Because authorization logic can be correct while the underlying identity data is stale. If roles, attributes, approvals and offboarding are not continuously maintained, access decisions drift away from business reality and over-access persists.
Why access control models can be correct and still drift from governance
Access control models often define the right logic for a point in time, but governance depends on the identity data feeding that logic staying current. When roles, attributes, approvals and joiner-mover-leaver changes are not continuously maintained, the policy engine can keep making “valid” decisions against outdated reality. That is why over-access can survive even in well-designed models.
The gap is usually not the model itself, it is the control loop around it. Authorisation Models Guide is useful here because RBAC, ABAC and ReBAC only stay trustworthy when the business meaning behind roles, attributes and relationships is actively governed. The governance problem appears when access rules are static, but the organisation is not.
That is why models that look precise on paper can still produce stale outcomes in production. IAM and IGA Basics helps frame the split between authorization logic and governance operations, while Role Mining and Role Design Guide shows how role quality, role ownership and role lifecycle affect whether a model remains aligned with the business.
What actually creates the governance gap
Most governance gaps come from drift between three things: the access model, the source data and the operating process. A role can still be “correct” for a job family even after the person changed teams, an attribute can still be syntactically valid even after a business process changed, and an approval can still exist even after the approver lost context. The model is not failing if the surrounding data and workflows are stale.
This is why lifecycle discipline matters as much as policy design. NHI Lifecycle Management Guide is a strong analogue for the broader governance pattern: provisioning, rotation, offboarding and visibility all need continuous maintenance, not one-time setup. In practice, governance fails when ownership, recertification and deprovisioning are treated as periodic admin tasks instead of ongoing control points.
Access reviews help, but only if they are connected to remediation. Access Reviews and Certification Guide is relevant because review volume without closure creates the illusion of governance while stale entitlements remain in place. The model may be formally approved, yet business reality has already moved on.
How practitioners should judge whether the model is still governed
The key test is not whether the policy syntax still works, but whether the access outcome still reflects current business need. If you cannot trace a role, attribute or approval back to an owner who can explain why it still exists, the control is already drifting. Good governance requires explicit accountability for role design, attribute quality, entitlement cleanup and exception expiry.
Where access is high impact, review should focus on blast radius rather than completeness theater. Segregation of Duties (SoD) Guide matters because a stale entitlement is most dangerous when it creates a toxic combination that nobody notices until an audit or incident. Likewise, Privileged Access Management Guide is relevant wherever standing privilege persists after the original business need has disappeared.
At scale, the real control is continuous verification. Identity Visibility and Intelligence Platforms (IVIP) Guide fits this problem because governance gaps become visible only when teams can see entitlement drift, dormant access and inconsistent ownership across the estate. Without that visibility, access control models stay logically sound but operationally blind.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Account lifecycle and removal of stale access drive this question. |
| AC-6 — Least Privilege | Over-access persists when entitlement governance lags behind business need. | |
| AU-6 — Audit Review, Analysis, and Reporting | Governance gaps are often found by reviewing access drift and stale approvals. | |
| Recommendation — Enforce account lifecycle controls to remove stale access and keep entitlements current. Limit access to the minimum needed and remove excess entitlements promptly. Review audit evidence to detect entitlement drift and drive remediation. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about how access control decisions stay aligned with governance. |
| A.5.18 — Access rights | Stale rights and delayed removal are central to the governance gap described. | |
| Recommendation — Define and enforce access control rules that reflect current business need. Review, update and revoke access rights on a defined lifecycle. | ||
Practitioner Guidance
What to prioritise: Start with the identities, roles and attributes that can create the largest unwanted access footprint if they drift. In most environments that means privileged users, shared access, third parties and any entitlement that crosses systems or environments.
What to verify: For each high-value role or attribute, verify that there is a named owner, a current business justification, a defined review cadence and a removal path when the justification expires. If any one of those is missing, the model is already relying on hope rather than governance.
Common mistake: Treating successful authorization decisions as evidence of good governance. A correct allow or deny result can still be produced by stale inputs, and stale inputs are exactly how over-access persists without visible policy failure.
Practitioner takeaway: The model is only as governed as the freshness of the data and lifecycle behind it, so measure drift and cleanup speed, not just policy correctness.
Related resources from NHI Mgmt Group
- Why do role-based access controls still leave governance gaps in cloud environments?
- Why do API keys, basic authentication, and scope-only models leave gaps in user-specific access control?
- Why do mature IGA programmes still leave major gaps in access governance?
- Why do central SSO platforms still leave access governance gaps?