Join our Newsletter — 33% off our NHI Course

How do organisations know whether manual identity work is still creating hidden control gaps?

Look for repeated tickets for access requests, MFA issues, password resets, delayed offboarding, and manual access reviews. If the same workflows keep needing human intervention, identity automation is not covering the full application estate. Another signal is inconsistent enforcement across apps, where core controls work in some systems but not in disconnected ones.

Why This Matters for Security Teams

Manual identity work often looks manageable until it starts masking control gaps across the estate. Repeated access tickets, delayed offboarding, exception-driven approvals, and inconsistent MFA enforcement are not just process annoyances; they are signals that identity governance is not keeping pace with application sprawl. NIST Cybersecurity Framework 2.0 frames this as a governance and control consistency problem, not merely an operations issue, because identity is only effective when it works across every system, not just the well-instrumented ones.

For organisations that manage Non-Human Identities alongside human access, the risk compounds quickly. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, and 97% of NHIs carry excessive privileges, which means hidden gaps are often sitting in plain sight until a breach or audit exposes them. The practical issue is not whether tickets are closed, but whether the same manual patterns are repeating because the underlying control model is incomplete. In practice, many security teams discover these gaps only after an audit finding, an offboarding miss, or an access incident reveals that “controlled” systems were never actually under consistent control.

Related NHIMG research on Ultimate Guide to NHIs and Top 10 NHI Issues shows how visibility and lifecycle failures frequently hide behind routine operational work.

How It Works in Practice

The fastest way to identify hidden control gaps is to treat manual work as a control signal. If identity teams are repeatedly handling the same requests by hand, the control is probably missing, incomplete, or only partially adopted. Mature programmes look for patterns across ticket queues, IAM logs, HR-triggered offboarding events, privileged access approvals, and manual recertification outcomes. The question is not only “how many tickets were raised?” but “which controls should have prevented the tickets altogether?”

Practitioners usually map the repeated manual tasks to control domains:

  • Access requests that bypass policy automation suggest weak role design or absent policy-as-code enforcement.
  • MFA reset tickets may indicate broken recovery flows, unsupported apps, or inconsistent identity federation.
  • Delayed offboarding usually points to poor joiner-mover-leaver integration and missing ownership for deprovisioning.
  • Manual access reviews often mean entitlements are not well modelled, or the application cannot support reliable attestation.

For NHI-heavy environments, the same logic applies to service accounts, API keys, certificates, and automation tokens. NHIMG’s Ultimate Guide to NHIs highlights the importance of lifecycle control, rotation, and visibility because manual exception handling tends to leave secrets and privileges in place long after they should have been revoked. NIST’s Cybersecurity Framework 2.0 is useful here because it pushes teams to measure whether controls are consistently implemented, not merely documented.

A practical assessment often includes sampling a few high-friction workflows, checking whether the same approval path appears across multiple apps, and identifying where identity automation stops at the perimeter of legacy or custom systems. These controls tend to break down when organisations operate fragmented directories, unmanaged SaaS sprawl, or bespoke applications that cannot consume central policy decisions or lifecycle events.

Common Variations and Edge Cases

Tighter identity automation often increases integration cost and change-management overhead, requiring organisations to balance control consistency against application complexity. That tradeoff matters because not every app can support modern federation, event-driven offboarding, or automated attestation, and some legacy platforms will continue to need compensating controls.

Current guidance suggests treating these exceptions as measurable risk, not as permanent normality. A disconnected system that requires manual access reviews should be tagged as an explicit control gap with an owner, a remediation target, and a compensating safeguard such as scoped PAM, shorter credential TTLs, or stronger monitoring. The same is true for access exceptions that keep reappearing: if a workflow is repeatedly manual, the organisation should ask whether the underlying entitlement model is wrong rather than merely understaffed.

There is no universal standard for how much manual intervention is acceptable, but best practice is evolving toward control coverage metrics that show where automation exists, where it fails, and where human approval is the only remaining safeguard. For practitioners, the key distinction is between temporary exception handling and chronic manual dependency. The former can be governed; the latter usually means the control estate is incomplete. NHIMG’s 52 NHI Breaches Analysis and JetBrains GitHub plugin token exposure illustrate how hidden identity gaps persist when organisations assume the presence of a process means the control is actually working.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC, PR.AC Manual identity work often signals weak governance and inconsistent access control coverage.
OWASP Non-Human Identity Top 10 NHI-02 Hidden gaps often appear in service accounts, keys, and other non-human identities.
NIST AI RMF GOVERN Identity automation gaps are a governance issue because they create inconsistent control accountability.
NIST Zero Trust (SP 800-207) Section 2.1, Section 3.1 Repeated manual exceptions undermine zero trust by preserving implicit trust paths.
CSA MAESTRO IAM and policy enforcement themes Agentic and automated workloads expose the same manual control gaps at machine speed.

Map recurring tickets to missing control owners and close gaps where access is still handled manually.