For years, many Identity Governance and Administration (IGA) programs have been measured through familiar operational metrics: provisioning time, certification completion rates, approval volume, policy violations, and the number of accounts created or removed.
Those metrics have value, but they also reinforce an outdated way of thinking.
They assume governance happens at checkpoints. A user receives access, the access remains in place, and sometime later a manager or application owner is asked to confirm whether it is still appropriate.
That model made sense when source systems were updated in batches, applications were mostly on-premises, integrations were limited, and access decisions changed slowly.
It does not fit the modern enterprise.
Today, workforce status, organizational relationships, project assignments, contracts, risk signals, application usage, and non-human identities can change continuously. Identity governance must operate continuously as well.
The real issue is not whether organizations can create better measurements for stale access. The more important question is whether the identity architecture prevents access from becoming stale in the first place.
Fischer Identity has supported continuous, policy-driven identity lifecycle management for years. The platform was designed to keep identity and access data synchronized with authoritative business conditions, not simply to discover outdated access during the next quarterly review.
The Old Way of Thinking: Access Changes Between Reviews
Traditional IGA programs commonly operate around several assumptions.
The first is that access is granted at a specific point in time, usually during onboarding or through an access request.
The second is that the original approval remains valid until someone reviews it again.
The third is that business changes are detected through scheduled synchronization, ticket submissions, or certification campaigns.
The fourth is that the certification process serves as the primary mechanism for discovering access that is no longer appropriate.
This produces a familiar operating pattern:
- An identity receives access.
- The person’s job, project, affiliation, sponsorship, or risk profile changes.
- The IGA platform may not immediately receive or act upon the change.
- The access remains active.
- A quarterly or annual certification eventually identifies the issue.
- A reviewer requests removal.
- The target system is updated.
That is not continuous governance. It is delayed correction.
The industry has spent years attempting to improve that model through automated recommendations, risk scoring, campaign prioritization, and machine learning. Those capabilities may reduce reviewer effort, but they do not correct the underlying architectural weakness.
A better certification recommendation does not change the fact that inappropriate access may have remained active for weeks or months before the review began.
The Modern Model: Identity as a Continuous Control System
A modern IGA platform should function as a closed-loop control system.
The flow should look like this:
Authoritative source event → Identity correlation → Policy evaluation → Access decision → Provisioning or revocation → Target reconciliation → Audit evidence
When a business condition changes, access should be recalculated.
When an employment relationship ends, applicable access should be removed according to policy.
When a person changes jobs, access associated with the previous job should be reevaluated while access associated with the new job is applied.
When a project ends, project-specific access should expire.
When a contractor’s sponsorship lapses, the contractor identity should transition according to the organization’s defined lifecycle.
When a risk signal is received, the identity platform should be capable of initiating an appropriate governance action.
In this model, certifications remain important, but they are not the engine of lifecycle management.
Certifications validate policy, confirm ownership, address exceptions, support regulatory requirements, and provide human review where judgment is necessary.
They should not be the primary process used to discover routine lifecycle changes that could have been enforced automatically.
Fischer Identity Has Operated This Way for Years
Fischer Identity was built around identity lifecycle orchestration, policy evaluation, automation, and reconciliation.
Its approach does not begin with the question, “When should this access be reviewed again?”
It begins with a more useful question:
What business condition justified this access, and how should the access change when that condition changes?
That difference is fundamental.
Fischer Identity supports role-based, attribute-based, and policy-based access models that allow organizations to connect access directly to authoritative identity data and business context. Access can be assigned, modified, retained, or removed based on employment status, organizational assignment, affiliation, department, job, course enrollment, sponsorship, project participation, contract dates, or other governed attributes.
This is especially important in environments where individuals hold multiple concurrent relationships.
A person may be an employee and a student.
A physician may also be faculty, a researcher, and a contractor at an affiliated facility.
A student may become an employee without ceasing to be a student.
A contractor may later become a permanent employee.
A faculty member may retain one relationship while an administrative appointment ends.
Fischer Identity can manage these relationships under a single identity while evaluating each lifecycle independently. Access tied to one relationship can be removed without unnecessarily disrupting access tied to another.
That is continuous identity governance in practice.
Entitlement Drift Is Usually a Design Problem
Organizations often talk about entitlement drift as though access naturally becomes less appropriate over time.
Sometimes it does. But in a well-designed environment, the real question is why the access was permitted to drift at all.
