Join our Newsletter — 33% off our NHI Course

What breaks when third-party access is not fully inventoried?

Identity governance loses visibility into the accounts, tokens, and certificates that actually extend trust into supplier environments. That creates hidden access paths, missed revocations, and scope drift that standard reviews often do not catch. The result is not just weaker oversight, but a broader attack surface that persists after the business reason for access has changed.

Why the inventory gap matters for third-party access

When third-party access is not fully inventoried, the problem is not just incomplete documentation. You lose the ability to answer a basic control question: who can still reach your systems through suppliers, contractors, integrations, and inherited trust paths, and under what conditions that access should still exist.

That matters because third-party access often spans multiple control planes, including human accounts, non-human credentials, and federated connections. A partial inventory can make an access relationship look clean in one system while still remaining active in another, which leaves revocation, review, and ownership decisions inconsistent.

Complete visibility is the difference between a bounded supplier relationship and a standing trust path that no one can confidently retire. For a broader control view, NHIMG’s IAM and IGA Basics explains why inventory, entitlement governance, and review are inseparable, and the Third-Party, B2B and Contractor Access Guide shows how supplier access should be governed as a lifecycle, not a one-time onboarding event.

What breaks operationally when access is only partially known

The first failure is revocation. If the inventory does not capture every account, token, certificate, or delegated path, offboarding becomes selective rather than complete. Teams may disable the obvious account while leaving behind shadow integrations, dormant service credentials, or alternate login routes that still work.

The second failure is review quality. Access recertification depends on a complete population. If the population is incomplete, reviewers approve a subset and assume they have covered the whole supplier relationship, which creates a false sense of control and lets scope drift accumulate between review cycles.

The third failure is accountability. Ownership is usually split across business, security, procurement, and the third party itself. Without an inventory, it becomes unclear which team is responsible for each access path, which slows exceptions, renewal decisions, and incident response when the supplier relationship changes.

In practice, this is why unmanaged tokens and stale credentials are so dangerous. NHIMG’s Salesloft OAuth token breach and Slack GitHub breach 2022 both show how a credential that outlives its intended use can remain a live trust path long after the original relationship has shifted.

How incomplete third-party inventories expand the attack surface

Incomplete inventory creates hidden access paths that attackers value because they are often harder to monitor than primary user accounts. A supplier token, support credential, or remote access key may bypass normal user review controls, especially when it is embedded in an integration or inherited through a platform relationship.

That hidden path also delays detection. If a credential is unknown to the inventory, it is less likely to be monitored for unusual use, rotated on schedule, or included in contingency actions after a supplier event. The result is persistence, not just access.

The risk is amplified when third-party access reaches privileged systems or sensitive datasets. NHIMG’s BeyondTrust breach 2024 is a useful reminder that a single exposed remote access key can become a high-impact pathway when supplier trust extends into privileged operations.

External guidance points in the same direction. OWASP Non-Human Identity Top 10 frames the common failure modes around secret leakage, overprivilege, and long-lived access, while MITRE ATT&CK Enterprise Matrix helps teams map how credential access and lateral movement can follow once a hidden trust path is found.

Risk and Threat Considerations

Partially inventoried third-party access is a control gap because it undermines least privilege, timely revocation, and visibility into inherited trust. The practical risk is that access survives the business need, which increases exposure even when the supplier relationship appears closed or reduced.

Failure mechanism: Unknown or untracked accounts, tokens, certificates, and federated paths evade review and offboarding, so revocation and monitoring only cover the visible subset of access.

Impact: Attackers can exploit stale or hidden access to persist, move laterally, or reach sensitive systems through a supplier trust path that defenders no longer actively manage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Third-party access gaps are an inventory and account lifecycle control problem.
Recommendation — Inventory external accounts and revoke stale third-party access paths on a fixed review cadence.
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Hidden supplier access commonly persists because offboarding misses all credentials and trust paths.
NHI-02 — Secret Leakage Undiscovered tokens and certificates create hidden trust paths that inventory should surface.
NHI-05 — Overprivileged NHI Incomplete inventories make it hard to see excessive supplier permissions and scope drift.
Recommendation — Track and revoke every third-party credential before closing the access relationship. Discover and rotate exposed third-party secrets as part of inventory reconciliation. Review third-party entitlements for least privilege and reduce access to the minimum needed.
NIST SP 800-53 Rev 5 AC-2 — Account Management Account inventories and lifecycle control are central to third-party access governance.
IA-5 — Authenticator Management Tokens and certificates are identity-bearing material that must be tracked and rotated.
Recommendation — Maintain a complete account inventory and disable third-party access when it is no longer required. Track, rotate, and revoke third-party authenticators on a defined schedule.

Practitioner Guidance

What to prioritise: Build the inventory from the access side, not just the vendor list. Start with all externally owned or externally enabled access paths, then reconcile them against actual system entitlements, token issuance, certificate issuance, and support channels.

What to verify: For each third party, verify that every access path has an owner, a business justification, an expiry or review date, and a revocation method that actually works across all connected systems. If you cannot prove revocation, treat the access as still active risk.

Common mistake: Teams often rely on procurement records or contract status as a proxy for live access. That misses machine-to-machine trust, delegated admin paths, and stale credentials that continue working after the commercial relationship has changed.

Practitioner takeaway: The inventory is not a reporting artifact, it is the control boundary that determines whether third-party access can be reduced, reviewed, and removed with confidence.