Periodic access review checks whether access was justified at a point in time, while continuous authorisation checks whether it is still justified as conditions change. The first is retrospective and slow, the second is live and conditional. In practice, organisations need both, but only continuous authorisation can close the window between change and enforcement.
Why periodic review answers a different question than live authorisation
Periodic access review and continuous authorisation both test whether access should continue, but they do so on different clocks. Review is a point-in-time governance activity: it checks whether access still makes sense based on evidence and ownership. Continuous authorisation is an enforcement model: it keeps evaluating whether the same access remains valid as the environment, risk, or context changes.
The practical difference is that review can confirm what was acceptable last week, while continuous authorisation can stop what is no longer acceptable now. That makes the first better for certification, attestation, and cleanup, and the second better for live access decisions where conditions can shift quickly.
Where the control boundary moves from governance to enforcement
Periodic review usually sits in the governance layer. It helps answer whether access is justified, whether the approver still exists, and whether the right owner is accountable for the entitlement. It is often used to reduce access creep and close out stale permissions, but its weakness is timing: access can remain active between review cycles.
Continuous authorisation sits closer to the decision point. It treats access as conditional on current signals, such as context, session state, location, device posture, transaction risk, or policy changes. For that reason, it is most useful when the cost of delay is high and the access decision must change as soon as the risk changes.
How to choose between them in practice
Most organisations should treat periodic review and continuous authorisation as complementary, not competing. Review is the right mechanism when you need accountability over broad entitlement sets, especially where human approvers, audit evidence, or formal recertification are required. Continuous authorisation is the right mechanism when you need immediate enforcement against drift, abuse, or changing conditions.
That distinction matters because a clean review programme does not prevent a risky session from persisting, and a strong live policy does not replace the need to prove who owns access and why it exists. If you only do review, you may find problems late. If you only do continuous authorisation, you may lose the governance evidence needed to justify access decisions over time.
Risk and Threat Considerations
Access review and continuous authorisation fail in different ways. Review creates a window where excess access can stay active until the next cycle, while continuous authorisation can fail if the policy inputs are stale, incomplete, or too noisy to enforce reliably. The main risk is believing that one control compensates for the blind spot of the other.
Failure mechanism: Review misses the gap between certification cycles, so access that has become inappropriate remains usable; continuous authorisation misses current context if policy signals, telemetry, or enforcement points are weak.
Impact: Stale privilege, delayed revocation, and avoidable exposure to misuse, lateral movement, or unauthorised action can persist longer than intended.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Periodic review and revocation depend on managing account and entitlement lifecycle. |
| AC-6 — Least Privilege | Both review and live authorisation exist to keep access limited to what is needed. | |
| AC-3 — Access Enforcement | Continuous authorisation depends on enforcing current policy at the decision point. | |
| Recommendation — Use AC-2 to recertify accounts and remove stale access on a defined schedule. Apply AC-6 to bound permissions and reduce standing access. Use AC-3 to enforce policy decisions as conditions change. | ||
| NIST Zero Trust (SP 800-207) | 3.2 — Policy Decision Point / Policy Enforcement Point | Continuous authorisation relies on real-time policy decisions and enforcement. |
| Recommendation — Separate decision and enforcement so access can be re-evaluated continuously. | ||
| NIST CSF 2.0 | PR.AA-05 — Least Privilege | The question is fundamentally about keeping access justified over time. |
| Recommendation — Align access review and live control decisions to least-privilege intent. | ||
Practitioner Guidance
What to prioritise: Use periodic review to establish ownership, entitlement justification, and recertification evidence; use continuous authorisation where the access decision itself must react to changing risk in real time.
What to verify: The review process should actually remove or reissue access, not just collect approvals. For continuous authorisation, verify that policy changes propagate fast enough to matter and that the enforcement point can act on current signals.
Practitioner takeaway: Treat review as proof that access was once acceptable, and continuous authorisation as protection that access is still acceptable.
Related resources from NHI Mgmt Group
- What is the difference between periodic access review and continuous AI audit?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between protecting applications and protecting access?