
Download the Full PDF
Demonstrate access governance to auditors and management.
Reporting about your current identity status and identifying potential risks or gaps remains a challenge. Based on our own experience and frameworks such as ISO 27001, we bundled a set of crucial indicators that you should measure in order to know whether you are in control — and to prove that you are.
✅ 8 categories of identity indicators
✅ How to choose the right indicators
✅ Based on the ISO 27001 framework
Why Proving Control Matters
Over the last decade, IT complexity has grown to challenging levels. Almost every company now manages a large number of applications in a complex IT infrastructure consisting of large amounts of accounts and permissions. Having control over who can access which data is crucial for privacy, compliance, and protection against cyber threats.
The traditional answer is introducing human governance processes for requesting, approving, and reviewing access. But how do you know if you're in control? And how can youprove it?
KPIs, KRIs, and KCIs
Key Performance Indicators (KPIs) measure performance — the achievement of identified goals. Key Risk Indicators (KRIs) measure risk exposure — they are an early warning to potential threats. Key Control Indicators (KCIs) measure the effectiveness of controls.
In practice there is not always a clear distinction between these three. What matters most is using them consistently to drive decisions and demonstrate accountability to auditors and management.

Four Aspects of Being in Control
There are four aspects of being in control of your identities: security,risk, operational efficiency, and compliance. The key identity indicators described in this guide often provide evidence for multiple aspects at once.

How to Choose the Right Indicators
For most organisations the same core set of key identity indicators is relevant. Nevertheless, no two organisations are exactly the same. Depending on their focus areas and regulatory obligations, some indicators will be more relevant than others.
The choice of indicators is also not set in stone. Strategies develop, regulations change, and your IAM maturity grows. Revisit your indicator set at least annually.
The 8 Categories of Identity Indicators
1. Orphaned Accounts
What: Accounts that are no longer active or have no owner.
Orphaned accounts are an interesting path for hackers to gain access to organisational resources. When an employee leaves or a contractor's project ends, their accounts must be deactivated immediately. Tracking orphaned accounts also improves operational efficiency by keeping the identity repository clean.
2. Privileged Accounts
Privileged accounts give significant access to organisation resources and sensitive data, or can change or disable security systems. When not properly managed, they pose significant security risks — including hard-coded passwords, shared admin accounts, and stealthy privileged users that are not labelled as such.
3. Excessive Permissions
The cumulated access rights of all users together determine the attack surface of your organisation. There is often a gap between granted and required access rights. A rule of thumb: a user may be considered over-privileged when their number of roles or permissions exceeds twice the average.
4. Separation of Duties
Separation of duties (SoD) is a crucial control for avoiding fraud by disseminating sensitive tasks across multiple people. Conflicting roles — "toxic combinations" — allow users to bypass critical controls and increase the risk of fraud and regulatory non-compliance.
5. Access Reviews
Periodic evaluations of who has access to what, and whether that access is still appropriate. Most frameworks — NIS 2, ISO 27001 — require regular access reviews for regulated environments. Failure to review access can result in outdated or unauthorised access going unnoticed.
6. Joiner-Mover-Leaver (JML)
JML processes manage user access throughout their lifecycle — from onboarding, through role changes, to offboarding. If access is not updated or removed during lifecycle events, organisations face increased risk of unauthorised access and non-compliance.
7. Role & User Hygiene
A well-maintained IT environment is better protected against security risks. This includes cleaning up inactive users, removing empty or obsolete roles, and ensuring every role and entitlement has an assigned owner responsible for reviews.
8. Data Quality
Garbage in is garbage out. The indicators will only reflect the actual state if the identity data is accurate and complete. Inaccurate or incomplete identity data undermines every aspect of IAM — from access decisions to audit reporting.
Ready to apply this to your environment?
Book a 20-minute call with our team — we'll walk you through Elimity Insights on your own scenarios. No pressure.