Customer CaseHow HR player Liantis took control of user access in daysDownload →
Guide

How to Prove That You Are in Control

8 categories of key identity indicators focused on showing provable control of users and their access.

Guide — How to Prove That You Are in Control

Download the Full PDF

Demonstrate access governance to auditors and management.

Reporting about your current identity status and identifying potential risks or gaps remains a challenge. Based on our own experience and frameworks such as ISO 27001, we bundled a set of crucial indicators that you should measure in order to know whether you are in control — and to prove that you are.

✅ 8 categories of identity indicators
✅ How to choose the right indicators
✅ Based on the ISO 27001 framework

Why Proving Control Matters

Over the last decade, IT complexity has grown to challenging levels. Almost every company now manages a large number of applications in a complex IT infrastructure consisting of large amounts of accounts and permissions. Having control over who can access which data is crucial for privacy, compliance, and protection against cyber threats.

The traditional answer is introducing human governance processes for requesting, approving, and reviewing access. But how do you know if you're in control? And how can youprove it?

KPIs, KRIs, and KCIs

Key Performance Indicators (KPIs) measure performance — the achievement of identified goals. Key Risk Indicators (KRIs) measure risk exposure — they are an early warning to potential threats. Key Control Indicators (KCIs) measure the effectiveness of controls.

In practice there is not always a clear distinction between these three. What matters most is using them consistently to drive decisions and demonstrate accountability to auditors and management.

Identity indicator framework overview

Four Aspects of Being in Control

There are four aspects of being in control of your identities: security,risk, operational efficiency, and compliance. The key identity indicators described in this guide often provide evidence for multiple aspects at once.

Four aspects of identity control

How to Choose the Right Indicators

For most organisations the same core set of key identity indicators is relevant. Nevertheless, no two organisations are exactly the same. Depending on their focus areas and regulatory obligations, some indicators will be more relevant than others.

The choice of indicators is also not set in stone. Strategies develop, regulations change, and your IAM maturity grows. Revisit your indicator set at least annually.

The 8 Categories of Identity Indicators

1. Orphaned Accounts

What: Accounts that are no longer active or have no owner.

Orphaned accounts are an interesting path for hackers to gain access to organisational resources. When an employee leaves or a contractor's project ends, their accounts must be deactivated immediately. Tracking orphaned accounts also improves operational efficiency by keeping the identity repository clean.

2. Privileged Accounts

Privileged accounts give significant access to organisation resources and sensitive data, or can change or disable security systems. When not properly managed, they pose significant security risks — including hard-coded passwords, shared admin accounts, and stealthy privileged users that are not labelled as such.

3. Excessive Permissions

The cumulated access rights of all users together determine the attack surface of your organisation. There is often a gap between granted and required access rights. A rule of thumb: a user may be considered over-privileged when their number of roles or permissions exceeds twice the average.

4. Separation of Duties

Separation of duties (SoD) is a crucial control for avoiding fraud by disseminating sensitive tasks across multiple people. Conflicting roles — "toxic combinations" — allow users to bypass critical controls and increase the risk of fraud and regulatory non-compliance.

5. Access Reviews

Periodic evaluations of who has access to what, and whether that access is still appropriate. Most frameworks — NIS 2, ISO 27001 — require regular access reviews for regulated environments. Failure to review access can result in outdated or unauthorised access going unnoticed.

6. Joiner-Mover-Leaver (JML)

JML processes manage user access throughout their lifecycle — from onboarding, through role changes, to offboarding. If access is not updated or removed during lifecycle events, organisations face increased risk of unauthorised access and non-compliance.

7. Role & User Hygiene

A well-maintained IT environment is better protected against security risks. This includes cleaning up inactive users, removing empty or obsolete roles, and ensuring every role and entitlement has an assigned owner responsible for reviews.

8. Data Quality

Garbage in is garbage out. The indicators will only reflect the actual state if the identity data is accurate and complete. Inaccurate or incomplete identity data undermines every aspect of IAM — from access decisions to audit reporting.

Talk to us

Ready to apply this to your environment?

Book a 20-minute call with our team — we'll walk you through Elimity Insights on your own scenarios. No pressure.