A policy-derived entitlement is not unmanaged simply because a person has not manually reviewed it since the original grant. If the entitlement remains tied to an active, authoritative business condition and that condition is evaluated whenever relevant source data changes, the access remains governed.
The more useful distinction is not simply reviewed versus unreviewed.
A mature program should distinguish among:
- Birthright access assigned through policy
- Dynamic access based on current attributes
- Requested access approved by an owner
- Temporary access with an expiration date
- Exception access
- Privileged access
- Directly assigned access
- Orphaned or unowned access
- Access that cannot be mapped to a current business rule
- Access that exists in the target but not in the intended IGA state
That last category is especially important.
The true governance concern is not entitlement movement by itself. Organizations change. Applications change. People change roles. New systems are deployed. Legitimate access volume can increase.
The real concern is unexplained access, meaning access with no valid policy, role, request, sponsorship, owner, or business condition supporting it.
Fischer Identity’s policy and reconciliation model is designed to identify and manage that distinction.
Governance Lag Should Measure the Entire Control Loop
Another common discussion point is the time between an access state becoming inappropriate and the organization detecting and remediating it.
That is a useful measurement, but it should be interpreted correctly.
In a weak implementation, governance lag may measure the number of days between a job change and the next certification campaign.
In a mature Fischer Identity implementation, governance lag should measure the performance of the complete identity control loop:
- How quickly did the source system publish the change?
- How quickly did Fischer Identity consume it?
- How quickly was the identity correlated?
- How quickly was policy reevaluated?
- How quickly was the provisioning or deprovisioning action initiated?
- How quickly did the target system process the action?
- How quickly did reconciliation confirm the final state?
That decomposition makes the metric actionable.
A delay may originate in the HR system, a scheduled source feed, an approval workflow, a target connector, a legacy application, or the target system itself.
Simply saying the IGA program detected inappropriate access late does not identify the underlying control failure.
Fischer Identity’s experience at the University of Virginia illustrates the difference between checkpoint-oriented identity management and continuous lifecycle automation. UVA replaced a legacy environment that could not support real-time processing with Fischer Identity, enabling automated provisioning and deprovisioning, dynamic policy-driven access, real-time synchronization, and identity reconciliation across a highly complex population. The implementation now manages more than 180,000 active users and nearly two million identity accounts.
The platform also accommodated UVA’s transition from multiple HR systems to Workday HCM through configuration changes rather than a custom redevelopment effort. That matters because continuous identity depends on the ability to adapt governance logic as authoritative business systems and processes change.
Time-Boxed Access Is Better Than Measuring Stale Justification
Organizations often treat the original business justification for an access request as though it remains valid until a future review says otherwise.
That is a weak control model.
If an entitlement was granted because a person was assigned to a six-month project, the project end date should be part of the access policy.
If a contractor requires access through the end of a contract, the expiration date should be enforced.
If elevated access is required for a maintenance window, the grant should be temporary.
If a visiting researcher is sponsored for one year, the identity and associated access should require renewal or expire.
Fischer Identity supports time-bound access and policy-driven expiration outside of standard birthright provisioning.
Requested access can be configured with:
- Start dates
- End dates
- Maximum permitted duration
- Required renewal
- Sponsor validation
- Manager or application owner approval
- Automatic expiration
- Notifications before expiration
- Escalation when ownership changes
- Different rules based on entitlement risk
This does not eliminate the need for review.
It changes the role of review.
The system enforces the known lifecycle automatically. Human review is reserved for deciding whether the access should be renewed, whether an exception remains valid, or whether the policy itself should be changed.
That is stronger than allowing access to persist indefinitely and later asking whether the original request still makes sense.
Birthright Access and Requested Access Should Not Be Governed the Same Way
One reason many IGA programs become difficult to manage is that they treat all access as if it has the same governance model.
It does not.
Birthright access is derived from established organizational policy. If a person is an active employee, they may receive baseline directory, email, collaboration, and business-system access.
Requested access is different. It may depend on business need, project participation, elevated responsibility, training, application ownership, or temporary operational requirements.
Privileged access is different again.
External identity access may require sponsorship.
Non-human identity access may require a human owner, application owner, defined purpose, credential rotation policy, and usage validation.
Fischer Identity supports these different models without forcing every entitlement into the same review cadence.
Birthright access can remain continuously tied to authoritative lifecycle data.
Requested access can be approved, risk evaluated, time boxed, renewed, or revoked.
Exception access can carry a shorter duration and more frequent review.
Privileged access can require stronger controls.
