Intro
“We’ll just use groups.” That’s how many IAM projects begin.
It sounds like a sensible approach, and for a while, it usually works. Then the organization grows, it brings in more applications and starts accumulating additional exceptions. Before you know it, managing access becomes much more difficult than anyone expected.
At some point – and especially once problems start appearing – many organizations start asking themselves where they are in their IAM journey. That’s what an IAM maturity model helps answer.
In this article, I’ll walk through the different stages, explain where organizations typically get stuck, and share what I’ve learned from helping them move forward. By the end, you’ll have a better understanding of where your organization stands today and what the next step should be.
In a nutshell:
- An IAM maturity score measures more than the success of a single implementation. That’s because a well-deployed platform doesn’t necessarily mean identities and access are managed consistently across the organization.
- Most companies today are in the early- to mid- tiers of the IAM maturity ladder. They often automate identity processes but struggle with governance, ownership, and long-term strategy.
- Stay wary of replacing groups with roles. Build RBAC around business functions through role mining, and not by copying existing permissions into a new structure.
- Technology alone won’t improve IAM maturity. Real progress starts with understanding your processes, identifying governance gaps, and choosing a platform that fits your organization. Not the other way around.
- Treat IAM maturity as a continuous improvement process. Focus on fixing the weakest area first, extend governance to non-human identities, and move up the ladder one practical step at a time.
What is IAM maturity – and why does the score matter?
Identity and access management maturity describes how well an organization manages identities and access. It shows how far it has gone from manual, disconnected processes to a structured approach that’s built on clear ownership, governance, and automation.
IAM maturity is how far an organization has progressed from ad-hoc, manually managed access toward automated, policy-driven, continuously verified identity control. A maturity model maps that journey into stages so you can benchmark where you are and prioritize what to fix next.
Now, I’d like to pose an important question here, straight away:
Can an organization have a successful IAM implementation and still score low on maturity? Yes, because delivering a platform on time and within scope doesn’t necessarily mean identity is managed consistently across the whole business.
That distinction has become much more important in recent years. Regulations such as NIS2, DORA, and ISO 27001 expect organizations to demonstrate control over identities and access. At the same time, every new application, cloud service, or acquisition adds more identities and permissions to manage, making it harder to maintain that control.
From my experience, maturity depends just as much on ownership, governance, and business processes as it does on technology. Some of the biggest gaps remain invisible for years because nobody has looked at identity from an organization-wide perspective. They only become apparent during an audit, after a merger, or when another IAM project uncovers them.
The, perhaps encouraging, news is that low maturity isn’t unusual. Every organization starts somewhere, and the first steps often bring the biggest improvements. A structured approach helps you uncover the issues that have been holding the program back, prioritize them, and build a stronger foundation for everything that comes next.
The IAM maturity model – understanding the journey
I recently came across a LinkedIn post by Josh Sargel, Head of Identity & Access Management at 3M, that presents a nine-level IAM maturity ladder. This framework resonates strongly with me, because it reflects how IAM programs typically evolve in the real world. Namely, organizations solve one challenge only to uncover the next. Here are the steps Sargel mentioned, along with my observations from working with IAM programs over the years.
IAM maturity ladder – the nine key steps
| Level | What it looks like |
| 1. Groups | Access relies on security groups with little governance. |
| 2. Group sprawl | Groups multiply until ownership and purpose become unclear. |
| 3. RBAC | Access starts to follow business roles instead of individual requests. |
| 4. Role explosion | Poor role design recreates the same complexity as groups. |
| 5. ABAC | Access decisions rely on attributes rather than static roles (RBAC vs ABAC). |
| 6. Governance | Access governance introduces ownership, certification, policies, and least privilege. |
| 7. Non-human identities | Non-human identities such as service accounts and bots become part of identity management, following the same least privilege principles. |
| 8. Zero Trust | Zero Trust continuously evaluates access based on context and risk. |
| 9. Identity as the control plane | Identity becomes the foundation of security across the organization. |
Here are a few of my main findings that refer to this proposed 9-step structure.
Most organizations spend longer than they think in the early stages
When we start working with a new client, I usually find them somewhere between Levels 1 and 4. Every now and then, I see elements of Level 5, such as dynamic access based on user attributes, but it’s still rare to find an organization that has adopted a mature, organization-wide approach to identity.
