Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do organisations underestimate the cost of manual…
Cyber Security

Why do organisations underestimate the cost of manual ticket handling in identity and access operations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

Teams often use salary instead of the true hourly cost, and calendar time instead of actual technician touch time. That understates labour, overhead, and delays caused by repeatable work. In identity operations, small tickets still consume expensive staff time, and high ticket volume turns that hidden effort into a recurring operating cost that automation can reduce.

Why This Matters for Security Teams

Manual ticket handling is often treated as a low-risk administrative function, but in identity and access operations it is usually a core control plane. Every access request, password reset, entitlement change, and exception approval consumes analyst time, introduces queue delays, and creates review overhead. That makes the cost problem both financial and operational: spend is hidden in labour allocation, and risk is hidden in the lag between request and fulfilment. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls reinforces that identity processes need repeatable, auditable control execution, not ad hoc handling.

Security teams also underestimate the knock-on effects. A ticket is rarely just one action. It may require verification, approval routing, fulfilment, logging, exception management, and post-action review. When those steps are manual, the real cost includes context switching, rework, and delays that affect provisioning accuracy and user productivity. In environments with privileged access, service accounts, or non-human identities, the same pattern becomes more expensive because the access decision is more sensitive and the approval chain is usually longer. In practice, many security teams encounter the true cost only after backlogs, SLA breaches, or audit exceptions have already accumulated, rather than through intentional cost measurement.

How It Works in Practice

The most common error is to price a ticket using only salary or help desk rate cards. That misses overhead, management time, queue latency, escalation handling, and the cost of follow-up work when requests are incomplete. A better model measures the full lifecycle of each identity task: intake, validation, approval, fulfilment, notification, reconciliation, and exception handling. For identity operations, those steps are often spread across IAM, security, service desk, and application owners, so the labour cost is fragmented and easy to undercount.

Practitioners usually see the real cost by classifying work into repeatable categories and measuring actual touch time rather than calendar elapsed time. Typical examples include:

  • Access requests that require multiple approvers or application owner review
  • Password resets and MFA recovery that trigger verification checks
  • Joiner, mover, leaver events that need updates across several systems
  • Privileged access grants that require time-bound approval and audit evidence
  • Non-human identity onboarding where secrets, certificates, or API keys must be issued and tracked, which aligns closely with the OWASP Non-Human Identity Top 10

Automation changes the economics by removing repetitive manual work, but only if the process is standardised first. If the underlying workflow is inconsistent, automation simply accelerates bad practice. The strongest cost reductions usually come from policy-based provisioning, self-service for low-risk requests, approval routing based on risk, and better integration between identity governance and ticketing systems. Current guidance suggests that control design should preserve traceability, because reduced manual effort should not mean weaker evidence or less accountability. These controls tend to break down when applications have inconsistent entitlement models, because fulfilment then depends on bespoke exceptions rather than standard workflow.

Common Variations and Edge Cases

Tighter automation often increases governance effort at the start, requiring organisations to balance lower run costs against policy design, integration work, and change management. That tradeoff is especially visible in regulated environments, where teams may keep manual approval steps for privileged access, finance systems, or sensitive customer data even when the ticket itself looks simple.

There is no universal standard for this yet, but best practice is evolving toward risk-tiered handling. Low-risk requests can often be automated or self-serviced, while high-risk requests still need human review, segregation of duties, and stronger evidence capture. The cost model also changes for organisations with many third-party contractors, distributed cloud platforms, or machine identities. In those cases, manual handling is more expensive because identity context is fragmented across directories, SaaS platforms, and infrastructure tooling.

Another edge case is audit-heavy environments. Some teams assume that manual review is cheaper because it feels safer, but the hidden cost appears in repeat evidence collection, reviewer fatigue, and delayed fulfilment. The better question is not whether a ticket was touched by a human, but whether the human touch added security value. For high-volume identity operations, that distinction usually drives the business case for automation and the control design needed to support it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.ACIdentity ticket handling affects access provisioning and least-privilege enforcement.
NIST AI RMFAutomation decisions should be governed for risk, accountability, and operational impact.
OWASP Non-Human Identity Top 10Manual handling of machine identities often creates secret sprawl and weak lifecycle control.
NIST SP 800-53 Rev 5AC-2Account management controls rely on consistent, auditable identity operations.

Standardise NHI issuance, rotation, and revocation so tickets do not become a hidden control dependency.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org