
Why we built this framework
Ask ten CISOs where their identity program stands today, and the answers will differ wildly: different vocabularies, different priorities, different definitions of “done.” There’s no shared standard for how to plan and implement an identity program, and that’s the gap Veza teams have spent years helping organizations close.
Identity has become one of the most fragmented domains in the enterprise. IAM teams speak one language. SecOps speaks another. Leaders sit somewhere in between, trying to reconcile spreadsheets, scripts, and a growing list of platforms that all claim to solve “access.”
The framework we share today came from several customer conversations, planning sessions and implementation cycles with Security Teams, IAM Teams, GRC and application owners, who asked us for exactly this: take me on a journey. Show me where I am. Show where I should go next. Give me a tool that I can use to talk about identity maturity that my board, my auditors, and my engineering teams can all grasp and agree on.
That request became the Identity Security Maturity Model, and it’s the framework we now use with organizations navigating identity transformation, whether that’s an IGA modernization, an identity security overhaul, or, increasingly, both at once.
For CISOs, CIOs, and Heads of Identity at large organizations with thousands of employees, and even 10x or 100x the amount of NHIs and AI Agents, this is where to start.
One unified guide
Nine out of ten enterprises we talk to are already mid-transformation on identity. Some started from a need to modernize their privileged access, while others wanted to improve their compliance processes with minimal increase in overhead. However, no transformation project looks like the other.
This model gives identity leaders two axes to reason about their program: an X-axis of five capability pillars (Visibility, Intelligence & Analytics, Monitoring & Orchestration, Workflows, and Control), and a Y-axis covering every identity that matters (human, non-human and AI agents).
This model also goes beyond human identities. It covers Service accounts, API keys, secrets, and autonomous agents that now outnumber the human workforce by a wide margin. They don’t badge in. They don’t get exit interviews. They don’t trigger an HR workflow when they should be turned off. A framework that ignores them only measures a fraction of an organization’s actual exposure to identity risks.
The five pillars of the identity security journey

1. Visibility: organizations cannot govern what they cannot see
Before organizations can address least privilege, dormant access, or overprovisioned access, they need a unified data model of who has access to what across cloud, SaaS, on-prem, and custom applications. That means an Access Graph, a comprehensive entitlements catalog, and honest visibility into high-risk combinations that today is hidden to a lot of organizations.
This is also where identity hygiene gets established. Once over-privileged access and the general health of the identity structure is clear, organizations are able to prioritize addressing their most critical access risks.
2. Intelligence & Analytics: turning visibility into judgment
Visibility tells organizations what exists. Intelligence tells them what matters. This pillar is where access risk dashboards, behavioral analytics, intelligent role analytics, and proactive risk modeling turn a flood of entitlement data into a prioritized list of what to fix first.
This is also where the “quick fix vs. major project” conversation happens. Not every risk deserves the same urgency: a dormant account with privileged access and a wildcard AWS IAM policy are not the same problem, and treating them the same way burns a team’s limited remediation capacity.
3. Monitoring & Orchestration: the engine of least privilege
Here’s the part of the model worth sitting with: least privilege is not a switch to flip. It’s a discipline organizations operate continuously. Visibility and intelligence are necessary, but they are part of a broader strategy to remediate risk and monitor drifts over time.
Monitoring and orchestration are what actually move the needle. This is privilege elevation alerting, cross-platform correlation, blast radius containment, and, critically, the automated remediation actions that turn “we found a risk” into “we removed it.” An identity with access it never uses can be an opportunity for license reclamation, but also can present an unnecessary opening to intellectual property data. This pillar is where that risky access actually goes away, via launching access reviews, deprovisioning a user and entitlements, or updating ownership on an orphaned service account.
4. Workflows: building it into how the business runs
Once organizations know what they have and can act on risk, the next step is making sure new risk doesn’t accumulate behind them. That’s what workflows are for: intelligent access reviews, self-service access requests, automated provisioning and deprovisioning for joiners, movers, and leavers, and just-in-time access that grants privilege only when it’s actually needed.
