IAM teams are often perceived as the department that says "No". Yet some Nos protect an organization's future, while others simply reveal missing standards, resources, or direction. Drawing on real-world experiences from ransomware response, large-scale IAM transformation, and application onboarding, this session explores how IAM organizations can better distinguish between good and bad Nos and Gos. Attendees will leave with practical ideas for making sustainable IAM decisions that balance business enablement, risk, and long-term scalability.