Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that identity governance is…
Governance, Ownership & Risk

What are the signs that identity governance is too hard for approvers to use?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Common signs include pending requests that sit untouched, senior approvers who rarely complete reviews on time, and mobile users who wait until they are back at a laptop. Those symptoms usually point to workflow friction, not policy failure. If people cannot act quickly, governance will drift.

When approvers are struggling, what does the workflow tell you?

The clearest signal is not usually a policy exception, it is a path people avoid. If requests linger in queues, approvers defer action until they have more time, or they only complete reviews when they are already at a desktop, the process is asking for more attention than the business can reliably give. That is a usability problem in governance, not a disagreement with the policy.

In practice, overloaded approvers start to create a shadow process: they batch approvals, delegate informally, or approve without context just to clear the queue. Those behaviours are important because identity governance only works when the review step is quick enough to fit real work patterns.

A useful comparison is the difference between a control that is technically correct and one that is operationally usable. An access review that requires too many clicks, too much context switching, or too much manual decision-making may still look compliant on paper, but it will not survive day-to-day use.

Which signs show the approver experience is too heavy?

The most reliable signs are behavioural. People stop responding promptly, review cycles slip past their due dates, and certain approver groups become chronic bottlenecks because they are difficult to reach or too busy to complete every request. When this happens repeatedly, the problem is usually not lack of intent, it is too much friction at the point of decision.

Another sign is channel mismatch. If mobile users consistently wait for a laptop, if managers need multiple tabs to understand one request, or if approvers cannot make sense of the context from the notification alone, the workflow is not aligned to how decisions are actually made. The stronger the friction, the more likely people are to postpone the decision or treat it as routine noise.

Over time, that creates governance drift. Approval becomes something that happens late, inconsistently, or with limited scrutiny, and the quality of the control falls even when the policy text remains unchanged.

What usually causes that friction in identity governance?

Friction usually comes from one of four places: too much context, too many decisions, too little time, or too many handoffs. Approvers may be asked to judge entitlements they do not understand, compare requests against role structures that are hard to interpret, or validate access across systems that do not present a single clear view.

Workflows also become hard to use when they combine high-volume review with low-value detail. If approvers must inspect every request individually but receive little risk context, they cannot separate routine items from genuinely sensitive ones. That is where access reviews and certification design matter, because review quality depends on both decision speed and decision quality.

At the governance layer, the same friction often appears when role design, segregation rules, or lifecycle handling are too complex for the audience doing the approving. A process that only specialists can use is not scalable governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingDelayed approvals need monitoring and review signals to spot control drift.
AC-2 — Account ManagementApprover friction directly affects account and entitlement governance workflows.
Recommendation — Track approval latency and escalate repeated review delays as a control effectiveness issue. Streamline account and entitlement approval paths so reviews finish within operational deadlines.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlIdentity governance approvals are part of access control execution and oversight.
Recommendation — Reduce approval friction so access control decisions remain timely and enforceable.
CIS Controls v8CIS-5 — Account ManagementAccount approval delays weaken operational control over user and privileged access.
Recommendation — Simplify approval workflows and monitor queues for repeated bottlenecks.
ISO/IEC 27001:2022A.5.15 — Access controlAccess decisions must be governable in practice, not just documented in policy.
Recommendation — Ensure approval processes are usable enough to support consistent access control decisions.

Practitioner Guidance

What to prioritise: Start with the approval path that blocks the most business activity, then look at where approvers most often stall. Measure time to approve, abandonment, and late completion by approver group so you can separate rare exceptions from structural friction.

What to verify: Check whether approvers can decide from the notification itself, whether the request carries enough business context, and whether the approval action works on the devices people actually use. If the answer is no, usability is already weakening control performance.

Common mistake: Teams often respond to slow approvals by adding more reminders or stricter deadlines. That can increase pressure, but it does not remove the underlying friction that caused the delay.

Practitioner takeaway: Treat repeated approval delay as a control-design signal. If the workflow is hard enough that approvers consistently defer it, the governance model is too complex for the operating rhythm it is meant to support.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org