Part of the reason is simply how IAM has changed. For years, organizations focused on automating joiner, mover, and leaver processes or group management. Governance wasn’t the priority, because there were fewer regulatory requirements. Also, cyber threats weren’t as sophisticated, and identity wasn’t yet viewed as one of the core pillars of security.
Today, the situation looks very different. Organizations need stronger control over identities and access, but many still don’t have the experience or internal expertise to design a long-term identity strategy. That’s why so many programs get stuck in the early stages of the maturity ladder.
The biggest mistake? Turning 4,000 groups into 4,000 roles
One of the most common traps is when organizations move from groups to role-based access control. Instead of simplifying access management, they recreate the same problem under a different name. That’s where the four thousand groups mentioned by Sargel become four thousand roles, and very little actually changes.
From my experience, a successful RBAC implementation starts with the business, and not with the technical permissions. That’s also the reason why role mining is such an important step. The goal is to understand how people work and build roles around business functions instead of individual entitlements.
Take someone in marketing as an example. They shouldn’t have to know they need access to Google Analytics, Figma, SharePoint, Jira, and several other systems. They simply request the appropriate business role. Behind the scenes, that role needs to map to everything they need to do their job.
When you design roles this way, thousands of technical permissions often become a few hundred meaningful business roles.
I would argue that the hardest part is cleaning up years of accumulated exceptions and legacy decisions. That usually requires organizational change, and that’s also where many initiatives lose momentum.
Maturity depends on both technology and governance
Many organizations that find themselves in access management trouble start by looking for a new IAM platform. I usually recommend taking a step back first.
Before choosing a tool, you have to understand your business processes, know where the biggest gaps lie, and define what success looks like for your company. Only then will it make sense for you to compare platforms.
I’ve seen situations where organizations selected a solution simply because that’s what a particular implementation partner specialized in. In my opinion, the process should work the other way around. Choose the tool that fits your organization, because every company has different priorities, budgets, and expectations. The “right” answer depends on much more than a feature list.
Don’t overlook identities that aren’t people
Service accounts, bots, APIs, suppliers, and contractors all need the same level of attention as employees.
A good starting point is to extend your JML processes to these identities as well. Every account should have:
- a clearly defined lifecycle
- an owner who’s responsible for it
- regular reviews to confirm it’s still needed.
Non-human identity accounts should have an expiration date or a review cycle, just like employee access does. That simple change makes it much easier to keep the environment under control as the number of identities continues to grow.
How do you actually assess your IAM maturity score?
If you want to properly measure identity and access management maturity, you cannot rely on a single gut-feel number or treat it as a one-time compliance checkbox. Instead, you need to look at specific operational dimensions and uncover your hidden risks and structural gaps. An accurate IAM maturity assessment helps you evaluate how identities move through your organization, how your team approves access, and whether your critical systems stay protected from unnecessary exposure.
Core assessment domains
When you look at established scoring models, they check your identity posture across four distinct dimensions:
- Identity lifecycle management. This covers your full Joiner-Mover-Leaver (JML) pipeline. You want to track how quickly you can provision access for a new hire, how seamlessly roles shift during internal moves, and whether you revoke access immediately upon departure. Without your IT team needing to process manual tickets.
- Account & access management: This reviews your single sign-on (SSO) integration, password sprawl, and central role definitions. Your main goal here is to stop “access accumulation” – that common habit where long-term employees hoard legacy permissions every time they change teams.
- Privileged Access Management (PAM). Here, you focus on your administrative, service, and non-human identities (NHI). This dimension checks whether your elevated permissions operate under strict monitoring, session recording, and individual accountability.
- Adaptability. This measures how efficiently your identity ecosystem absorbs unexpected changes, like mergers and acquisitions, rapid cloud migrations, shifting regulatory requirements, or unmanaged shadow IT.
Diagnostic questions: spotting your gaps
Answering a few practical diagnostic questions will help you surface immediate blind spots before you dive into a formal audit:
- How long does full provisioning take for your new hires, and what percentage of JML tasks require manual IT work? Automated JML processes save you time, but your coverage matters just as much. If your automation covers internal staff while leaving contractors, temporary guests, or non-human accounts (NHIs) completely unmanaged, you leave a major security gap wide open. Once an attacker compromises an unmonitored guest account, climbing the ladder toward higher privileges gets much easier.
