Join our Newsletter — 33% off our NHI Course

Who is accountable when excessive identity permissions are not reviewed and revoked on time?

Accountability sits with the organisation’s identity, security, and control owners, not with the monitoring tool. If access reviews and revocations lag, governance fails at the process level. Teams need clear ownership for approvals, revocation enforcement, and exception handling so stale access does not remain active beyond its intended business purpose.

Why This Matters for Security Teams

When excessive permissions are not reviewed and revoked on time, accountability does not sit with the monitoring platform. It sits with the identity owner, the approver, and the control owner responsible for enforcing a working review cycle. The security issue is usually not a missing alert; it is a broken governance process that allows stale access to remain active after the business need has ended.

This is especially dangerous for non-human identities, where access tends to be broader, longer-lived, and easier to overlook than human access. NHI Management Group notes that 97% of NHIs carry excessive privileges, and 71% are not rotated within recommended time frames in its Ultimate Guide to NHIs. That pattern turns delayed reviews into a compounding risk, not a one-time miss. The issue is reinforced by the OWASP Non-Human Identity Top 10, which treats entitlement sprawl and weak lifecycle control as core exposure points.

In practice, many security teams discover the accountability gap only after stale access has already been used for lateral movement, rather than through intentional access certification.

How It Works in Practice

Accountability needs to be assigned across the full access lifecycle, not just at the point of approval. The requestor, reviewer, system owner, and identity governance function each have a role, but one party must own the actual revocation outcome. If that ownership is unclear, reviews may be completed on paper while privileged access remains active in the directory, vault, cloud control plane, or CI/CD toolchain.

For human access, periodic certifications, exception tracking, and revocation SLAs are standard controls. For NHIs, the same idea must be more operational because machine access often survives long after the workload changes. NHI Management Group’s NHI Lifecycle Management Guide emphasizes that lifecycle state, ownership, rotation, and offboarding must stay linked. That aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls, which separates access approval from access removal and expects organisations to enforce both.

  • Assign a named business owner for each identity and permission set.
  • Define who approves, who executes revocation, and who verifies completion.
  • Set review cadences by privilege level and data sensitivity, not by convenience.
  • Track exceptions with expiry dates so temporary access does not become permanent.
  • Measure overdue reviews and failed revocations as control failures, not administrative delays.

Where this breaks down is in distributed cloud and DevOps environments, because entitlements are often created outside the central IAM workflow and never return to it for cleanup.

Common Variations and Edge Cases

Tighter review and revocation controls often increase coordination overhead, requiring organisations to balance speed of operations against assurance that access really disappears when it should. That tradeoff is real in fast-moving engineering teams, regulated environments, and merger situations where ownership records are incomplete.

There is no universal standard for every exception path yet, especially for service accounts, shared pipelines, and break-glass access. Current guidance suggests treating these cases differently from ordinary user access: use shorter review windows, explicit expiry, and separate approval chains. The risk is highest where one team requests access, another team provisions it, and no single owner is accountable for cleanup. That is a recurring theme in the Top 10 NHI Issues and the Guide to the Secret Sprawl Challenge, both of which show how forgotten credentials and scattered ownership turn minor misses into persistent exposure.

For audit and response purposes, the practical test is simple: if nobody can prove who must revoke access, then nobody truly owns the control. In shared-service, outsourced, or inherited identity stacks, that accountability often becomes fragmented enough that revocation stalls until a breach or audit finding forces closure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 Stale NHI access is a core identity lifecycle weakness.
NIST CSF 2.0 PR.AA-5 Access permissions must be monitored and adjusted over time.
NIST SP 800-63 Identity assurance depends on ongoing lifecycle control, not one-time approval.
NIST AI RMF Governance requires clear accountability for control execution.
NIST Zero Trust (SP 800-207) AC-4 Zero trust requires continuous permission enforcement and least privilege.

Inventory NHI owners and enforce timely review, expiry, and revocation for every non-human identity.