Provisioning-only IAM fails when it changes access state but leaves privilege, segregation of duties, and lifecycle risk untouched. Accounts can be created and removed efficiently while excess entitlements, stale access, and inconsistent audit evidence continue to accumulate across connected systems.
Provisioning Is an Access State Change, Not a Governance Model
Provisioning-only IAM changes who can log in, but it does not decide whether that access should exist, how long it should last, or what the identity is allowed to do. The missing layer is policy governance: entitlement design, review, segregation of duties, and lifecycle control. Without it, accounts may be efficient to create and remove, yet still drift into overprivilege and audit gaps.
That is why IAM should be treated as an operating model, not a ticketing workflow. If the control plane only creates accounts, the organisation still has to answer who owns the entitlement model, who approves exceptions, and how access is recertified when roles, systems, or risk change. A provisioning engine can execute policy, but it cannot replace policy.
In practice, this distinction is why mature programmes pair account lifecycle with access governance. NHIMG’s IAM and IGA Basics is useful here because it separates authentication and provisioning from authorization, entitlement management, and review. The same separation is reflected in the broader lifecycle view in the NHI Lifecycle Management Guide, where provisioning is only one stage in a control process that also includes rotation, offboarding, and recertification.
What Breaks When Policy Is Missing
The first failure is privilege creep. If access is granted once and never re-evaluated, users, service accounts, and applications accumulate entitlements that no longer match current duties. The second failure is segregation of duties, because provisioning alone does not stop conflicting access paths from being assigned across separate systems. The third failure is evidentiary, since audit teams cannot rely on account existence as proof that access was appropriate at the time it was used.
Policy also matters across connected systems. A single identity may be provisioned correctly in one platform while retaining stale rights elsewhere, especially when entitlements are duplicated or ownership is unclear. That is why lifecycle-oriented control is not just about creation and deletion, but about synchronized review, revocation, and exception handling. NHIMG’s Joiner-Mover-Leaver (JML) Guide is relevant because movers and leavers are exactly where provisioning-only IAM tends to fail most visibly.
For organisations that want a broader operating model rather than a narrow admin process, the Identity Security Programme Guide is a good reference point. It frames IAM as governance, ownership, and roadmap, not just account administration. That matters because unmanaged entitlements usually persist where there is no clear business owner for access decisions.
Why Audit Evidence and Least Privilege Start to Drift
Provisioning-only IAM often looks healthy in dashboards because account counts, onboarding SLAs, and deprovisioning completion rates can all be good while actual access quality gets worse. The missing signal is entitlement validity. If no policy layer checks whether privileges are still needed, evidence becomes misleading: the system can prove that an account exists, but not that its current permissions are justified.
That gap is where least privilege fails operationally. Rights are not excessive only at birth, they become excessive over time as roles change, temporary access expires late, and inherited permissions remain in place. If governance is absent, remediation also becomes harder because there is no baseline for normal access, no owner to approve exceptions, and no routine to challenge dormant or high-risk access paths. NHIMG’s Top 10 NHI Issues is relevant because the same lifecycle and governance failures show up in machine and service identities as well as in human accounts.
For practitioners looking at cloud and platform environments, the failure is usually more visible in effective permissions than in issued accounts. The Cloud PAM and CIEM Guide is a useful companion because it focuses on actual privilege, not just identity presence. Provisioning tells you the account exists; governance tells you whether that account should still have the access it has.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Accounts must be provisioned, reviewed, and removed under policy control. |
| AC-5 — Separation of Duties | Policy governance must prevent conflicting access from being granted together. | |
| AC-6 — Least Privilege | Provisioning alone does not constrain standing permissions to what is needed. | |
| Recommendation — Enforce account lifecycle reviews and disable access when it is no longer justified. Define conflicting entitlements and block incompatible access assignments. Restrict entitlements to the minimum required and remove excess access promptly. | ||
| NIST CSF 2.0 | PR.AA-05 — Least Privilege | The question is about policy-driven access limitation beyond simple account creation. |
| Recommendation — Apply least-privilege rules to entitlements, not just to account provisioning. | ||
Practitioner Guidance
What to verify: Confirm that every birthright, exception, and inherited entitlement has an owner, an expiry or review point, and a business justification. If you cannot trace a permission to an accountable decision, the IAM process is provisioning accounts, not governing access.
Decision rule: If your IAM metrics stop at account creation, treat the programme as incomplete. Add entitlement review, segregation-of-duties checks, and stale-access removal before claiming access governance maturity.
What good looks like: Access changes are policy-driven, reviews produce deltas, and deprovisioning removes rights across all connected systems, not only the primary directory. The useful outcome is not more accounts created faster, but fewer unjustified permissions surviving past their need.
Practitioner takeaway: Provisioning is the mechanism that turns policy into accounts; governance is the mechanism that keeps those accounts justified. If policy is missing, the organisation is left with efficient identity administration and weak authorization control.