Because neither protocol decides whether access should exist, only how a session or account change is carried out. SAML can confirm a login, and SCIM can move account data, but governance must determine whether the entitlement is still valid, whether approvals are required, and whether separation of duties rules are being met over time.
Why Identity Governance Still Matters After SAML and SCIM
SAML and SCIM solve important plumbing, but they do not decide whether a person or service should keep access, whether an entitlement is still justified, or whether a control exception has expired. identity governance fills that gap by defining ownership, approval, review, and revocation decisions over time. Without it, organisations can automate account creation and login while still accumulating stale access, excessive privilege, and segregation-of-duties conflicts.
That distinction matters because identity risk is usually lifecycle risk, not just provisioning risk. A clean login flow can still coexist with outdated group membership, orphaned accounts, or access that was valid at hire time but no longer matches the role, project, or regulatory duty. Current guidance also treats access review and entitlement attestation as distinct control functions, not side effects of federation or directory sync. For a practical overview of the lifecycle side of this problem, see Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs.
In practice, many security teams discover the gap only after a joiner-mover-leaver event, an audit exception, or a privilege review reveals that the account was technically managed but never actually governed.
How SAML and SCIM Fit Into the Governance Stack
SAML and SCIM are execution mechanisms. SAML authenticates and hands off identity assertions so a session can be established. SCIM synchronises account attributes, creates or updates identities, and can deprovision users in connected systems. Neither protocol answers the policy questions that matter most: who approved the entitlement, what business purpose it serves, when it must be revalidated, and whether it conflicts with another role or duty.
In a mature operating model, identity governance sits above the protocol layer and uses those protocols as enforcement channels. Governance defines the entitlement catalogue, approval workflow, recertification cadence, exception handling, and ownership model. SCIM then helps enact those decisions consistently across systems, while SAML helps ensure the authenticated session reflects the intended identity source. That separation is important because access can be technically current and still be wrong from a risk perspective. For background on the broader identity control problem, see Ultimate Guide to NHIs and the NIST Cybersecurity Framework 2.0.
- Use SAML to standardise authentication, not to grant lasting entitlement.
- Use SCIM to propagate lifecycle changes, not to decide business need.
- Use governance to approve access, review it periodically, and remove it when the justification ends.
- Use attestation and exception management to catch access that automation cannot judge safely.
Where this guidance breaks down is in highly dynamic environments with many entitlements, because provisioning can keep pace with change while human approval and review processes lag behind.
Where the Gaps Show Up in Real Environments
Stronger automation often reduces manual effort, but it also makes it easier to assume that managed equals governed. That tradeoff becomes visible when organisations have many apps, frequent role changes, or non-human identities that are synced but not continuously reviewed. In those environments, the main failure mode is not broken authentication; it is entitlement drift.
Common edge cases include delegated admin access, temporary project access that was never removed, and separation-of-duties conflicts that only appear when multiple systems are viewed together. Best practice is evolving toward continuous access evaluation, but there is no universal standard for how often every entitlement must be recertified or which exceptions may be tolerated. Organisations should therefore treat SAML and SCIM as necessary infrastructure and identity governance as the control that decides whether the resulting access remains defensible. For a control-oriented reference point, NIST SP 800-53 Rev 5 Security and Privacy Controls is useful for access review and account management expectations.
Practitioner takeaway: If the organisation cannot explain why an entitlement still exists, then federation and provisioning success do not equal governance success.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | SAML/SCIM-managed identities still need lifecycle control over machine access and entitlements. |
| Recommendation — Inventory and govern non-human credentials so provisioning does not become standing access. | ||
| CIS Controls v8 | 5 — Account Management | Governance is needed to review, revoke, and validate accounts beyond automated sync. |
| Recommendation — Review account ownership and disable stale access paths on a defined schedule. | ||
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication, and Access Control | The question is about whether access remains appropriate after authentication and sync. |
| GV.RM-01 — Risk Management Strategy | Identity governance addresses residual access risk that protocol automation cannot resolve. | |
| Recommendation — Apply access governance to verify that authenticated identities still have justified privileges. Set a governance cadence for entitlement review, exception expiry, and revocation. | ||
| NIST Zero Trust (SP 800-207) | AC-3 — Access Enforcement | SAML and SCIM enforce identity events, but access must still be policy-driven. |
| Recommendation — Enforce access decisions with policy so authentication events do not equal lasting permission. | ||
Related resources from NHI Mgmt Group
- Why do periodic access reviews still matter when organisations already have identity controls in place?
- What signals show that identity governance is still too user-centric?
- Why is it important to integrate identity and data governance?
- Should organisations prioritise external exposure or internal credential governance first?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org