Join our Newsletter — 33% off our NHI Course
Home› Guides› Identity Security Programme Guide
Guide Governance, Risk & Compliance

Identity Security Programme Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 4 min read
On this page

Identity security is no longer a set of separate projects for SSO, access reviews and password vaults. It is a programme that spans employees, contractors, customers, service accounts, workloads, API keys and AI agents, across dozens of platforms and teams. Many organisations still run these as disconnected efforts with different owners, budgets and tools, which leaves gaps exactly where attackers look. This guide sets out how to structure an identity security programme: scope, operating model, roles and responsibilities, roadmap, funding and governance.

Key takeaways

  • Scope the programme to all identity types: workforce, customer, non-human and AI agent.
  • Define a clear operating model: who sets policy, who builds and runs platforms, who owns identities and who assures controls.
  • Build the roadmap from risk and maturity, not from product purchases.
  • Fund the programme as a long-term capability with measurable outcomes, not a series of one-off projects.
  • Report to leadership in business risk terms with a small set of meaningful metrics.

Programme scope

DomainIncludesRelated guides
Workforce identitySSO, MFA, lifecycle, access reviewsWorkforce Identity, JML
Privileged accessAdmin accounts, JIT, session management, break-glassPAM, JIT
Identity governanceRoles, requests, certifications, SoDIAM and IGA Basics
Non-human identityService accounts, keys, secrets, certificates, workload identityUltimate Guide to NHIs
AI agent identityAgent registration, delegation, authorisation, monitoringAgentic AI Identity
Customer identityRegistration, authentication, account takeover, consentCIAM
Identity threat detectionITDR, posture management, visibilityITDR, ISPM

Operating model

Roles and responsibilities

ActivityCISO / securityIAM teamPlatform and cloud teamsApplication and identity ownersRisk, audit, compliance
Identity policy and standardsAccountableResponsibleConsultedInformedConsulted
Identity platforms (IdP, IGA, PAM, secrets)InformedAccountable and responsibleConsultedInformedInformed
Workload and cloud identity implementationConsultedConsultedAccountable and responsibleConsultedInformed
Access approval and reviewInformedResponsible (process)InformedAccountableConsulted
NHI and agent ownershipInformedResponsible (process)ResponsibleAccountableInformed
Identity threat detection and responseAccountableConsultedConsultedInformedInformed
Control assurance and auditConsultedConsultedConsultedConsultedAccountable

Adapt the model to your organisation; the key is that every activity has a clearly accountable owner.

Centralised, federated or hybrid

  • Centralised: one IAM team builds and operates everything. Consistent, but can become a bottleneck.
  • Federated: business and platform teams implement identity controls against central standards. Scales better, but needs strong governance.
  • Hybrid (common): central team owns policy and core platforms; platform teams own workload identity and NHIs in their domains; application owners own access decisions.

Building the roadmap

  1. Assess: maturity across domains, current risks, audit findings and incidents. See the Identity Security Maturity Model.
  2. Prioritise by risk: typically phishing-resistant MFA for admins, privileged access reduction, NHI discovery and secrets, leaver processes and agent governance.
  3. Sequence dependencies: inventory and ownership before governance; authoritative sources before automation.
  4. Plan in phases: quick wins in the first quarter, foundational capabilities over the first year, optimisation afterwards.
  5. Define outcomes: each initiative has measurable risk reduction targets. See the Identity Security Metrics Guide.

Funding

  • Build the case on risk reduction, audit and regulatory requirements, operational efficiency and enablement of business initiatives such as AI adoption. See the Business Case Guide.
  • Fund platforms and the people to run them; tooling without operating capacity fails.
  • Allocate budget for application integration, often the largest hidden cost.

Governance

  • An identity steering group with security, IT, platform, business and risk representation.
  • Regular reporting to the CISO and risk committee; periodic board briefings.
  • Standards and exceptions process with expiry dates.
  • Alignment with regulatory obligations. See the Identity Security Regulatory Map.

Common failure patterns

  • Programme scoped to workforce only, leaving NHIs and agents unowned.
  • Tool-led roadmaps that buy platforms before defining processes and owners.
  • No accountable owner for identities created by platform and development teams.
  • Metrics that measure activity (reviews completed) rather than outcomes (access removed, risk reduced).

Practitioner checklist

  • Define programme scope across workforce, privileged, customer, non-human and AI agent identity.
  • Agree an operating model with clear accountability for every activity.
  • Assess maturity and build a risk-prioritised, phased roadmap.
  • Fund platforms, people and integration effort.
  • Establish governance, standards and exception processes.
  • Report outcome-based metrics to leadership.

How NHI Mgmt Group can help

We support programme initiation, maturity assessments, roadmaps and business cases for identity, NHI and agentic AI security. Contact us, or see our services.

Related NHI Mgmt Group resources: Identity Convergence Guide · Identity Security Maturity Model · Governing the Invisible · IAM and IGA Basics

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org