Skip to main content
finger-print-being-scanned

Have we been solving the wrong IAM problems as an industry?

For more than a decade, identity programmes have largely been framed as technology initiatives. The conversation typically centres on replacing legacy tooling, deploying Identity Governance and Administration (IGA), implementing Access Management, modernising authentication or reducing technical debt.

These activities are important. However, they are not the primary reason most organisations struggle to achieve value from identity investments.

Recent Gartner research found that only 20% of IAM leaders successfully improve business agility while simultaneously minimising loss and disruption. More than half of organisations report increases in identity-related incidents, despite years of investment in IAM technology.

The problem is not a lack of tools. The problem is that IAM programmes are too often measured by technical delivery milestones rather than business outcomes.

Organisations celebrate:

  • Platform deployments
  • Application onboarding
  • Certification campaigns
  • MFA adoption rates
  • Provisioning automation

Yet boards are increasingly concerned with entirely different questions:

  • How quickly can we integrate acquisitions?
  • How quickly can we onboard talent?
  • Can we safely enable AI agents?
  • Can we demonstrate regulatory compliance continuously?
  • Can we prove accountability for access decisions?

These are not technology questions. They are business capability questions.

Identity is no longer simply concerned with workforce access. Modern organisations increasingly rely on identities to enable customers, partners, applications, services, workloads and AI agents. As the number and diversity of identities increase, so does the consequence of making poor decisions about governance, ownership and accountability. Organisations that continue to treat identity as a technology project will struggle to scale securely, whereas those that treat it as a business capability are better positioned to support digital transformation, operational resilience and AI adoption.

Gartner now describes IAM as both a business enabler and a cybersecurity imperative, elevating identity from a supporting technical function to a business-first mechanism central to digital transformation, resilience and security.

This shift fundamentally changes how identity programmes should be designed, measured and governed.

Why Identity Programmes Keep Creating More Technology and Less Value

One of the most revealing findings from Gartner’s IAM Leadership Survey is not the technology data.

It is the operating model data.

Nearly 60% of IAM leaders report regularly delaying strategic activities to address short-term business demands. Only 33% consistently consider user-centric measures such as adoption and satisfaction when making strategic decisions. Just 27% provide standardised IAM capabilities across their organisation.

Viewed another way, the majority of IAM functions are operating reactively. They are trapped in delivery cycles. Every urgent onboarding requirement. Every emergency access request. Every audit finding. Every exception process. Every application integration. Gradually pulls the programme further away from its intended strategic outcomes.

The result is an environment where IAM teams become exceptionally busy whilst struggling to demonstrate measurable business impact.

At Condatis, we increasingly see identity programmes suffering from a failure to convert evidence into accountable action.

The organisation often possesses abundant signals that underlying problems already exist:

  • Access ownership is unclear.
  • Critical applications have no accountable owner.
  • Manual approvals create delays.
  • Excessive permissions accumulate over time.
  • Exception processes become permanent.

Yet because these conditions have existed for years, they become accepted as normal. Technology is then introduced to address symptoms rather than causes.

The platform changes. The operating model does not.

This is why many organisations mistakenly believe they have a technology problem when they actually have an accountability problem. New platforms improve visibility, automation and policy enforcement, but they cannot answer fundamental questions that the organisation itself has failed to address:

  • Who owns identity data?
  • Who owns access decisions?
  • Who owns exceptions?
  • Who is accountable for governance outcomes?

Gartner’s research consistently highlights that successful IAM programmes align capabilities to measurable business outcomes and business priorities, rather than focusing solely on technical implementation. Organisations that do not establish those foundations often find themselves continuously deploying new tooling while achieving very little meaningful improvement.

Identity Data is the Constraint Nobody Wants to Talk About

Many identity programmes assume technology is the primary inhibitor to progress. In practice, identity data is often the largest constraint. Most organisations already operate multiple sources of identity information:

  • HR systems
  • Active Directory
  • Cloud directories
  • Line-of-business applications
  • Service management platforms
  • Partner directories

Over time these sources drift apart. Ownership becomes unclear. Accountability becomes fragmented. Data quality deteriorates. Yet modern identity platforms are entirely dependent on the integrity of the data they consume. Automating poor-quality identity data simply allows organisations to distribute poor decisions more quickly and at greater scale.

This becomes even more significant as organisations move towards:

  • automated provisioning
  • delegated access models
  • machine identities
  • AI agents

If the organisation cannot explain who owns a digital identity today, it will struggle even more to explain who owns the actions performed by an autonomous identity tomorrow. Technology can automate governance. It cannot create accurate identity data where none exists.