External identities can have configurable ownership, expiration, grace periods, and renewal processes. Fischer Identity can also serve as an authoritative lifecycle source for populations that do not exist in a traditional HR or student system.
This is how governance should work. Control design should reflect the nature of the access.
Signal Consumption Should Drive Governance Actions
Another outdated assumption is that identity governance only responds to HR events and certification decisions.
Modern identity governance should consume signals from across the enterprise.
Those signals may include:
- HR or student-system changes
- Contractor or vendor lifecycle events
- Project completion
- Training expiration
- License consumption
- Application usage
- Account inactivity
- Authentication risk
- Device posture
- Credential compromise
- Security incident alerts
- Separation-of-duties violations
- Privileged activity
- SIEM events
- CASB findings
- Non-human identity behavior
- AI-generated risk indicators
A signal does not always need to produce the same response.
Depending on policy and risk, it may trigger:
- Immediate access removal
- Temporary suspension
- Step-up authentication
- A targeted access review
- Owner validation
- Credential rotation
- Notification
- Incident creation
- Workflow escalation
- Recalculation of dynamic roles
- Reassessment of an identity’s risk level
Fischer Identity is capable of consuming risk and business signals and applying policy-driven actions. Its design supports integration with AI-enabled source systems and the use of externally generated risk information to revoke access, initiate notifications, escalate incidents, or apply additional controls.
This is where continuous identity becomes more than fast provisioning.
It becomes continuous decision-making.
The IGA Platform Must Remain the System of Record for Governance
Authentication and authorization platforms make runtime decisions.
They determine whether a user can sign in, whether a device is trusted, whether a token should remain valid, or whether a session should be challenged.
Those controls are essential.
They do not replace IGA.
The IGA platform remains responsible for:
- Identity ownership
- Lifecycle state
- Account ownership
- Entitlement ownership
- Business justification
- Policy
- Role qualification
- Access request history
- Approval history
- Certification
- Expiration
- Exception management
- Provisioning
- Deprovisioning
- Reconciliation
- Audit evidence
The correct architecture is not IGA or runtime access control.
It is a continuous loop between them.
The IGA platform provides accurate identity, lifecycle, ownership, and entitlement state to the authorization layer.
The authentication and runtime layers provide risk, usage, and behavioral signals back to governance.
Fischer Identity can act as the governance and orchestration layer that connects those systems.
When governance data is continuously maintained, the authorization layer is not making decisions from stale identity information.
Runtime enforcement cannot compensate for inaccurate lifecycle governance. It can only make faster decisions using whatever identity and entitlement data it has been given.
Source Data Still Determines Governance Quality
Continuous identity depends on authoritative, timely, and accurate data.
An IGA platform cannot immediately revoke access for a terminated employee if the HR system does not publish the termination.
It cannot expire project access if no project end date exists.
It cannot properly transition a contractor if the contractor source has no owner, status, or expiration.
It cannot calculate job-based access correctly if job data is incomplete or temporarily removed during an HR transaction.
These are not merely technical integration concerns. They are business process design concerns.
Fischer Identity works with customers to identify authoritative sources, align business events, normalize identity data, define matching logic, and establish clear provisioning and deprovisioning triggers. The platform supports multiple source systems and advanced identity matching, but the strongest governance model still begins with accountable source data.
This is particularly important in highly configurable systems such as Workday HCM. Hire, job change, leave, and termination processes must be understood so that the identity platform can distinguish a true lifecycle event from a temporary state created during an HR transaction.
Continuous identity does not mean blindly reacting to every data change.
It means understanding the business meaning of those changes and applying the correct policy.
Reconciliation Completes the Governance Process
A provisioning request is not proof that access was changed.
The target system may have rejected the transaction.
A connector may have failed.
A manual administrator may have changed the account directly.
A legacy system may not support complete deprovisioning.
A cloud application may apply changes asynchronously.
For that reason, continuous governance must include reconciliation.
The IGA platform should compare the intended state against the actual target state and identify:
- Missing accounts
- Unexpected accounts
- Missing entitlements
- Excess entitlements
- Orphaned accounts
- Failed deprovisioning
- Direct changes made outside the governance process
- Accounts linked to the wrong identity
- Accounts with no accountable owner
Fischer Identity includes reconciliation as part of the lifecycle and governance model. This helps ensure that the target environment reflects the access state established by policy, not merely that a workflow attempted to make a change.
That distinction is critical.
A governance system that does not validate the target state cannot honestly claim that access is current.
Continuoce Extends to Non-us GovernanHuman and AI Identities
Much of the current industry discussion about non-human identities presents them as a new category that traditional IGA cannot govern.
