Join our Newsletter — 33% off our NHI Course

What breaks when organisations enforce identity governance only at onboarding and not throughout the access lifecycle?

Point-in-time governance leaves stale entitlements, orphaned accounts, and unused privileges in place long after business conditions change. That gap weakens compliance, increases audit findings, and creates hidden access paths for attackers. Effective programmes need ongoing certification, revocation, and policy enforcement across joiner, mover, and leaver events.

Why This Matters for Security Teams

Onboarding-only governance creates a false sense of control because access is approved once and then treated as stable, even though roles, vendors, systems, and risk change continuously. That leaves stale entitlements, orphaned accounts, and excessive privileges active long after they stop being justified. The problem is especially visible in NHI estates, where a recent NHIMG research summary found that 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks.

Security teams often miss the fact that joiner-only controls do not protect the access lifecycle. A user or workload can be cleanly provisioned on day one and still become over-entitled by day thirty, whether through role drift, project changes, vendor handoffs, or automation that never got deprovisioned. Frameworks such as the NIST Cybersecurity Framework 2.0 and the OWASP Non-Human Identity Top 10 both point toward continuous control, not point-in-time approval.

In practice, many security teams encounter the real exposure only after an audit finding, a failed access review, or a breach investigation shows that “approved” access had quietly outlived its business purpose.

How It Works in Practice

lifecycle governance works when identity decisions are tied to ongoing business context, not just the initial account request. That means every meaningful change in employment status, project assignment, vendor relationship, or machine workload should trigger review, reduction, or revocation. For human users, this usually spans joiner, mover, and leaver events. For NHIs, it also includes key rotation, secret expiry, token revocation, and ownership changes across CI/CD, cloud, and API ecosystems.

Practitioners should treat onboarding as the start of control, not the finish. A workable programme usually combines:

  • Periodic access certification for privileged and sensitive access
  • Automatic revocation when accounts are unused, expired, or unowned
  • Short-lived credentials and secret rotation for non-human identities
  • Policy checks aligned to business role, system sensitivity, and time bound need
  • Logging that proves access was reviewed and removed, not merely approved

That approach is consistent with the control intent behind NIST CSF 2.0 and the control discipline described in NHI Lifecycle Management Guide. For teams managing secrets at scale, the Guide to the Secret Sprawl Challenge is a useful reference because stale credentials are often the technical symptom of weak lifecycle governance. These controls tend to break down in environments with unmanaged service accounts, shadow IT, or legacy applications that cannot support automated deprovisioning because ownership and revocation paths are unclear.

Common Variations and Edge Cases

Tighter lifecycle governance often increases operational overhead, requiring organisations to balance stronger assurance against the friction of reviews, exceptions, and service disruption. That tradeoff is real, especially where business teams depend on always-on access, but the alternative is allowing dormant privilege to accumulate unnoticed.

Best practice is evolving, and there is no universal standard for how often every entitlement should be recertified. High-risk access usually warrants shorter review cycles, while low-risk, low-impact access may be reviewed less often. The key is to avoid treating all identities the same. An inherited admin role, a third-party OAuth grant, and a dormant contractor account do not carry the same risk profile.

For NHIs, lifecycle failures often show up differently than for human users. Secrets may never “leave” unless rotation is enforced, so onboarding-only governance can be especially dangerous when systems issue long-lived tokens or certificates. The Guide to NHI Rotation Challenges helps illustrate why rotation and revocation are inseparable from governance. The practical lesson is simple: if access can be created in minutes but removed only manually, the organisation is carrying avoidable residual risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-03 Addresses stale NHI credentials and weak rotation across the access lifecycle.
NIST CSF 2.0 PR.AA-01 Identity lifecycle control is central to governing who can access what over time.
NIST SP 800-63 IAL2 Lifecycle governance depends on maintaining assurance as identity context changes.
NIST Zero Trust (SP 800-207) AC-2 Zero Trust requires continuous access decisions, not one-time onboarding approval.
NIST AI RMF Lifecycle governance supports ongoing accountability and risk monitoring for AI-driven access.

Apply governance and monitoring processes that reassess identity risk as conditions change.