Utilities should move routine access administration into governed workflows that handle onboarding, role changes, and leavers consistently across business and operational systems. The main goal is to remove dependence on ad hoc approvals and spreadsheet-driven tracking, because that is where stale access and audit gaps accumulate. Automation is most valuable when it preserves evidence as well as speed.
Why manual access governance breaks down in utilities
Manual access governance fails when the process depends on people remembering every joiner, mover, leaver, and exception across both office and operational environments. Utilities often have long-lived accounts, shift-based access, contractors, and mixed IT and operational technology estates, so a spreadsheet or email chain cannot reliably show what is active, who owns it, or when it should be removed.
The failure is usually not a single bad approval. It is the accumulation of small misses, a role change not reflected everywhere, a leaver not fully removed, a temporary exception that never expires, or a shared account that outlives its owner. Over time, that creates stale access, weak accountability, and audit evidence that is incomplete or hard to reconstruct.
That is why structured lifecycle control matters more than ad hoc review, and why utilities benefit from treating IAM and IGA basics as an operating model rather than a tooling choice. The question is not whether access can be approved manually, but whether the organisation can prove that every approval, change, and removal was applied consistently.
What good governed workflows replace
Governed workflows replace one-off approvals with repeatable handling of onboarding, role changes, and leavers. In practice, that means access requests are tied to a named source of truth, changes are routed through defined approvals, and removal is triggered by events such as termination, role transfer, or contract end rather than by memory or periodic cleanup.
This approach also makes role design and lifecycle rules visible. If the workflow cannot distinguish between a temporary elevated task, a standing business role, and privileged operational access, it will eventually recreate the same manual failure in a slower form. A useful control design keeps business systems, operational systems, and privileged paths aligned enough that access can be granted and revoked without separate human tracking layers.
For recurring onboarding and offboarding activity, the Joiner-Mover-Leaver (JML) Guide is the clearest internal navigation point, because it maps the exact lifecycle moments where access drift usually begins. Where access decisions depend on a stable job function, role engineering becomes equally important, and the Role Mining and Role Design Guide helps avoid turning every request into a bespoke exception.
Utilities also need to remember that lifecycle control is not only about humans. A workflow that manages only employee accounts but ignores service accounts, shared credentials, or automation identities will leave the riskiest access outside the process. That is why the Lifecycle Processes for Managing NHIs remains relevant even in a largely human access governance question: the same lifecycle discipline has to reach machine and operational identities too.
How to keep evidence, reviews, and segregation from becoming paper controls
Automation only reduces risk when it preserves evidence and forces closure. If approvals happen in one system but removals happen somewhere else, or if reviews are generated but never drive revocation, the organisation has simply digitised the spreadsheet problem. The control should produce a record of who approved, what changed, when it changed, and whether the resulting access state was actually reconciled.
This is also where recertification and segregation of duties become operational, not ceremonial. Reviews must identify whether access still matches the current role and whether any combinations of privilege are now unsafe. If utility teams treat these as periodic compliance events, they will miss the exact cases manual governance is worst at finding, namely dormant access, inherited access, and conflicting access that spans multiple systems.
Where access review quality matters, the Access Reviews and Certification Guide supports the practical side of closing the loop, while the Segregation of Duties (SoD) Guide is useful when the real risk is conflicting authority rather than simple excess access. Both help move governance from documentation to enforced control.
Utilities that want audit-ready access governance should also make ownership explicit, because nobody can remediate what nobody is accountable for. The Identity Visibility and Intelligence Platforms (IVIP) Guide is useful where the hard part is simply seeing what access exists and where it came from, especially when business and operational estates do not share the same administration model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Utilities need governed account lifecycle handling for onboarding, movers, and leavers. |
| AC-6 — Least Privilege | Manual governance failures often leave excessive standing access in place. | |
| AU-2 — Event Logging | Access governance must preserve evidence of who approved and what changed. | |
| Recommendation — Automate account provisioning, modification, and deprovisioning through controlled workflows. Restrict access to the minimum required and remove unnecessary privileges promptly. Log access requests, approvals, changes, and removals for auditability. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights need controlled issuance, review, and removal across lifecycle events. |
| A.5.15 — Access control | The topic is about reducing access governance failure through controlled administration. | |
| Recommendation — Establish formal access-rights management for granting, changing, reviewing, and revoking access. Define and enforce access control rules that limit ad hoc approvals and standing exceptions. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Utilities need managed access administration instead of spreadsheet-driven tracking. |
| CIS-5 — Account Management | Joiner-mover-leaver failures are account lifecycle failures in practice. | |
| Recommendation — Centralise access control and review processes to remove stale or excessive permissions. Automate account lifecycle events and disable or remove dormant access quickly. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | The question focuses on access governance, approvals, and lifecycle control. |
| Recommendation — Apply consistent identity and access controls across the full access lifecycle. | ||
Practitioner Guidance
What to prioritise: Start with joiner, mover, and leaver paths that affect privileged and operational access, because that is where manual drift creates the largest blast radius. Then extend the same workflow discipline to contractors, shared accounts, and automation identities.
What to verify: Before trusting the control, verify that the workflow actually triggers removal, not just approval, and that the resulting access state is reconciled against the authoritative source. If evidence cannot show who approved, who executed, and what was removed, the process is still too manual.
Common mistake: Treating automation as a speed layer on top of the old process. If the organisation keeps spreadsheet logic, inbox approvals, or offline exceptions, it will preserve the same governance gaps at higher volume.
What good looks like: Access changes are event-driven, traceable, and closed loop, with clear ownership for each system and a repeatable way to prove that stale access has been removed.
Practitioner takeaway: The objective is not to automate approvals for their own sake, but to make access changes deterministic, evidence-backed, and revocable across the full lifecycle of each identity.