Join our Newsletter — 33% off our NHI Course

Should organisations prioritise connector depth or review automation first?

Connector depth should come first if the organisation cannot reliably discover who has access and to what. Automation cannot improve governance when the underlying inventory is incomplete, because faster reviews of bad data only accelerate the wrong decisions.

Why connector depth has to beat automation when inventory is incomplete

connector depth is the discovery problem: if you cannot reliably ingest the systems, directories, SaaS apps, cloud tenants, and admin planes that hold access paths, you do not yet have enough ground truth to automate review decisions. Review automation only becomes valuable after the inventory layer can see enough of the environment to produce a defensible access picture.

That is why connector work is not just “more integrations”, it is the prerequisite for trustworthy governance. A shallow connector set tends to miss inherited permissions, externally shared objects, dormant accounts, and system-specific entitlement models, which means the organisation may optimise the review process while still overlooking the highest-risk access paths.

Where review automation starts to pay off

Automation becomes the better investment once discovery is broad enough that the organisation is no longer debating whether the list is materially incomplete. At that point, automation can reduce manual effort, shorten review cycles, and make recurring recertification more consistent across large populations of accounts and entitlements.

In practice, the best automation targets are repetitive decisions with stable evidence: standard role memberships, periodic access attestations, unchanged privilege baselines, and exception routing. The more the review depends on interpretation, cross-system correlation, or business context, the more the workflow still needs human judgement even if the surrounding task is automated.

How to sequence both without creating false confidence

The most practical sequence is to use connector depth to establish coverage, then use automation to scale the review motion. That means prioritising high-value sources first, not every possible connector at once: start with the systems that create the most privilege, the widest blast radius, or the most frequently reviewed access decisions.

Once those core sources are covered, automate the parts of review that are already well-understood and repeatable, and keep an explicit exception path for ambiguous access, unusual entitlements, and systems that are still only partially integrated. CIS Controls v8 is useful here because it ties inventory, account management, and access control together as a sequence rather than separate projects.

Risk and Threat Considerations

Shallow connector coverage creates a governance blind spot, because the organisation may believe it is reviewing access comprehensively while the underlying dataset is still incomplete. When that happens, automation can accelerate approval of stale, inherited, or invisible access instead of reducing risk.

Failure mechanism: incomplete connectors fail to surface all relevant identities, entitlements, and relationships, so the review engine processes partial or stale data and produces confident but unreliable decisions.

Impact: excessive access can persist undetected, review exceptions can be normalised, and the organisation can lose trust in the review programme because controls appear efficient without being complete.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-1 — Inventory and Control of Enterprise Assets Connector depth depends on complete asset and system discovery.
CIS-6 — Access Control Management The question is about sequencing access governance and review automation.
Recommendation — Expand asset discovery before automating access reviews. Prioritise authoritative access control data before automating recertification.
NIST CSF 2.0 ID.AM-01 — Physical devices and systems within the organization are inventoried Inventory completeness is the prerequisite for reliable governance automation.
Recommendation — Establish complete inventory coverage before scaling automated reviews.
NIST SP 800-53 Rev 5 CM-8 — System Component Inventory Connector depth is fundamentally about creating a trustworthy component inventory.
AC-2 — Account Management The answer concerns governing account visibility and recurring review decisions.
Recommendation — Build a reliable component inventory before automating access decisions. Use authoritative account data as the basis for automated review workflows.

Practitioner Guidance

What to prioritise: fix coverage where missing connectors distort the highest-risk access decisions first, especially systems with broad privilege, inherited permissions, or the largest user populations.

Decision rule: if reviewers still need spreadsheets, manual exports, or tribal knowledge to explain who has access, treat connector expansion as the next control improvement before scaling automation further.

What good looks like: the review workflow can reconcile authoritative sources, show what was in scope, and explain exclusions without requiring a separate data-chasing exercise.

Practitioner takeaway: automate to scale a trustworthy inventory, not to compensate for one that is still incomplete.