The perimeter security model is functionally obsolete for most organisations. The network boundary that once defined the security boundary has dissolved replaced by a distributed architecture in which users, services, and data operate across environments that no firewall can meaningfully contain.
Identity has become the effective perimeter. Credentials determine what can be accessed, from where, and by whom. This is widely understood at the technical level. What has not kept pace is the governance model that identity security requires. The result is a critical control domain that is technically sophisticated and organisationally ungoverned.
What identity governance actually means
Identity governance is not the same as identity management. Identity management is the technical discipline of provisioning accounts, enforcing authentication, and controlling access. It is largely a solved problem for mature organisations, at least in its basic form.
Identity governance is the organisational discipline of making and maintaining decisions about who should have access to what, on what basis, and for how long. It requires that someone owns those decisions, that there is a process for reviewing them over time, and that the outcome of that process is visible to the people accountable for the organisation’s risk posture.
Most organisations have the first. Very few have the second in a form that would withstand regulatory scrutiny. The distinction matters because the most common identity failures in regulated environments are not technical failures. They are governance failures: excessive permissions that were never reviewed, service accounts that outlived the projects they were created for, privileged access that was granted for a specific purpose and never revoked.
How the governance gap forms
Identity governance gaps are structural. They form through a combination of speed, fragmentation, and misallocated ownership that is predictable rather than exceptional.
Access is provisioned quickly because the business requires it. Access reviews are scheduled periodically but treated as administrative exercises rather than genuine risk decisions. The people conducting reviews are often not the people with the context to assess whether access is still appropriate. They approve what they cannot easily explain, which means they approve most of it.
Cloud adoption compounds the problem. Cloud environments provision access at a scale and velocity that manual governance processes cannot match. Infrastructure-as-code creates permissions through automated pipelines. Service-to-service access accumulates without the same visibility as human user access. The identity estate grows faster than the governance model designed to manage it.
The result is an organisation whose technical identity controls are sound and whose effective access posture is unknown. Unknown because nobody has a current, accurate picture of who has access to what, whether that access is appropriate, or whether it has been reviewed.
What regulators see
Identity and access management is one of the most scrutinised control domains in regulatory examinations of cloud environments. Regulators do not examine it because it is technically interesting. They examine it because it is where the most consequential failures concentrate.
What they look for is evidence of a governance process, not just technical controls, but the decision-making structures that determine whether those controls reflect the organisation’s actual access requirements. They ask who owns access decisions for privileged accounts. They ask what triggers an access review outside the scheduled cycle. They ask how the organisation would know if a service account had been compromised and used to move laterally.
Answers that describe technical capabilities without describing governance processes do not satisfy these questions. A well-configured identity platform without a functioning access governance process is a control that exists on paper and erodes in practice.
The governance model identity security requires
Identity governance requires ownership at the business level, not just the technical level. Access decisions are business decisions, they determine who can affect what outcomes in the organisation’s systems. Delegating those decisions entirely to IT or security functions disconnects them from the context required to make them well.
It requires a review process that is genuinely risk-driven. High-privilege access, access to sensitive data, and access that crosses organisational boundaries warrant more frequent and more rigorous review than standard user access. Treating all access reviews with the same cadence and the same level of scrutiny produces a process that is thorough in appearance and superficial in effect.
It also requires that the organisation accepts an uncomfortable operational constraint. Access that cannot be justified should be revoked, even when revocation creates friction. The friction of access removal is recoverable. The consequences of unreviewed access in the hands of a compromised account are not.
Identity is the perimeter. The governance model that perimeter requires is not yet standard practice. For regulated organisations, that gap is not a future problem. It is a current one.


