Teams end up certifying accounts that are still entitled but no longer justified by use. In practice, that means dormant seats, stale API keys, and unused admin permissions stay open because the review process sees status, not behaviour.
What breaks when access review ignores actual use?
The review becomes a paper exercise instead of a control. If you only check whether someone still has a Claude entitlement, you can miss that the account is no longer used, that an API key is idle but valid, or that an admin role is technically assigned but functionally dead. The result is retained access that looks justified on paper and stale in practice.
That matters because entitlement recertification is supposed to answer a different question from ownership or employment status. The real control question is whether the access is still needed for current work, current integrations, and current risk tolerance.
Why status-based review overstates approval
Status tells you that an account exists and may still belong to an approved user or system. It does not tell you whether the entitlement is actively exercised, whether the secret is embedded in a forgotten workflow, or whether the permission has become an unused but exploitable path. When telemetry is absent, reviewers tend to approve whatever still appears assigned, which is how dormant seats and stale credentials survive cleanup.
Anthropic Claude evaluation incidents 2026 is a useful reminder that Claude access can be part of a live attack surface, not just a licensing record. A review process that does not incorporate behavioural evidence cannot distinguish a legitimately retained integration from one that has simply gone quiet.
The same problem applies to service credentials and administrative permissions. If no one can see whether a key has been used recently, every still-valid secret looks equally acceptable, even when one of them has not been exercised for months.
Why activity telemetry changes the decision
Activity telemetry adds the missing proof of use. It lets a reviewer compare entitlement with behaviour: recent API calls, interactive logins, tool invocations, failed authentications, and admin actions. That turns review from “does this exist?” into “is this still necessary, and is it being used in the way we expect?”
Nx s1ngularity attack 2025 shows why this matters operationally. Compromised publishing tokens, leaked secrets, and AI CLI abuse all benefit from credentials that remain valid longer than their legitimate use justifies. Telemetry does not replace access control, but it gives reviewers a way to spot stale standing access before it becomes a persistence path.
Without that signal, teams frequently over-certify. They preserve access because nobody can prove it is idle, not because anyone can prove it is needed.
What the review process should prove before it approves access
Effective review should confirm that the access is both authorised and active for a current business or operational purpose. If the entitlement is for a human user, reviewers should look for recent use that aligns with role expectations. If it is for an API key or admin credential, they should confirm a current integration, owner, and rotation path. If none of that can be shown, the safer assumption is that the access is stale.
For Claude-related access, that means reviewers should not treat “still assigned” as equivalent to “still needed.” A seat with no activity evidence, a key with no recent calls, or an admin permission with no recorded use should trigger remediation, not automatic approval.
Risk and Threat Considerations
When access review ignores telemetry, unused but valid credentials stay available for misuse, theft, or reactivation. That creates avoidable exposure because dormant access is easy to overlook, hard to defend in a spreadsheet, and often more dangerous than active access precisely because nobody is watching it closely.
Failure mechanism: Reviewers certify status instead of use, so stale entitlements, dormant secrets, and unused administrative permissions remain valid long after their legitimate purpose has ended.
Impact: Attackers inherit a larger pool of low-visibility access paths, and organisations keep paying for or trusting access that no longer has a defensible business need.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-07 — Long-Lived Secrets | Idle Claude keys and unused permissions are long-lived secret risk. |
| NHI-05 — Overprivileged NHI | Unused admin permissions remain excessive if activity is not checked. | |
| Recommendation — Rotate or remove secrets that have no recent verified use. Trim privileges that are assigned but not operationally justified. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Reviews should verify and remove unnecessary access rights. |
| Recommendation — Review access against current business need and revoke stale entitlements. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | API keys and credentials need lifecycle control, not just status checks. |
| Recommendation — Track authenticator use and retire credentials that no longer serve a current purpose. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access-rights review must confirm continued need, not only assignment. |
| Recommendation — Recertify access using usage evidence and remove dormant rights. | ||
Practitioner Guidance
What to verify: Require recent activity evidence for each Claude seat, API key, or admin entitlement before approval. If the reviewer cannot point to a current workflow, integration, or operational owner, treat the item as a removal candidate rather than a renewal candidate.
Decision rule: If access is valid but unused, do not auto-renew it. Place it in a revoke-or-rejustify queue, because inactivity is often the strongest signal that the entitlement has outlived its purpose.
Practitioner takeaway: Access review is only meaningful when it tests whether the entitlement is still being used for something current, not merely whether it is still assigned.
Related resources from NHI Mgmt Group
- What breaks when dormant accounts are reviewed without activity context?
- What breaks when OneDrive is used without strong access controls and activity monitoring?
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?