- Are you recording administrative and third-party sessions for full auditability?Privileged access management demands strict controls. You need real-time oversight and session recording for high-level accounts so your security team maintains complete visibility into every administrative action.
- How do you manage system and application access – through structured role models or one-off approvals? Granting permissions on a piecemeal, permanent basis leads straight to access collection. If you don’t run mandatory access reviews every six to twelve months, your users will naturally gather excess rights over time.
- How much password sprawl are your users dealing with every day? Forcing people to manage dozens of separate credentials creates constant friction and bad password habits. When you consolidate login flows through a well-secured Identity Provider (IdP) with Single Sign-On (SSO) and robust MFA, you strike the right balance between smooth daily usability and strong, centralized protection.
- Can your current setup instantly handle access changes during a sudden organizational shift or M&A deal? Your identity systems need enough built-in flexibility to onboard hundreds of new accounts or adapt to fresh compliance rules without breaking your existing security policies.
Want to put a clear benchmark on your core dimensions? Run through One Identity’s free IAM Maturity Survey. It scores your IAM maturity score across these operational domains in just six targeted questions, giving you an immediate baseline for your next team discussion.
Why IAM maturity still eludes most organizations
Although cybersecurity budgets are rising along with strict regulatory pressure, many organizations still hit an invisible ceiling. They start with strong momentum, only to stall halfway up the IAM maturity model. They buy enterprise-grade software, yet daily operations remain messy and security teams still struggle to answer basic audit questions.
Why do so many identity initiatives hit a wall?
Reaching advanced maturity takes more than acquiring licenses. Most plateaus happen because of structural missteps:
- Treating IAM as a project, not a program. When leadership views identity work as a one-time deployment with a fixed end date, momentum drops the moment the core platform goes live.
- Buying tools before defining processes. Software cannot fix broken workflows. Purchasing an identity suite without mapped business processes forces teams to digitize bad habits.
- Overlooking non-human identities (NHIs) and third parties. Many Joiner-Mover-Leaver (JML) setups manage internal employees smoothly, yet leave contractors, service accounts, and API tokens unmonitored.
- Skipping access governance. Assigning permissions without clear role definitions or periodic reviews leads directly to access accumulation. Employees hoard rights as they move through different roles, widening the internal attack surface.
- Unclear identity ownership. When responsibility sits scattered between IT support, security ops, and business unit heads, no single leader owns a long-term strategy.
What high performers do differently
Those who want to break through an identity plateau should shift away from quick fixes toward real access governance. Organizations that actually climb the ladder look at the problem through a practical, battle-tested lens:
- Move from designed processes to real coverage. A JML model on paper means little if it only manages staff. High performers look closely at their coverage gaps. External guests, contractors, and non-human identities (NHIs) must follow the exact same lifecycle rules. Leaving guest accounts unmanaged creates an easy foothold. Once inside, an attacker can climb the ladder toward privileged access much faster than starting from the outside.
- Treat PAM as a strict, audited requirement. Privileged access demands separate rules and full transparency. High performers record administrative sessions to maintain complete auditability and visibility over every action taken inside critical systems.
- Stop access collection. Employees naturally collect permissions over time, accumulating rights as they change roles. High performers replace permanent approvals with structured role models and mandate access reviews every 6 to 12 months to strip away unused rights.
- Standardize single sign-on safely. User friction leads to weak security practices. While distributed accounts and separate passwords sound safer to some, managing dozens of logins creates severe risks. High performers integrate systems – with an Identity Provider – to enable SSO. Proper design and strong controls make SSO both user-friendly and fully secure.
Moving up the ladder requires identity management as a continuous discipline. Process alignment with real access habits builds an identity architecture that stays secure, compliant, and ready to scale.
From score to plan – how to climb the next rung
Nobody jumps from level 2 straight to level 9. IAM maturity is a step-by-step climb, and the goal for any given quarter is simply to reach the next rung.
Moving forward requires shifting from a raw score to a targeted action plan. A proper IAM maturity assessment does not just hand over a number; it uncovers the operational gaps holding the organization back.
