Humans vs habits: Why IAM fails without behavioural change

IAM is full of technical promise, but routinely undone by human shortcuts

Identity and access management has never lacked ambition. The idea is simple enough: give the right people the proper access at the right moment, and nothing more. However, the execution is anything but simple: directories, SSO platforms, conditional access policies, privileged access management and governance suites create a web of controls that, in theory, should box off most identity risk.

The uncomfortable part of IAM is how often it comes unstuck. The reason is rarely a bug or a cryptographic flaw; itโ€™s the human layer we tend to treat as the least interesting part of identity security. The way people actually work and make decisions exerts more influence over identity risk than any single technology ever deployed to fix it.

The shortcuts we donโ€™t talk about enough

Bad security habits look painfully ordinary when written down. Itโ€™s colleagues sharing passwords, managers clearing approval queues while between meetings, developers accumulating privileged rights over time because revoking them always comes with the fear that something will break, and IT teams quietly extending contractor access because the project rolled over a deadline. No one sets out to make a bad call โ€“ they make the fastest call that doesnโ€™t explode their afternoon.

Itโ€™s hard to blame them. Organisations explicitly or implicitly reward speed, promoting fast delivery, rapid decisions and clearing blockers. Revoking access or challenging an approval feels too much like creating a blocker rather than fixing one. Secure identity practices land in a world that still promotes insecure habits.

Why identity controls feel like speed bumps

Most identity controls introduce small moments of friction. Step-up authentication asks someone to reverify, JIT requests prod them to justify access again, AM elevation screens create a pause before an admin session, and governance reviews drop approval requests in front of people who have other jobs to do.

These interventions are reasonable and are often essential. But they fight with habits designed to save time and mental energy. At work, habits are survival skills. We donโ€™t decide to form them; we accidentally fall into them because they work more often than they fail, and because organisations donโ€™t tend to make the secure version of a task more straightforward than the insecure one.

When identity controls feel arbitrary, adoption fails. When they clearly map to the outcome someone is trying to achieve, users tolerate them far better. Purpose matters. Humans make constant little cost-benefit calculations without announcing theyโ€™re doing it. If the identity loop costs more time and brainpower than the job demands, the loop loses.

The confidence trap

IAM often drifts into identity theatre. SSO reduces password prompts, conditional access policies silently green-light sessions, PAM tools log sessions, governance systems dispatch approvals, and identity postures look healthy on dashboards. All of the machinery is running, so organisations feel safer than they are.

High-confidence, low-scrutiny and friction-averse workplaces are a gift to attackers. Nearly every intrusion response report now singles out credential misuse as a primary enabler of breaches. The patterns are consistent: valid accounts, trusted devices, known names, and approvals that look and feel legitimate to someone who is in a hurry.

Machine identities have their own risks, but they rarely create them in isolation. Configurations go bad because overly permissive human approvals let them. Contractors inherit broad access because habitual extensions let them, and privilege accumulates because quiet human deferrals to convenience let it. The technology enforces exactly as much rigour as the organisation wraps around it. No more, no less.

Building identity systems for humans who are busy

The most successful IAM programmes donโ€™t start with new rules. They start by assuming humans will be humans, and designing identity flows accordingly.

Conditional access prompts should be as plain and practical as possible, clearly tied to the task at hand. Privileged access should expire without negotiation or ceremony, encouraging the mindset that elevated access is a brief, purposeful act. Approvals should contain enough colour about why someone needs something that reviewers feel compelled to slow down and read it. Access reviews should be frequent enough to set a rhythm, but not so frequent that they become background noise. Provisioning and de-provisioning should be administratively trivial, so it loses its social awkwardness.

Good IAM training is less about reading policy aloud, and more about rehearsing real tasks until the secure option feels like second nature. It should line up with the daily pressures an employee or engineer actually faces, giving them the permission and practical cover to ask questions without fearing it will turn into a crisis.

Making the secure choice the ordinary choice

Identity security only works when secure behaviour feels normal, boring even. The default should be least privilege because it requires no extra effort to adopt. Privileged sessions should be temporary because thatโ€™s how everyone already treats them. Approvers should challenge context, as it is part of how requests are written. Contractors should lose access at the agreed-upon time because extensions arenโ€™t a negotiation; they’re a configuration. Asking a question in an approval form should feel like part of the job because part of the job is slowing down for a moment to get it right.

Organisations donโ€™t need perfect people to run IAM well. They need environments that stop glorifying unsafe shortcuts and quietly remove their utility until they drop out of use on their own.

Habits are sticky because organisations build workplaces that make them stick. IAM starts working correctly when the organisation changes that environment first, letting the rest follow one ordinary day at a time.

Carly Page
Carly Page

Carly is a freelance technology journalist and editor with a long string of credits to her name. Her bylines include Forbes, IT Pro, The Metro, Stuff, TechCrunch , TechRadar, TES, Uswitch and WIRED.
She has written about collaboration and innovation for TechFinitive.