Every login attempt at a state regulatory agency carries the question: does this person deserve access to what they’re asking for? A citizen renewing a professional license, an inspector pulling up a facility record from a job site, a board member reviewing confidential complaint files from home. Each scenario demands proof of identity, a defined boundary around what that identity unlocks and a record of what happened next.
NASCIO’s State CIO Top Ten Policy and Technology Priorities for 2026 names Identity and Access Management (IAM) the seventh priority among state technology leaders, spanning citizen digital services, workforce access, access control, authentication, credentialing and digital standards. IAM also lands at #4 on NASCIO’s list of priority technologies for the year, right behind AI, application modernization and cloud. State CIOs increasingly treat identity as infrastructure, not an afterthought added to a login page.
This article continues a 10-part series on NASCIO’s 2026 priorities for state regulatory agencies. Each installment examines how pairing advanced technology with disciplined operations helps agencies meet rising expectations with the staff and budgets they actually have.
What NASCIO Means by Identity and Access Management
NASCIO groups six related disciplines under this one priority:
- Citizen digital services: public-facing tasks like license applications, renewals, permit requests and complaint submissions
- Workforce access: how staff, board members and contractors reach internal systems from multiple devices and locations
- Access control: what each authenticated user actually sees and edits once inside a system
- Authentication: verifying that a person logging in matches the identity they claim
- Credentialing: confirming that a license or certification (nursing, contracting and accounting) remains legitimate and current
- Digital standards: a shared framework that replaces one-off, agency-specific login systems
Why IAM Ranks So High in 2026
Three factors push IAM up the priority list:
- Attackers target credentials first. Weak or reused passwords remain the easiest way into a government system.
- Sensitive data sits behind every login. Background checks, human care licensing records, financial disclosures and complaint files all demand strong access control.
- Staffing stays tight. Password-reset and login-support calls pull staff away from processing applications and investigating complaints. Strong IAM reduces that drag.
Citizen Digital Services: Secure by Design, Not Just Convenient
A licensee’s first experience with a portal shapes their opinion of the whole agency. GL Suite’s self-service portal features demonstrate what a well-built portal delivers:
- 24/7 access to renewals, applications, and document uploads
- Authentication through OpenID Connect, Microsoft Windows Authentication, LDAP and SQL Server Database Authentication
- Multi-factor login options and single sign-on
- Role-based access control, so a public applicant sees only their own file and a board member sees only their assigned case queue
Identity and access work together. A verified credential, not a shared password sitting in an inbox, determines what a user reaches.
Workforce Access and Access Control: Protecting the Back Office
Internal access control carries equal weight to citizen-facing security. Consider what a typical week looks like:
- Board members review confidential complaints from personal devices
- Investigators pull records in the field
- New hires need appropriately scoped permissions from day one, not week three
Use Case: Trading Spreadsheets for Single Sign-On in Alabama
The Alabama Home Builders Licensure Board moved from scattered desktop databases and spreadsheets to a centralized system with single sign-on and automated audit trails. The shift cut password-related help desk calls and gave the agency traceable records of who touched which file, and when.
GL Solutions CTO Ryan Pedersen describes the goal directly in GL Solutions’ podcast on future-proofing state technology: role-based access and audit trails “ensure that only authorized personnel view sensitive data and ensure the tracking of each action for accountability.” He calls security “a continuous improvement mindset” rather than a project with an end date.
Read the full Alabama Home Builders Licensure Board case study for more detail.
Use Case: Cloud Migration Meets Configuration Control in Arizona
The Arizona Medical Board migrated hosting to a FedRAMP-certified cloud environment and layered role-based configuration controls on top, letting staff adjust fields, screens, and reports without waiting on developers, while every change stays tracked and attributable.
Read the full Arizona Medical Board case study to learn more.
Authentication, Credentialing, and Digital Standards
- Open standards reduce lock-in. OpenID Connect, for example, lets citizens sign in with a familiar Google or Microsoft account while the agency retains full control over what that account touches internally.
- Standards ease cross-agency data sharing. A background check completed at one department flows securely into a licensing decision at another. Pedersen calls this capability a direct contributor to public safety, since it gets critical data to the right people quickly.
- Credentialing deserves the same rigor as login authentication. Verifying that a nurse, home builder, or gambling licensee holds a legitimate, current credential requires the same scrutiny agencies apply to verifying the person checking on it. Treating both as one connected identity challenge closes gaps that fraudsters exploit.
Identity & Access Management Checklist for 2026
- Enforce multi-factor authentication across both citizen portals and internal staff logins.
- Adopt role-based access control tied to job function and revisit roles whenever a job changes.
- Build audit trails into every system to support compliance reviews and speed up incident response.
- Favor open standards (OpenID Connect, OAuth 2.0) over proprietary logins to reduce vendor lock-in.
- Automate password recovery to cut helpdesk volume and free staff for higher-value work.
- Treat credentialing verification as an identity problem, not a separate system.
Identity & Access Management FAQs
- What does NASCIO mean by Identity and Access Management?
NASCIO’s 2026 Top Ten defines Identity and Access Management (IAM) as the combination of citizen digital services, workforce access, access control, authentication, credentialing and digital standards — the full set of systems that verify identity and control what that identity reaches.
- Why does IAM rank so high on the 2026 list?
Stolen credentials drive a large share of data breaches, and state agencies hold sensitive licensing, health and financial data behind every login. Tight IT budgets and staffing also push agencies toward automation that reduces manual identity-verification work.
- What’s the single highest impact step an agency takes on IAM?
Multi-factor authentication (MFA). Research shows MFA blocks the large majority of account compromise attempts, making it one of the highest-return security investments available.
- How does IAM apply specifically to licensing and credentialing?
Regulatory agencies verify two identities at once: the person logging in and the credential (a license, certification or permit) that person holds. A strong IAM strategy treats both as connected parts of the same identity problem.
- How can licensing management software improve identity and access management?
Modern licensing management software like GL Suite strengthens identity and access management by supporting multi-factor authentication, role-based access control, secure citizen self-service portals, comprehensive audit trails and standards-based authentication. These capabilities help state regulatory agencies improve security while providing a better experience for applicants, licensees, inspectors and board members.
Identity as the Load-Bearing Wall
Identity and access management underpins nearly every other item on NASCIO’s 2026 list. AI initiatives depend on knowing exactly which systems and data an AI tool reaches. Modernization projects hinge on migrating access controls cleanly. Digital government efforts succeed only when citizens trust that their information stays protected behind the login screen.
State regulatory agencies that treat identity as foundational infrastructure, rather than a checkbox on a procurement form, position themselves to meet nearly every other 2026 priority with far less friction. GL Solutions helps agencies achieve that goal with GL Suite, a configurable AI-powered regulatory licensing software platform that combines strong security, role-based access control, audit trails and modern government licensing software capabilities to support secure digital government services.
Renee Moseley joined GL Solutions in 2016 with an educational and professional background in research and writing, along with software documentation. At GL Solutions she produces informative content to help regulatory agencies stay current on news and information that supports their success.
Time to Modernize
GL Solutions helps your regulatory agency run, grow and adapt with modern software and automation designed to address your agency’s biggest challenges. GL Solutions embeds AI into regulatory agency workflows in GL Suite, giving staff practical, policy-driven support that boosts efficiency, improves consistency and advances modernization—while keeping agency control and accountability at the forefront. Contact us to learn more.