Identity security is no longer a set of separate projects for SSO, access reviews and password vaults. It is a programme that spans employees, contractors, customers, service accounts, workloads, API keys and AI agents, across dozens of platforms and teams. Many organisations still run these as disconnected efforts with different owners, budgets and tools, which leaves gaps exactly where attackers look. This guide sets out how to structure an identity security programme: scope, operating model, roles and responsibilities, roadmap, funding and governance.
Key takeaways
- Scope the programme to all identity types: workforce, customer, non-human and AI agent.
- Define a clear operating model: who sets policy, who builds and runs platforms, who owns identities and who assures controls.
- Build the roadmap from risk and maturity, not from product purchases.
- Fund the programme as a long-term capability with measurable outcomes, not a series of one-off projects.
- Report to leadership in business risk terms with a small set of meaningful metrics.
Programme scope
| Domain | Includes | Related guides |
|---|---|---|
| Workforce identity | SSO, MFA, lifecycle, access reviews | Workforce Identity, JML |
| Privileged access | Admin accounts, JIT, session management, break-glass | PAM, JIT |
| Identity governance | Roles, requests, certifications, SoD | IAM and IGA Basics |
| Non-human identity | Service accounts, keys, secrets, certificates, workload identity | Ultimate Guide to NHIs |
| AI agent identity | Agent registration, delegation, authorisation, monitoring | Agentic AI Identity |
| Customer identity | Registration, authentication, account takeover, consent | CIAM |
| Identity threat detection | ITDR, posture management, visibility | ITDR, ISPM |
Operating model
Roles and responsibilities
| Activity | CISO / security | IAM team | Platform and cloud teams | Application and identity owners | Risk, audit, compliance |
|---|---|---|---|---|---|
| Identity policy and standards | Accountable | Responsible | Consulted | Informed | Consulted |
| Identity platforms (IdP, IGA, PAM, secrets) | Informed | Accountable and responsible | Consulted | Informed | Informed |
| Workload and cloud identity implementation | Consulted | Consulted | Accountable and responsible | Consulted | Informed |
| Access approval and review | Informed | Responsible (process) | Informed | Accountable | Consulted |
| NHI and agent ownership | Informed | Responsible (process) | Responsible | Accountable | Informed |
| Identity threat detection and response | Accountable | Consulted | Consulted | Informed | Informed |
| Control assurance and audit | Consulted | Consulted | Consulted | Consulted | Accountable |
Adapt the model to your organisation; the key is that every activity has a clearly accountable owner.
Centralised, federated or hybrid
- Centralised: one IAM team builds and operates everything. Consistent, but can become a bottleneck.
- Federated: business and platform teams implement identity controls against central standards. Scales better, but needs strong governance.
- Hybrid (common): central team owns policy and core platforms; platform teams own workload identity and NHIs in their domains; application owners own access decisions.
Building the roadmap
- Assess: maturity across domains, current risks, audit findings and incidents. See the Identity Security Maturity Model.
- Prioritise by risk: typically phishing-resistant MFA for admins, privileged access reduction, NHI discovery and secrets, leaver processes and agent governance.
- Sequence dependencies: inventory and ownership before governance; authoritative sources before automation.
- Plan in phases: quick wins in the first quarter, foundational capabilities over the first year, optimisation afterwards.
- Define outcomes: each initiative has measurable risk reduction targets. See the Identity Security Metrics Guide.
Funding
- Build the case on risk reduction, audit and regulatory requirements, operational efficiency and enablement of business initiatives such as AI adoption. See the Business Case Guide.
- Fund platforms and the people to run them; tooling without operating capacity fails.
- Allocate budget for application integration, often the largest hidden cost.
Governance
- An identity steering group with security, IT, platform, business and risk representation.
- Regular reporting to the CISO and risk committee; periodic board briefings.
- Standards and exceptions process with expiry dates.
- Alignment with regulatory obligations. See the Identity Security Regulatory Map.
Common failure patterns
- Programme scoped to workforce only, leaving NHIs and agents unowned.
- Tool-led roadmaps that buy platforms before defining processes and owners.
- No accountable owner for identities created by platform and development teams.
- Metrics that measure activity (reviews completed) rather than outcomes (access removed, risk reduced).
Practitioner checklist
- Define programme scope across workforce, privileged, customer, non-human and AI agent identity.
- Agree an operating model with clear accountability for every activity.
- Assess maturity and build a risk-prioritised, phased roadmap.
- Fund platforms, people and integration effort.
- Establish governance, standards and exception processes.
- Report outcome-based metrics to leadership.
How NHI Mgmt Group can help
We support programme initiation, maturity assessments, roadmaps and business cases for identity, NHI and agentic AI security. Contact us, or see our services.
Related NHI Mgmt Group resources: Identity Convergence Guide · Identity Security Maturity Model · Governing the Invisible · IAM and IGA Basics