Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do identity governance programmes still leave so…
Governance, Ownership & Risk

Why do identity governance programmes still leave so much manual toil in place?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Governance, Ownership & Risk

Identity governance programmes still leave toil because many environments combine long-tail applications, missing APIs, limited functionality in available APIs, and automation logic that is too simplistic for real operational decisions. Legacy automation also breaks down when applications were never designed for deep orchestration, so teams keep falling back to repetitive human intervention.

Why identity governance still leaves manual toil in place

identity governance programmes are usually built to answer entitlement questions, not to fully automate every operational decision. In practice, the hardest work sits in the exceptions: applications with weak APIs, inconsistent entitlement models, approval chains that depend on business context, and joiner-mover-leaver workflows that do not map cleanly to a single policy. That is why teams often automate the obvious parts and leave the messy edge cases to humans.

Long-tail systems are the main drag. Many were never designed for orchestration, so governance tools can discover access but cannot reliably change it without brittle scripts, ticket handoffs, or compensating controls. Where the access model is opaque, teams also need human review to decide whether a request is legitimate, whether a removal will break a process, or whether a privileged role is actually a shared operational function. The result is that identity governance becomes a control layer with a manual backstop rather than a fully closed loop.

That pattern is common across NHI and human identity environments alike, and the same governance gap shows up when organisations cannot maintain basic lifecycle discipline. NHIMG research on NHI operations notes that 71% of non-human identities are not rotated within recommended time frames, which is a reminder that policy intent and operational execution often diverge when automation is incomplete. In practice, many security teams discover the toil only after repeated exceptions have already become the normal way work gets done.

How the manual work shows up in real operations

Manual toil usually appears in four places: access requests, approvals, reconciliations, and remediation. Requests need manual enrichment because the requester often cannot describe the exact entitlement in system terms. Approvals need people because the decision depends on business purpose, separation-of-duties conflicts, or whether temporary access is justified. Reconciliations need humans because entitlements drift across directories, SaaS apps, and custom systems. Remediation needs humans because revoking access may require coordination with application owners or release windows.

Automation breaks when the identity governance platform can only see part of the truth. A workflow may know that access exists, but not whether it is tied to a service account, a batch job, a delegated admin role, or an application-specific object that has no reliable API. In those environments, the control plane becomes partially informational and partially procedural. Teams then rely on tickets, spreadsheets, and manual attestations to bridge gaps the tooling cannot close.

This is why the question is not simply “why not automate more?” It is “what decision can be standardised without creating business breakage or false confidence?” For some access changes, a deterministic policy is enough. For others, the right control is a tighter human approval path with better evidence, not a weaker automation promise. The practical boundary is where the system can execute safely without needing interpretation. Current guidance suggests using the available control surface rather than forcing one uniform workflow across every application.

  • Use automation for repetitive, well-bounded actions such as provisioning, deprovisioning, and periodic recertification where the entitlement model is stable.
  • Keep humans in the loop where the access meaning is context-dependent, such as emergency access, shared accounts, or critical production roles.
  • Instrument the workflow so every manual exception becomes measurable technical debt, not an invisible normal state.

For broader identity governance patterns, the Ultimate Guide to NHIs is useful because it frames lifecycle, visibility, and revocation as operational controls rather than abstract policy goals. These controls tend to break down when the application estate is fragmented, because the governance platform cannot enforce decisions consistently across systems that expose different levels of automation.

Where teams should draw the automation boundary

Tighter automation often reduces repetitive work, but it also increases the cost of getting the policy wrong, so organisations need to balance throughput against assurance. The boundary should be drawn around decision quality, not around the desire to eliminate tickets. If the system can confidently classify the request and execute safely, automate it. If the system cannot understand the access context or cannot reverse the action cleanly, keep a human decision point.

What to prioritise: Focus first on the workflows that create the most repeated effort with the least decision value, such as standard joiner and leaver actions, simple role assignments, and evidence collection for access reviews.

What practitioners underestimate: Manual toil often persists because it is compensating for bad data, weak ownership, or poor application design, not because teams are reluctant to automate. Until those root conditions change, adding another workflow layer usually just moves the manual work somewhere less visible.

Practitioner takeaway: The goal is not zero human involvement; it is to reserve human judgment for genuinely ambiguous access decisions and remove humans from routine, repeatable ones.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v85 — Account ManagementIdentity governance toil is driven by account lifecycle drift and exception handling.
6 — Access Control ManagementManual approvals and entitlement cleanup reflect weak access control enforcement.
8 — Audit Log ManagementGovernance teams need evidence to track manual exceptions and remediation gaps.
Recommendation — Standardise account lifecycle workflows and eliminate unmanaged manual exceptions. Enforce least-privilege access and review exceptions that require human approval. Retain audit evidence for approval, provisioning, and revocation actions.
NIST CSF 2.0PR.AC — Access ControlThe topic centers on governing who gets access and how access changes are controlled.
PR.DS — Data SecurityAccess to identity data and entitlement records affects how safely governance can operate.
DE.CM — Continuous MonitoringToil persists when teams cannot see drift, failures, and unhandled exceptions in real time.
Recommendation — Implement access governance rules that distinguish routine changes from exception cases. Protect identity and entitlement data so governance decisions use reliable records. Monitor entitlement drift and workflow failures to surface manual backlogs early.
NIST AI RMFMAP — MapGovernance automation depends on understanding system context, owners, and decision paths.
MEASURE — MeasureProgrammes need metrics for manual effort, exception rate, and control effectiveness.
MANAGE — ManageIdentity governance needs ongoing control tuning when automation does not fit every system.
Recommendation — Map identity workflows, ownership, and exception paths before automating decisions. Measure exception frequency and manual effort to identify where governance automation fails. Use measured exceptions to adjust governance controls and reduce avoidable manual work.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org