Yes. Separate reviews miss the combined risk of broad access with excessive privilege. An account can look acceptable on one dimension and still be overexposed on the other. Reviewing them together is the only way to see how far a mover has drifted from the current job need.
Why internal role changes need one joined review of access and admin rights
Internal movers are where entitlement drift hides. A person can keep a normal-looking application access profile while still carrying elevated admin power that no longer matches the new role, or the reverse. Reviewing both dimensions together lets managers see the real current exposure, not two separate snapshots that each look reasonable on their own.
That joined review is especially important when the move crosses functions, business units, or support tiers. In practice, the question is not only whether the new role needs access, but whether any retained admin path now creates standing privilege, separation-of-duties conflict, or a forgotten route into systems the person should no longer influence.
For a broader view of entitlement drift and review design, IAM and IGA Basics explains how access governance, role design, and mover events fit together.
What changes when access and admin are assessed together
Assessing access alone answers “can this person see or use the system?” Admin review answers “can this person change, approve, or override controls?” Those are different risk layers, and a mover can be clean on one while carrying excess on the other. Joined review prevents the common error of treating broad read or use rights as harmless when they sit beside powerful configuration or privileged functions.
It also helps identify when the new role still depends on legacy permissions that were acceptable in the old job but no longer support the person’s current duties. That matters because excess rights often accumulate through exception handling, temporary coverage, or inherited group membership, then persist after the move unless someone explicitly reconciles them against both job need and privilege level.
Good practice is to treat mover review as a single decision about effective authority, not two unrelated checks. If the access set and the admin set are reviewed by different teams or on different cycles, the organisation may miss the interaction between them and leave a user with far more reach than either review alone would show.
Where the role also involves privileged operations, Privileged Access Management Guide is useful for understanding how standing privilege, just-in-time access, and admin review should reinforce each other.
How to make the review operationally useful
The strongest review model starts from the new role profile, then checks all active access and all administrative capability against that target state. That includes application entitlements, group membership, delegated admin, break-glass paths, service consoles, approval rights, and any access inherited through shared roles. If the reviewer only compares old role to new title, they will miss transitive rights and indirect privilege.
Where teams want a deeper certification process, the review should close with a clear remove, retain, or exception decision for each material entitlement. A good outcome is not just “approved,” but “approved because it maps to the current job and creates no excess privilege.” When a permission survives the move only because it is hard to remove, that is a control weakness, not a valid entitlement.
For lifecycle handling of movers, leavers, and periodic entitlement cleanup, NHI Lifecycle Management Guide offers a practical model for reconciling provisioning, offboarding, and visibility so old rights do not linger.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Mover reviews are an account and privilege governance problem. |
| Recommendation — Review account changes and remove excess access when roles change. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Role changes should eliminate privileges no longer needed for the new job. |
| IA-5 — Authenticator Management | Role changes often require credential or secret reissue to prevent lingering access. | |
| Recommendation — Remove unnecessary permissions and admin rights after each role change. Rotate or revoke authenticators tied to the old role when access should change. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights must be reviewed and adjusted when employment or role changes occur. |
| A.5.16 — Identity management | Internal movers require identity lifecycle updates so old permissions do not linger. | |
| Recommendation — Recertify and adjust access rights after internal role changes. Update identity records and entitlements promptly when roles change. | ||
Practitioner Guidance
What to prioritise: Review the new role’s actual duties first, then compare every retained access path and every admin capability against that duties set. If the user keeps any privilege that can change configuration, approve access, or reach production systems outside the new remit, treat it as a removal or exception decision, not a routine approval.
What to verify: Confirm that the review covers direct access, inherited group access, delegated admin, and any legacy permissions that survive role changes through automation or manual exception. The control is only trustworthy if the reviewer can show both the current role need and the explicit reason each retained privilege remains.
Common mistake: Teams often certify access review and privileged access reviews separately, then assume the combined result is safe. That produces rubber-stamped approvals because neither review sees the full authority picture. The better test is whether the person’s effective power still matches the new job with no hidden privilege carryover.
Practitioner takeaway: A mover review should answer one question: what authority does this person effectively have now? If access and admin are judged in isolation, excess privilege survives more easily than it should.
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- Should organisations prioritise external exposure or internal credential governance first?
- When should organizations review access controls?
- How should organisations reduce risk from stale access after role changes or offboarding?