This is the pillar where identity stops being a security afterthought and becomes part of how the business operates: onboarding, offboarding, and everyday access requests running through a governed process instead of a ticket queue or an email thread.
5. Control: keeping the house clean
The final pillar is a maintenance discipline. Privileged access assurance, MFA assurance, role assignment, and compliance assurance exist to make sure the progress made in the first four pillars doesn’t erode the moment over time. New SaaS apps get onboarded. New agents get provisioned. New employees join. Control is what keeps all of that inside the guardrails already built, for humans, non-humans, and agents alike.
All pillars are positioned to achieving and furthermore maintaining the principle of least privilege in the organization. This is a function of visibility, intelligence, monitoring, and workflows, compounding in that order.
The four stages of maturity

Overlay those five pillars against four stages, and the result is a self-assessment tool for your team:
| Stage | What it looks like |
|---|---|
| Partial | “Front door” access for some platforms, spreadsheets for access reviews, manual audit log reviews, limited and manual joiner/mover/leaver processes |
| Informed | Access mapping with alerts for high-risk combinations, access risk dashboards, scheduled reviews, semi-automated JML |
| Repeatable | Cross-platform correlation, risk-based prioritization, continuous monitoring with automated high-risk removal, automated JML |
| Adaptive | Real-time mapping with behavioral analytics, predictive risk modeling, fully automated certification and compliance assurance, just-in-time access |
Here’s what we consistently see in practice: most large enterprises, including sophisticated, well-resourced ones, are sitting in Partial. They have pieces of a program: some scripts for onboarding, some spreadsheets for reviews, some ad-hoc risk assessments. What they don’t have is a connected system that moves them towards ongoing risk reduction.
Identity creation has outpaced identity governance for years, now exponentially more so as businesses run AI systems in all business units. The goal of this model is to help orient teams on next steps to improve their identity posture.
Security and Governance
Organizations leading an identity program at scale are managing two constituencies whether they’ve named them or not: Identity Security (the SecOps-adjacent function protecting the organization’s own systems) and Identity Governance (the IGA-style function focused largely on running and improving compliance and provisioning). Although we have seen these two functions move closer to each other every year, the problems they face still require different skill sets and follow separate priority lanes.
Where to start
The practical version of these four stages are:
- Integrate HR Systems, Directories and Systems with critical data to deliver an organization’s Access Graph. This model immediately surfaces known risks including: Over-privileged Access, Blast Radius, Orphaned Accounts with entitlements to resources in plain language (Create, Read, Delete, Update). Organizations no longer need a year-long project to know these numbers now that they have a data model they can trust.
- Elevate what’s actually important. Prioritize by business impact and effort, and let the low-effort, high-impact fixes go first.
- Wire remediation into existing processes. Whether that’s the SOC workflow, the ITSM platform, an update to Joiner-Leaver-Mover(JLM) workflows or a Slack alert to a resource owner. Findings must turn into action and not add more information to already-overloaded security teams.
- Build the automation muscle. Automate joiner/mover/leaver. Automate access reviews. Extend all of it to non-human identities and AI agents from the start, not as a phase-two afterthought.
Identity debt doesn’t wait for the roadmap
The uncomfortable truth behind this model is that identity risk compounds whether or not an organization is ready to address it. New SaaS apps, new hires, new automation pipelines, and new AI agents are being provisioned in the environment right now, at a pace manual processes can’t keep up with. The organizations that get ahead of this aren’t the ones with the most tooling. They’re the ones with a shared framework for where they are and what comes next.
That’s what this model is for. Use it as a discovery tool with internal stakeholders. Use it to plan the next steps in your organization’s journey in identity security and governance.
Want to see where your organization actually stands? Schedule a conversation with our team to map your environment against the five pillars, starting with the Access Graph that makes everything after it possible.





