Join our Newsletter — 33% off our NHI Course

Why do NHIs need separate access review campaigns instead of human recertification workflows?

NHIs need separate campaigns because their access is often tied to systems, teams, or pipelines rather than employees. That changes who can approve changes, who should be notified, and what evidence proves action. A machine identity review must therefore track remediation state and owner response, not just reviewer certification.

Why NHI access reviews are not the same as human recertification

Human recertification assumes a person, a manager, and a stable employment relationship. NHI campaigns usually start from a system, pipeline, application, or service owner, and the real question is whether that access still matches the integration’s purpose and risk. That changes the approval path, the evidence required, and the remediation workflow.

NHI campaigns also need to reflect how the identity is used. A service account may support one production flow, many workflows, or a third-party integration, so “approve or remove” is rarely enough. The review has to confirm ownership, dependency, and whether the access is still needed by the system that depends on it, not just whether a named person still wants it.

For a broader identity baseline, the distinction is captured well in IAM and IGA Basics, which separates access governance from simple user access administration.

What a machine identity review must prove

An effective NHI review checks three things that human recertification often leaves implicit: the technical owner, the business or application dependency, and the remediation path if access is no longer justified. If any of those are missing, the campaign can produce paper approval without reducing exposure.

This is why good NHI review design often borrows from lifecycle thinking. The question is not only “should this access exist today?” but also “who will respond if it is stale, overprivileged, or tied to an abandoned pipeline?” A review campaign that cannot assign ownership or close the loop is usually a discovery exercise, not a governance control.

The lifecycle lens is described in NHI Lifecycle Management Guide, which connects provisioning, rotation, offboarding, visibility, and access review into one control loop.

That is also why Access Reviews and Certification Guide is useful here, because it treats review campaigns as a mechanism for removing access and closing remediation, not just collecting signatures.

How the workflow changes in practice

Human recertification usually routes to a manager or application owner and asks whether the user should still have access. NHI review campaigns often need a different routing model, because the right approver may be a platform team, pipeline owner, service owner, or system custodian. In many cases, the person who can confirm necessity is not the person who can safely make the change.

The review record also needs stronger remediation evidence. For NHIs, a good outcome is not just “approved” or “denied.” It is whether the credential was rotated, the permission set was reduced, the integration was retired, or the owner explicitly accepted the residual risk. That is a different evidence model from standard employee certification.

When ownership is unclear, NHI Ownership and Accountability Guide is the clearest companion resource, because unresolved ownership is usually the reason review campaigns stall.

For teams handling service accounts directly, Service Account Security Guide adds the operational detail needed to review machine identities that are embedded in applications and infrastructure.

Risk and Threat Considerations

NHI reviews create real exposure when organisations reuse human recertification patterns without changing the workflow. The common failure mode is rubber-stamping: a reviewer certifies access they cannot actually evaluate, while stale credentials, overprivilege, or orphaned integrations remain active.

Failure mechanism: approvals are routed to the wrong owner, remediation is not tracked to completion, or the evidence is too thin to show that the access change actually happened. In that case, the campaign becomes administrative noise rather than control enforcement.

Impact: stale machine access can persist unnoticed, expanding the blast radius of compromise, keeping abandoned pipelines alive, and hiding privilege drift until a downstream incident exposes it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management NHI reviews validate whether accounts still need access and who owns removal.
IA-5 — Authenticator Management Machine reviews often expose long-lived secrets and credentials that need lifecycle control.
AC-6 — Least Privilege NHI campaigns are meant to remove excess permissions, not just renew approval.
Recommendation — Use AC-2 to review, disable, and remove stale machine accounts on a defined schedule. Use IA-5 to rotate, replace, and retire machine authenticators on a controlled lifecycle. Use AC-6 to trim each NHI to the minimum access needed for its current function.
ISO/IEC 27001:2022 A.5.15 — Access control NHI review campaigns are an access control process that must govern non-human access separately.
A.5.16 — Identity management NHI campaigns depend on owning and tracking machine identities across their lifecycle.
A.5.18 — Access rights Recertification must confirm that access rights still match the service or pipeline need.
Recommendation — Apply A.5.15 to define review and approval rules for non-human access. Apply A.5.16 to keep machine identity ownership and status current. Apply A.5.18 to recertify and remove unnecessary machine access rights.
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Separate campaigns help ensure NHIs are removed when integrations or owners disappear.
NHI-05 — Overprivileged NHI Machine reviews exist to detect and reduce access that exceeds current operational need.
NHI-07 — Long-Lived Secrets NHI reviews often reveal secrets that stay valid far too long without reassessment.
Recommendation — Use NHI-01 to offboard abandoned identities and revoke their access. Use NHI-05 to reduce excessive machine permissions during review campaigns. Use NHI-07 to identify and replace long-lived credentials during review.
CIS Controls v8 CIS-5 — Account Management Separate campaigns improve discovery, approval, and removal of machine accounts.
Recommendation — Use CIS-5 to inventory accounts and remove unused or excessive machine access.

Practitioner Guidance

What to prioritise: Build NHI review campaigns around ownership and remediation, not around the human manager model. If the identity can change production state, the review must end with a verifiable action, such as rotation, revocation, scope reduction, or documented risk acceptance.

What to verify: Every reviewed NHI should have an accountable owner, a current purpose, and a clear dependency map. If reviewers cannot explain what breaks when access is removed, the campaign is not ready for approval.

Practitioner takeaway: Human recertification asks whether a person still deserves access, but NHI review asks whether a system still needs it and whether the organisation can prove the cleanup happened.