That conclusion is often based on a narrow, workforce-only implementation model.
A non-human identity still has governance attributes:
- An owner
- A sponsor
- A purpose
- A target system
- An application or workload
- A credential
- A creation event
- An expected duration
- An entitlement set
- A risk classification
- A usage pattern
- A renewal requirement
- A retirement condition
An AI agent adds complexity, but the governance model remains recognizable.
The agent should be linked to an accountable human, business process, application, or organizational owner. Its accounts and entitlements should be governed. Its authority should be limited. Its lifecycle should be managed. Its access should not survive the purpose, project, deployment, or person that justified it.
Fischer Identity can govern these identities as first-class identity objects rather than leaving them outside the identity program.
The market may describe NHI and agentic governance as a new frontier. Fischer Identity’s underlying model, ownership, lifecycle, policy, provisioning, reconciliation, certification, and expiration, has supported these principles for years.
Better Metrics Still Matter
None of this means identity programs should reject better measurements.
They should improve them.
A modern Fischer Identity program could measure:
- Source-to-governance latency
The time between an authoritative business event and its receipt by the identity platform.
- Policy evaluation latency
The time required to correlate the identity, evaluate applicable rules, and determine the desired state.
- Provisioning latency
The time between the access decision and execution in the target system.
- Reconciliation latency
The time required to confirm that the target system reflects the intended state.
- Exception aging
The amount of time an access exception remains active beyond its expected duration.
- Unmapped access rate
The percentage of target entitlements with no valid role, policy, request, or ownership basis.
- Time-box compliance
The percentage of temporary grants that expire or renew according to policy.
- Orphan remediation time
The time required to identify and resolve accounts without a valid owner.
- Signal-to-action latency
The time between receiving a risk or business signal and applying the required governance response.
- Policy coverage
The percentage of access governed through deterministic policy rather than manual assignment or unmanaged processes.
These metrics measure the quality of continuous governance.
They do not assume governance only occurs during a campaign.
Certifications Are a Validation Layer, Not the Lifecycle Engine
Certification remains an important IGA capability.
There are valid reasons to ask a manager, application owner, sponsor, or data owner to confirm access.
Some decisions require human judgment.
Some regulations require formal attestation.
Some access cannot be fully derived from attributes.
Some exceptions must be reconsidered.
Some business owners need to validate that the governing policy still reflects reality.
The mistake is treating certification as the primary lifecycle control.
A mature Fischer Identity implementation uses certification to validate the governance system and address exceptions, not to compensate for missing integrations, absent expiration dates, incomplete source data, or weak lifecycle policies.
Quarterly reviews should not be the first time the organization discovers that an employee changed jobs three months ago.
Fischer Identity Is Beyond Campaign-Centric IGA
Fischer Identity has more than 20 years of experience solving complex identity governance and lifecycle problems.
The company has not built its reputation through the loudest marketing or the largest advertising budget. Fischer has invested in the product, its configurability, its implementation model, and the customer experience.
That matters because many of the capabilities now being described as the future of IGA have been practical requirements in Fischer customer environments for years:
- Continuous identity lifecycle processing
- Real-time or near-real-time source integration
- Dynamic RBAC, ABAC, and PBAC
- Multi-role identity governance
- Automated provisioning and deprovisioning
- Time-boxed requested access
- External identity lifecycle management
- Signal-driven workflows
- Target reconciliation
- Non-human identity governance
- Hybrid cloud and on-premises integration
- Configuration without custom code
Fischer Identity does not require organizations to choose between lifecycle automation and governance, or between cloud and on-premises systems. The platform uses the same codebase across deployment models and supports complex hybrid environments through a configuration-driven approach.
The Better Question
The central question should not be: How quickly is stale access accumulating between our reviews?
It should be: Why is the access allowed to become stale, and what authoritative event, policy, expiration, signal, or reconciliation control should have prevented it?
That is the difference between measuring an outdated operating model and designing a modern identity governance program.
Continuous identity is not a slogan.
It is an architecture.
It requires accurate source data, strong identity matching, policy-based access, time-bound exceptions, signal consumption, automated lifecycle actions, target reconciliation, and measurable end-to-end responsiveness.
Fischer Identity has been delivering that model for years.
The future of IGA is not simply faster campaigns or better scores for aging access.
It is maintaining the correct identity and access state continuously, across every governed identity, account, entitlement, source, and target.
That is not old IGA with new terminology.
That is modern identity governance.