Join our Newsletter — 33% off our NHI Course

Should organisations prioritise role mining before access reviews or after them?

Role mining should feed access reviews rather than compete with them. Reviews tell you what is currently assigned, while role mining helps explain whether those assignments belong in a durable role or are just leftover exceptions. Used together, they produce cleaner governance than either process alone.

How role mining and access reviews should work together

role mining and access reviews solve different parts of the governance problem. Reviews are backward-looking: they confirm what access exists and whether it is still justified. Role mining is structural: it groups repeated access patterns into durable roles, surfaces exceptions, and reveals where the current model is drifting into ad hoc assignment.

That means role mining is usually more useful as an input to the review process than as a replacement for it. If you mine roles first, reviewers can judge whether an assignment belongs in a stable entitlement model or should be removed as an outlier. If you review first, you still need role mining to turn repeated approvals into a cleaner model that is easier to maintain.

For organisations with many entitlements, the practical question is not which process is “right”, but which one reduces review fatigue and role explosion faster. A mature governance programme uses review findings to improve role design, then uses improved roles to make the next review cycle smaller and more accurate.

Why sequencing changes the quality of governance

When access reviews happen without role context, they tend to become item-by-item certification exercises. That can confirm whether access was assigned, but it often misses the deeper question of whether the access pattern itself is coherent. Role mining adds that missing structure by showing whether the same combination of entitlements appears across many users and should become a maintained role.

When role mining happens without review evidence, it can be built on stale assignments, inherited privileges, or one-off exceptions that were never cleaned up. The result is a role model that looks tidy on paper but preserves bad historical access decisions. The strongest approach is iterative: review, mine, redesign, then review again against the improved model.

This is especially important where access patterns change quickly, because static role models age poorly when exceptions accumulate. A role that is based only on historical assignment patterns can accidentally normalise overprivilege unless the review process is used to strip away access that no longer belongs.

What good operating practice looks like

Good practice is to use the review cycle to identify candidate roles, and then use role mining to explain and rationalise the patterns behind those candidates. That gives the reviewer a reason to distinguish between durable business need, temporary exception, inherited access, and true outlier. It also gives role owners a cleaner starting point for role refactoring.

In larger environments, Role Mining and Role Design Guide is the most direct starting point for building a maintainable role model, while Access Reviews and Certification Guide helps teams keep the review process focused on removing access rather than rubber-stamping it.

Where organisations need broader identity governance context, IAM and IGA Basics is useful for understanding how reviews, roles, and entitlement governance fit together, and IGA Buyer’s Guide helps teams evaluate whether their tooling can actually support that workflow. For broader control design, the CIS Controls v8 and ISO/IEC 27001:2022 Information Security Management both reinforce the need to control access, review it regularly, and keep governance evidence defensible.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Role mining and reviews both tighten account and entitlement governance.
Recommendation — Review and rationalise access assignments before they accumulate into excess entitlements.
ISO/IEC 27001:2022 A.5.15 — Access control Sequencing role mining with reviews directly affects access governance and entitlement control.
A.8.2 — Privileged access rights Reviewing and mining roles is critical where elevated access is embedded in roles.
A.5.18 — Access rights The question is fundamentally about how access rights are validated and normalised.
Recommendation — Define and operate access control rules that are regularly reviewed and refined. Keep privileged access roles tightly owned, reviewed and reduced to need. Audit access rights periodically and remove assignments that no longer fit the role model.

Practitioner Guidance

What to prioritise: Start by cleaning up the highest-volume or highest-risk entitlement sets, because that is where role mining will produce the most value for the next access review cycle. If the review population is already noisy, use mining to reduce exception volume before expanding the certification scope.

Decision rule: If the access pattern repeats across many users and the business can explain it, treat it as a role-design candidate; if it appears as a one-off or has weak justification, treat it as a removal candidate. Role mining should therefore inform review outcomes, not sit beside them as a separate governance exercise.

What practitioners underestimate: The main failure mode is allowing reviews to certify existing messes indefinitely. The point of combining the two processes is to convert recurring access into a stable model and push everything else back toward removal or exception handling.

Practitioner takeaway: The best sequence is iterative, not linear, but the operational priority is clear: use reviews to expose what exists, use role mining to decide what should become durable, and keep feeding the cleaner model back into the next review cycle.