Join our Newsletter — 33% off our NHI Course

Should IAM teams prioritise orphaned accounts or authorization documentation first?

They should usually start with orphaned accounts if the live identity estate is poorly controlled, because stale accounts create direct access risk. If the inventory is broadly clean, then updating the authorization concept may deliver faster governance value and stronger audit evidence across the next review cycle.

Which Should Come First: Orphaned Accounts or Authorization Documentation?

Prioritisation depends on the state of the identity estate, but the practical rule is simple: if live accounts are already stale, disconnected from ownership, or hard to inventory, clean that up first because it reduces immediate access risk. If the inventory is already reasonably trustworthy, improving authorization documentation can create faster governance gains and better audit evidence.

Why Orphaned Accounts Usually Win When Inventory Quality Is Poor

Orphaned accounts create an active security problem, not just a records problem. They can retain access after a role change, project exit, vendor offboarding, or application retirement, which means the organisation may be unable to explain who can still act, why they can act, or whether the access should exist at all.

That is why lifecycle controls and ownership clarity matter. NHIMG’s Joiner-Mover-Leaver (JML) Guide and NHI Ownership and Accountability Guide both reflect the same operational reality: if you cannot reliably assign or remove ownership, access tends to linger past its intended life. That lingering access is often the highest-risk gap because it affects real permissions, not just policy wording.

Orphaned-account cleanup also tends to expose other hidden problems, such as dormant entitlements, shared credentials, and inconsistent deprovisioning paths. In other words, once the estate is messy, the first useful question is often “what still exists and who still controls it?” rather than “how is access supposed to be described?”

When Authorization Documentation Becomes the Better First Move

If the account inventory is broadly clean and ownership is clear, authorization documentation can be the higher-value first step. In that situation, the main problem is usually not unknown access, but weak traceability of why access exists, which roles or policies grant it, and how reviewers should interpret exceptions during recertification or audit.

That is where access model clarity helps. NHIMG’s IAM and IGA Basics and Authorisation Models Guide are relevant because they separate authentication, authorization, and entitlement design. If the team can already identify the actors and accounts correctly, then improving role, policy, or entitlement documentation may give faster governance value than another discovery sweep.

Well-written authorization documentation also shortens review cycles. Reviewers can validate whether a role is still needed, whether access is too broad, and whether the current model matches the business process without first reconstructing the whole estate from scratch.

How to Sequence the Work Without Losing Time

A sensible sequence is to treat orphaned-account remediation as the first control when uncertainty is high, then move to authorization documentation once the live inventory is stable enough to trust. That sequence avoids polishing policy language around identities that should already have been removed.

Where the estate is stable, reverse the order only if the documentation gap is blocking governance decisions. A concise rule is: fix unknown or ownerless access before you refine the wording around known access. After that, improve the authorization model so future access reviews, approvals, and exception handling are easier to execute consistently.

The strongest supporting evidence for this kind of prioritisation is usually operational, not theoretical. If the team cannot answer “who owns this account?” or “why does this entitlement still exist?” without manual investigation, orphaned-account work should come first. If those questions are already answerable, then the documentation gap is likely the faster path to cleaner governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Account inventory and orphaned-account cleanup are core account-management concerns.
Recommendation — Inventory accounts, remove orphaned access, and keep account ownership current.
NIST SP 800-53 Rev 5 AC-2 — Account Management The question centers on removing stale accounts and governing account lifecycle.
AC-6 — Least Privilege Authorization documentation determines whether access is more than the minimum needed.
Recommendation — Maintain an account lifecycle process that disables or removes orphaned accounts promptly. Document and review entitlements so access stays limited to least privilege.
ISO/IEC 27001:2022 A.5.18 — Access rights Access-right review and removal directly align to deciding between cleanup and documentation.
A.5.15 — Access control The question is about how to govern access first, either by cleanup or by model definition.
Recommendation — Review and remove unnecessary access rights on a defined schedule. Define, document, and enforce access control rules before recurring review cycles.

Practitioner Guidance

What to prioritise: Start with orphaned accounts when ownership, lifecycle status, or removal history is uncertain. That is the better first move whenever there is a realistic chance that live access outlasts business need.

What to verify: Before investing in authorization documentation, verify that the account inventory is materially complete, ownership is assigned, and deprovisioning is working for both human and non-human accounts. If those basics are not reliable, the documentation effort will understate the true risk.

Decision rule: If you would not trust the current access list in an audit or incident response, prioritise cleanup first. If the access list is trustworthy, prioritise the authorization model, because that is what improves recurring governance, review quality, and control evidence.

Practitioner takeaway: The right first task is the one that removes the most uncertainty from the live control plane, because governance only improves when the organisation can trust both who has access and why that access exists.