That tradeoff becomes sharper in regulated environments where consent, legitimate interest, and contractual necessity can all apply to the same person or dataset. Current guidance suggests there is no universal standard for this yet, so the right answer is usually policy-driven design rather than a single ownership model.
One common edge case is when a preference center controls both human communications and machine-triggered sharing. In that situation, privacy teams may still own the meaning of the choice, but identity governance should own the enforcement path because automated systems do not interpret intent reliably. Another case is delegated administration, where business users can update preferences for clients, employees, or households. That requires stronger authorization, auditability, and segregation of duties than a normal self-service portal.
Where agentic workflows are involved, the risk is higher because an autonomous process can continue acting with cached permissions after a user has withdrawn consent. That is why many organisations now treat preference-state changes like security events, not just UX updates. The Ultimate Guide to NHIs — Regulatory and Audit Perspectives is especially relevant when teams need to show how a policy decision moved from privacy intent into enforcement evidence. In short, preference centers belong in both domains, but identity governance should own the control path when the question is who can act on the choice.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC | Sets shared governance and policy ownership for privacy-to-enforcement workflows. |
| NIST SP 800-63 | AAL | Preference changes need strong identity assurance before access or consent state is altered. |
| NIST AI RMF | GOVERN | Agentic systems can apply or ignore preference state unless governance is explicit. |
| OWASP Non-Human Identity Top 10 | NHI-04 | Preference drift often persists through unmanaged non-human identities and stale permissions. |
| CSA MAESTRO | MAESTRO-2 | Agent workflows need runtime policy enforcement when user choices change. |
Require appropriate assurance before allowing preference updates that change access rights.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org