“We are a 2” is a sentence that means nothing on its own. It carries no information about whether privileged sessions are recorded, whether SSO covers the long tail of internal tools, or whether a leaver's access actually disappears on their last day. The five-level scale that most IAM maturity models share, ours included, is only useful once you know what a level looks like in the operational detail that separates it from its neighbors.
This piece is that detail. It walks through levels 0 to 4 with concrete examples from real capability areas, not the abstract stage descriptions most frameworks stop at. For what the levels mean structurally, how they roll up into domains, and how foundational controls gate the overall score, see The IAM Maturity Model, Explained. This article assumes that context and goes deeper on one question: what does a 2 actually look like on a Tuesday?
Level 0: Absent
At level 0, the capability is not a weak process. It is no process, running on whichever individual happens to remember. In privileged access management, this looks like administrator credentials sitting in personal password managers or a shared spreadsheet, with no vault, no session logging, and no way to answer “who has domain admin” without asking around. In identity governance, joiner-mover- leaver handling is fully manual and ad hoc: someone emails IT when a person starts, and access is granted or removed based on who remembers to send the next email. In authentication, single sign-on is not used or barely adopted, so most applications still run on standalone, unmanaged credentials.
Level 0 is not rare. Most organizations clear it in authentication and identity governance, where compliance pressure has forced at least a minimal program. It persists longest in privileged access and in newer surfaces like customer identity, where nobody has yet been assigned clear ownership.
Level 1: Initial
A capability exists at level 1, but it depends on a person rather than a process. Privileged credentials are vaulted with MFA, which is real progress over level 0, but session control is limited: once a credential is checked out, what happens with it is not monitored. Identity lifecycle events are HR-triggered, meaning an HR system event starts the process, but execution across downstream systems is still manual, so the time from “HR marks someone as terminated” to “their access is actually gone everywhere” can run days. SSO exists for core enterprise applications only, leaving a long tail of legacy and internally built tools on local authentication. Behavioral detection, where it exists at all, is limited to static rules for known-bad patterns rather than any model of what normal looks like for a given user.
The tell for level 1 is that the capability works when the right person is paying attention and fails silently when they are not. Audits at this stage tend to surface exceptions rather than systemic gaps, which is exactly why level 1 programs often self-rate a level higher than they should.
Level 2: Developing
Level 2 is where documented process replaces individual memory, and where the majority of organizations sit today according to independent research. Privileged sessions are brokered through a proxy with an audit trail, so at least the highest- value systems have real session control. Joiner and leaver processing is automated, though mover events, someone changing roles internally, are still handled by hand, which is where access accumulates uncorrected. SSO is widely available but not strictly enforced, so it covers most of the estate without covering all of it. Behavioral detection moves to contextual baselining: signals like location, device, and time of access establish what normal looks like for a given user, catching deviations a static rule would miss.
Coverage is the defining weakness of level 2 across every domain. The process is real, the documentation exists, and it genuinely works everywhere it has been rolled out. What it has not done is reach the entire estate, and the gap between “the process works” and “the process covers everything” is where most level 2 organizations overstate themselves.
Level 3: Established
At level 3, the capability is proactive and its coverage is measured, not assumed. Privileged access moves to just-in-time: standing access is minimized, and elevation requires an approval, logged and time-bound. Identity lifecycle management is fully automated with policy-based provisioning across joiners, movers, and leavers alike, so a role change actually triggers an access change instead of leaving stale entitlements behind. SSO is enforced across all workforce applications, including the long tail that level 2 typically leaves out. Behavioral analytics become model-driven: machine learning flags anomalous identity activity and triggers an automated response, rather than routing every alert to a human queue.
Level 3 is where most organizations should be aiming, and for most capabilities it is the right stopping point. The jump from level 2 to level 3 is usually the most expensive step in the whole scale, because it requires closing coverage gaps rather than adding a new tool, and coverage gaps are organizational problems as much as technical ones.
Level 4: Optimized
Level 4 replaces static control with continuous verification. Privileged access reaches zero standing privilege, where no account holds persistent elevated rights and every session is granted, verified, and revoked around the actual work being done. Identity lifecycle governance becomes continuous and risk-aware, adjusting entitlements based on behavior and context rather than only on HR events. Identity risk scoring runs continuously and feeds every access decision in real time, rather than sitting in a standalone tool that only flags incidents after the fact.
Level 4 across an entire program is genuinely rare, and it is not free. The published research bears this out: in the IDSA's 2024 survey of 521 security professionals, only 8% placed their organization at the highest maturity level. Chasing level 4 in a domain that is not where the organization's risk concentrates is usually a worse use of budget than closing a level 1 gap somewhere else.
Common Misgradings
Four patterns account for most of the gap between how organizations self-rate and what a structured assessment finds.
Confusing deployment with enforcement. “We have SSO” and “SSO is enforced everywhere” describe different levels. The first is often true at level 1; the second is level 3. The same gap shows up in MFA rollouts, where a percentage of applications covered gets remembered as full coverage.
Confusing a tool license with a working process. Owning a PAM platform is not the same as every administrator credential running through it. Evidence, not procurement history, settles the question: pull an actual session recording, or check whether a specific shared credential still exists outside the vault.
Grading the design instead of the exception path. A joiner-mover- leaver process can be well designed and still fail in practice for contractors, service accounts, or acquired subsidiaries that were never folded into it. A structured assessment scores what happens to the exceptions, not just the documented main path.
Averaging instead of reporting the floor. A domain with three strong capabilities and one absent one is not a solid 2.5. It is a program with a specific, nameable gap that a single averaged number will hide. This is exactly why a credible model decomposes scores by domain and capability rather than reporting one blended figure, and why foundational gaps are treated as a ceiling on the whole program rather than smoothed into an average.
Why the Level Rarely Matches Across Domains
Almost no organization sits at the same level everywhere. It is common to find workforce authentication at level 3, built on years of SSO rollout, sitting next to privileged access at level 1, because PAM programs are harder to fund and easier to defer. That unevenness is the actual finding a maturity assessment exists to surface. A single blended score, the kind a rushed self-assessment tends to produce, erases exactly the information that would tell a CISO where the next investment should go.
AXIS scores 37 questions across nine domains against this same five-level scale, with concrete evidence expectations attached to every option so an answer can be checked rather than asserted. The full methodology, including how domain scores combine and how foundational gaps cap the result, is on the methodology page.
Common Questions
What level should every domain be at? Level 3 is the reasonable target for most domains in most organizations. Level 4 is worth pursuing selectively, in the domains where the organization's actual risk concentrates, typically privileged access and identity threat detection.
Can an organization be level 0 in one domain and level 3 in another? Yes, and this is the normal case rather than the exception. Domains mature at different speeds because they compete for different budget and different executive attention.
Why do self-assessments usually score higher than structured ones? Because self-assessment tends to grade the design and the procurement rather than the exception path and the evidence. A capability that works for 90% of the estate reads, from memory, as “we have this,” when the honest answer depends on what happens in the remaining 10%.
AXIS is free to use. Get a domain-by-domain maturity score with evidence-based options at every level, not a single blended number.
Start AssessmentSources
- IDSA, “2024 Trends in Securing Digital Identities” (521 professionals)
- SailPoint, “The Horizons of Identity Security 2025-2026” (375 IAM decision-makers)
- Ponemon Institute and GuidePoint Security, “The State of IAM Maturity” (2025, 626 IT professionals)
- Simeio, “State of Identity 2024”