Join our Newsletter — 33% off our NHI Course

Why do lifecycle gaps keep showing up in access review campaigns?

Because joiner, mover, and leaver failures are not resolved before certification begins. Temporary access, contractor departures, and orphaned service accounts flow into the review as unresolved cleanup work, which makes the campaign a backstop for identity operations that should have already removed the exposure.

Why Lifecycle Gaps Keep Reappearing in Review Campaigns

access review campaigns expose lifecycle debt because they are often run after entitlement drift has already accumulated. If joiner, mover, and leaver changes are delayed, the review inherits temporary access, contractor access, stale exceptions, and accounts that no longer have a clear owner. The campaign then becomes a catch-up exercise instead of a control that confirms access is still justified.

That is why the same patterns return quarter after quarter: the review process can flag exposure, but it cannot retire it unless upstream identity operations have already done the cleanup. Organisations often treat certification as the place where bad access is discovered, when it should be the place where a small residue is validated, not a backlog is sorted. NHI Lifecycle Management Guide

In practice, many security teams only notice lifecycle weakness when reviewers are forced to approve or reject access they never intended to own in the first place.

How the Breakdown Shows Up in Practice

The mechanism is usually simple: identity lifecycle events happen in one system, while access reviews happen later in another. When those two rhythms are not aligned, the campaign receives whatever was never removed on time. That includes short-term access that should have expired, project access for people who moved roles, and service accounts that survived a decommissioned workload.

Once those items enter certification, reviewers face ambiguity. They may not know whether the access is still needed, who should answer for it, or whether removing it will break a live workflow. The result is predictable: approvals default to caution, denials are deferred, and exceptions get renewed because the cleanup path is unclear. A control that should be validating necessity ends up preserving uncertainty.

  • Joiner gaps create accounts that are over-provisioned from day one.
  • Mover gaps leave old entitlements attached after a role change.
  • Leaver gaps preserve access after departure or contract end.
  • Orphaned non-human identities become especially hard to certify because ownership is missing or disputed.

That is why lifecycle discipline matters more than review cadence. If the access origin, owner, and expiry are not accurate before the campaign starts, reviewers cannot make meaningful decisions; they can only react to leftover exposure. NHI Lifecycle Management Guide and the OWASP Non-Human Identity Top 10 both highlight how unmanaged non-human access becomes a persistent governance problem. Organisations also need a stable way to verify inventory and expiry data at scale, which is where lifecycle controls become more important than the review itself. Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs

These controls tend to break down when identity, HR, vendor, and cloud ownership data are inconsistent, because the review tool cannot reliably tell what should already have been removed.

Common Variations and Edge Cases

Tighter lifecycle control often increases operational overhead, because every temporary grant, role change, and exception needs a reliable expiry or owner. The benefit is cleaner certification, but the tradeoff is more dependency on accurate upstream data and faster offboarding discipline.

Some environments make the problem worse in specific ways. Contractors may be managed outside the core HR process, so their access expires late or not at all. Service accounts may be tied to applications rather than people, which makes the reviewer question whether the account is truly dormant or simply undocumented. In distributed teams, the approver may not be the person who understands the entitlement, so the campaign becomes a routing exercise instead of a decision point.

There is no universal standard for this yet, but current guidance suggests treating certification as a verification layer, not a cleanup layer. The better the lifecycle hygiene, the shorter and more decisive the review. The worse the lifecycle hygiene, the more the campaign becomes a repository for unresolved access debt, and the less trustworthy the approvals become as evidence of control.

For organisations with many non-human identities, the failure mode is often scale rather than intent: small lifecycle misses compound quickly when tokens, keys, and service accounts are created faster than they are retired. Guide to the Secret Sprawl Challenge

Risk and Threat Considerations

Lifecycle gaps create persistent overexposure because stale human and non-human access remains active long enough to be reused, abused, or simply forgotten. The risk is not only unnecessary privilege, but also weak accountability: if no one owns the entitlement, no one is reliably responsible for removing it.

Failure mechanism: When joiner, mover, and leaver events are not reconciled before certification, old access paths remain valid and can survive role changes, departures, and system retirements. Attackers and internal abusers benefit from these stale paths because they often bypass fresh approval scrutiny and may carry legitimate authentication.

Impact: Organisations inherit avoidable privilege exposure, larger blast radius, more false confidence in review outcomes, and a higher chance that dormant credentials or orphaned accounts will become the easiest route to compromise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Inventory and Ownership Lifecycle gaps create orphaned NHIs and unclear ownership across access review campaigns.
NHI-02 — Secrets and Credential Management Stale service accounts and leftover secrets often surface during access reviews.
NHI-03 — Lifecycle and Offboarding Joiner, mover, and leaver failures are the core cause of repeated review exceptions.
Recommendation — Inventory every NHI and assign accountable owners before certification starts. Rotate or revoke stale machine credentials before reviewers are asked to approve them. Automate offboarding and role-change revocation so reviews validate, not clean up, access.
CIS Controls v8 5 — Account Management Recurring review exceptions signal weak account provisioning and deprovisioning discipline.
6 — Access Control Management Campaigns are meant to validate least privilege after lifecycle changes.
Recommendation — Enforce timely account creation, modification, and removal with periodic reconciliation. Review and remove unnecessary access paths that persist after a user or role changes.
NIST CSF 2.0 PR.AA-01 — Identity Management, Authentication, and Access Control Lifecycle gaps weaken identity accuracy and ongoing access control.
GV.RM-03 — Risk Management Strategy Repeated lifecycle debt means review campaigns are absorbing unmanaged access risk.
Recommendation — Maintain current identity records and revoke access when the business need ends. Treat recurring certification findings as governance issues requiring upstream remediation.
MITRE ATT&CK T1078 — Valid Accounts Stale or orphaned access can remain a valid path for misuse or persistence.
Recommendation — Hunt for and remove valid accounts that no longer have a legitimate operational purpose.

Practitioner Guidance

What to prioritise: Start by separating review cleanup from lifecycle remediation. If a campaign repeatedly surfaces the same access, treat that as an identity operations defect, not as a reviewer performance problem.

Decision rule: If the entitlement would be hard to defend without a current business owner, expiry date, or system owner, remove or suspend it before certification begins rather than asking reviewers to rationalise it.

What good looks like: Reviewers should see a mostly accurate inventory where exceptions are rare, ownership is current, and temporary access has already expired unless there is a documented reason to extend it.

What practitioners underestimate: The campaign is often the first place that missing offboarding, poor vendor teardown, or unmanaged service-account creation becomes visible. If the same items recur, the control problem is upstream lifecycle governance, not the review workflow itself.

Practitioner takeaway: Access reviews are most effective when they validate a clean identity state; when they are used to discover and fix lifecycle debt, the organisation is certifying uncertainty instead of access.