Technology Modernisation Is Not Transformation

One of the most common mistakes we see in identity programmes is the assumption that replacing a platform automatically improves the identity function. It rarely does. Identity migrations frequently preserve existing; access models, approval processes, ownership gaps, service accounts, governance exceptions and technical debt.

The organisation successfully migrates. The operating model remains unchanged. The result is often a modern platform operating with legacy assumptions. This is particularly visible in large-scale migration programmes where the pressure to deliver encourages teams to replicate current-state processes rather than challenge them.

A useful question for leadership teams is:

“What are we changing apart from the technology?”

If the answer is unclear, the programme may be delivering platform modernisation rather than genuine transformation. As Gartner notes, IAM programmes create the most value when strategies, governance structures, processes and business outcomes are clearly defined before technology implementation begins.

AI Is Not Creating A New Identity Problem, It Is Exposing Existing Ones

Much of the market conversation surrounding AI governance focuses on controlling AI agents.
Condatis believes this framing is incomplete. AI agents are not introducing fundamentally new identity challenges. They are exposing weaknesses that already exist.

Gartner’s 2025 Machine Identity survey found that 94% of organisations are experiencing growth in machine identities, driven largely by AI agents, automation and expanding workload ecosystems. Gartner now identifies AI Agent Identity, Workload Identity Management, Identity Security Posture Management and Workload Access Management as emerging strategic disciplines within modern identity programmes.

The significance of this shift should not be underestimated. For many organisations, machine identities already outnumber human identities. AI accelerates this challenge further. The consequence is that decisions about ownership, lifecycle management, delegated authority, least privilege and accountability become more important than ever. These are governance questions first and technology questions second.

Many organisations are already struggling to answer basic governance questions such as:

  • Who owns this account?
  • Why does this access exist?
  • Who approved it?
  • What evidence supports it?
  • When should it be removed?

If those questions cannot be answered for human identities, they become almost impossible to answer for autonomous AI actors operating at machine speed. The challenge is not simply controlling AI. The challenge is controlling delegated authority. Every AI agent ultimately receives authority from a human decision, business policy, access model and governance process.

An unmanaged AI agent is therefore rarely an AI problem, it’s usually a governance problem operating at a larger scale. This is why organisations pursuing AI initiatives without first understanding identity maturity often find themselves attempting to govern automation using processes that are already struggling to govern people.

Identity Is Becoming an Executive Accountability Function

Historically, IAM has frequently sat several layers below executive leadership. It was often viewed as a technical service concerned with accounts, passwords and directory administration. That model is rapidly becoming outdated. Boards routinely review financial, regulatory, operational and cyber risks. Yet many organisations cannot answer a surprisingly simple question:

"Who is accountable for the identities that operate across our organisation?"

This applies not only to employees but also to service accounts, applications, workloads, automation platforms and increasingly AI agents. As identity becomes the control plane for modern business operations, accountability for identity becomes an executive concern, not simply a technical one. Gartner describes identity-first security as a shift that places identity controls at the centre of enterprise security architecture and digital business. This fundamentally changes the role identity should play in governance discussions.

Modern IAM increasingly influences:

  • Cybersecurity effectiveness
  • Operational resilience
  • Regulatory compliance
  • Workforce productivity
  • Third-party access
  • Digital transformation
  • AI adoption

Gartner’s broader identity research now consistently positions IAM as the primary control plane for modern security and digital business. Identity-first security places identity controls at the centre of enterprise security architecture rather than treating them as supporting infrastructure.

This creates an important challenge for boards. Most boards already receive reporting on financial, operational, cyber and regulatory risk. Few receive reporting on identity risk despite identity increasingly underpinning them all.

The question for executive leadership is therefore no longer:

“Is our IAM platform modern?”

The question is:

“Can we demonstrate control, accountability and evidence for every digital identity operating inside our organisation?”

That includes people, machines and, that includes AI.

Conclusion

The identity industry has spent years discussing platforms, tooling and migrations. Those discussions remain important, but they are no longer sufficient. Identity has become a business capability, a security control, a governance function and increasingly a prerequisite for AI adoption.

Organisations that continue to approach identity as a technology project will likely continue measuring success through implementation milestones. Organisations that approach identity as an operating model will measure success through business outcomes.

Technology still matters, but technology is no longer the most important decision.

  • Governance is.
  • Accountability is.
  • Evidence is.
  • Outcomes are.
Let's talk.

Start your journey with a free briefing

Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.

Get started

Stay Ahead of Identity, Security & AI Governance

Practical insights, real-world experiences, new research, and exclusive event invitations from the identity specialists helping organisations navigate transformation with confidence.

Privacy Preference Center

Condatis
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.