When I advise IT and security teams on their next move, the starting point always depends on where they currently stand on the ladder. For teams sitting between levels 1 and 4, progress comes down to answering two fundamental questions: How do I handle things right now? and How should they look instead?
My approach focuses on finding the root cause rather than treating surface symptoms:
- Identify the gaps. I compare current workflows against target standards. I pinpoint the areas left completely unaddressed by existing IAM or IGA processes. Whether that means unmonitored guest accounts, manual JML steps, or missing PAM controls.
- Prioritize the lowest-scoring domain. I focus immediate energy on the weakest area first rather than spreading resources thin.
- Integrate missing areas into core processes. I bring those unmanaged identities or missing review cycles into structured management workflows.
- Refine what already exists. I evaluate current processes and optimize them to remove friction and security blind spots.
Answering these core questions creates a clear roadmap. Plugging these gaps automatically moves the organization up the ladder.
Get your real maturity picture with QWEY
An IAM maturity survey gives you a rough number, but a thorough IAM maturity assessment uncovers root causes and outlines exact steps to take. The move from self-assessment to expert evaluation bridges the gap between a score and a fix for underlying gaps.
Partner with QWEY for dedicated IAM consulting to get a clear roadmap tailored to your environment. Share the current setup and top challenges to receive a suggested plan with rough estimates within days – completely free with no obligation.
Book a free 60-minute consultation
FAQ
What is an IAM maturity model?
IAM maturity model is a framework to check where an organization actually stands with identity and access security. Instead of guessing, it measures processes, like user onboarding, privileged access, and permission reviews against clear standards to show what works, where security gaps hide, and what step to take next.
How do I measure my IAM maturity score?
Forget gut feelings. A real score comes from asking hard questions about daily operations across key areas:
- Identity lifecycle. Do JML processes run smoothly, or does IT still handle user onboarding and offboarding manually?
- Identity coverage. Do these processes cover everyone – employees, external contractors, guest accounts, and non-human identities (NHIs) – or just core staff?
- Privileged access. Are admin accounts strictly controlled, monitored, and recorded for total audit transparency?
- Access governance. Do regular access reviews happen every 6 to 12 months, or do long-term employees just collect permissions over time?
What are the levels of IAM maturity?
Most models break progress down into logical stages:
- Ad-hoc (Levels 1–2). Manual tickets, custom scripts, zero centralized control, and heavy password sprawl.
- Defined (Levels 3–4). Central IdP in place, basic SSO, and documented JML steps – though guest accounts and service accounts often slip through the cracks.
- Governed (Levels 5–6). Automated provisioning, structured role models, mandatory access reviews, and session recording for privileged accounts.
- Continuous (Levels 7–9). Full visibility across all identity types, automated risk response, continuous access checks, and complete alignment with business strategy.
What’s the difference between RBAC and ABAC?
RBAC assigns access based on predefined roles, while ABAC makes access decisions based on attributes such as department, location, or employment status. In practice, the two models solve different problems:
- RBAC groups permissions into business roles, making access easier to request and manage.
- ABAC evaluates attributes and policies, allowing access to adapt automatically as users or business conditions change.
Many mature IAM programs combine both approaches, using RBAC as the foundation and ABAC where more flexibility is needed.
Why do most organizations get stuck on IAM maturity?
Most organizations get stuck because IAM maturity depends on governance, ownership, and business processes as much as it does on technology.
From my experience, technology is rarely the biggest obstacle. Organizations often lack clear ownership of identity, carry years of legacy access and inconsistent processes, or underestimate how much organizational change an IAM program requires. As a result, they implement a platform but never address the underlying issues that limit progress. That’s why many companies remain in the early stages of maturity, even after investing in IAM.
How long does it take to move up a maturity level?
There’s no fixed timeline because every organization starts from a different point and faces different challenges. The pace depends on factors such as:
- The size and complexity of the IT environment.
- The quality of existing identity data.
- The number of applications and identities to manage.
- The organization’s readiness to improve governance and processes.
Some organizations make noticeable progress within a few months, while larger transformation programs can take years. The goal is to build a solid foundation that supports the next stage of maturity, and not just pacing up the ladder regardless of the consequences.