Average return measures total output relative to total input across the whole range, while marginal return measures the extra output gained from one more unit of input. In optimization, marginal return drives the correct allocation decision. Two subsystems can have very different averages but still be equally attractive at the margin, which is what determines the optimal mix.
Why the marginal view wins in optimization
Average return is useful for describing how efficient a subsystem has been over a whole operating range, but optimization decisions are made at the margin. The practical question is whether one more unit of input creates more output than the next best place to put that input. That is why two subsystems can show very different averages and still be equally good, or equally bad, for the next allocation decision.
In system design, average return often hides diminishing returns, fixed-cost effects, and uneven capacity. A subsystem with a strong average can still be a poor destination for additional resources if its marginal return has already fallen. A weaker-looking subsystem can be the right choice if the next increment still produces more value than the alternative.
When comparing options, practitioners should separate descriptive efficiency from decision efficiency. Average return answers “how well has this performed overall?” Marginal return answers “where should the next unit go?” That distinction matters whenever resources are scarce, inputs are divisible, or different subsystems compete for the same budget, compute, attention, or time.
For a broader reference on the non-human side of system allocation, the Ultimate Guide to NHIs is useful because it frames lifecycle and governance issues around machine-scale assets that often accumulate hidden cost and risk as they grow. Its visibility and rotation findings also show why whole-population averages can look acceptable while the marginal control gap remains large. NHI Mgmt Group’s data point that only 5.7% of organisations have full visibility into service accounts is a reminder that aggregate comfort can mask the next unit of exposure.
Where average return misleads system design
Average return is most likely to mislead when the system has fixed overhead, thresholds, or non-linear scaling. A subsystem may need a minimum input before it becomes productive, which can make its average look poor early on even though the marginal return improves once it is operating in range. The reverse also happens: an initially efficient subsystem can saturate quickly, making later inputs wasteful.
This is why average return is best treated as a summary metric, not an allocation rule. It helps you compare long-run efficiency, spot waste, and understand historical performance, but it does not tell you where the next input creates the most value. Marginal return is the control signal for optimization because it reflects the incremental consequence of a decision at the current state of the system.
In practical terms, the decision maker should ask whether the next unit changes capacity, quality, latency, throughput, or some other binding constraint. If it does, the marginal effect may be positive even when the average looks unimpressive. If it does not, the average may still be attractive while the marginal effect is already close to zero.
Related lifecycle and allocation issues are a common theme in resource-heavy identity estates, and the Touchpoints Between AI and Non-Human Identities is a useful navigation point when autonomous systems are part of the allocation picture. It helps explain why additional access, tooling, or delegated capacity should be judged at the margin, not by the overall apparent productivity of the system that uses it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 — Outcomes and Performance Measurement | Marginal return is a performance signal used to prioritize resources. |
| GV.RM-01 — Risk Management Strategy | Allocation should shift to the highest marginal gain under constraints. | |
| Recommendation — Measure incremental security value so resources follow the highest-return control changes. Allocate limited resources to the controls that reduce the most risk per added unit. | ||
| CIS Controls v8 | 5 — Account Management | Optimization often depends on where the next control effort most reduces access risk. |
| Recommendation — Prioritize the account controls that deliver the greatest incremental reduction in exposure. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | NHI resource allocation benefits from judging the next control by incremental risk reduction. |
| Recommendation — Direct effort toward the NHI control gap with the largest marginal risk reduction. | ||
Practitioner Guidance
What to prioritise: Use marginal return whenever you are choosing between competing uses of the next unit of input. Average return can describe the system, but it should not decide the next allocation unless all marginal options are effectively equal.
What to verify: Check whether the subsystem has fixed startup costs, saturation, or threshold behaviour. Those conditions often make average return and marginal return diverge sharply, which is exactly when allocation mistakes become expensive.
Trade-off: Optimising for marginal return can make the system look less “fair” or less evenly balanced in the short term, because the best current increment may go to the already stronger subsystem. The right test is not symmetry, it is whether the next unit produces the greatest net gain.
Practitioner takeaway: If the question is about where to place the next unit of input, treat average return as context and marginal return as the decision rule.
Related resources from NHI Mgmt Group
- What is the difference between agent skills and a large system prompt?
- What is the difference between red teaming an AI system and proving it is safe?
- What is the difference between system instructions and user prompts in AI security?
- What is the difference between identity inventory and a dynamic system of record?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org