Join our Newsletter — 33% off our NHI Course

What should IAM and IGA teams do when access decisions are still manual?

They should move the programme toward a single governed identity inventory, event-driven revocation, and approval processes that expose the full entitlement set before access is granted. Without that shift, the organisation is certifying incomplete data and allowing privilege drift to accumulate.

Why Manual Access Decisions Break Down

Manual approval is usually a sign that the access model is outpacing the controls around it. When reviewers cannot see the full entitlement set, they end up approving fragments of access instead of a complete decision. That creates a false sense of governance, because the organisation is certifying what it can see, not what the identity actually has.

A governed identity inventory is the practical starting point because it gives IAM and IGA teams one place to reconcile accounts, entitlements, ownership and source-of-truth data. Without that foundation, every approval is vulnerable to stale records, duplicate identities, role drift and inconsistent joiner-mover-leaver handling.

The shift from manual review to governed decisions is not just about speed. It is about making access decisions with enough context to distinguish normal business need from privilege creep, cross-environment exposure and inherited access that no one intended to keep.

What Changes When Approval Becomes Event-Driven

Event-driven revocation is the control that stops access from surviving longer than its business reason. Instead of waiting for the next periodic review, teams act when a trigger occurs, such as a role change, project end, termination, contract expiry or risk signal. That matters most where standing access creates avoidable exposure.

For access to be revoked quickly and safely, the approval model has to be tied to accurate entitlement data. The review process should expose inherited roles, nested groups, toxic combinations and effective access before the request is approved. That is where Access Reviews and Certification Guide becomes useful, because it focuses on closing the loop rather than treating review as a paperwork exercise.

Manual steps still have a place, but only for exceptions, high-risk access and business context that automation cannot reliably infer. For routine access, the goal is to reduce human decision load by making the system present the complete picture up front, then automate the removal of access when the event says the entitlement is no longer justified.

How IAM and IGA Teams Should Re-Engineer the Process

The programme should be built around lifecycle control, not ticket handling. A strong pattern is to anchor requests to authoritative sources, validate them against the full entitlement set, and keep revocation in the same governed workflow. That is the difference between approving access and managing identity risk.

Teams should also align role design and access review logic so that managers and reviewers are not forced to inspect hundreds of line-item entitlements by hand. The right model uses roles, policies and ownership to reduce approval ambiguity, then escalates only the cases that truly need human judgement. IAM and IGA Basics is a useful reference for that operating model, especially where organisations are clarifying the boundary between authentication, entitlement management and governance.

When leaver and mover events are involved, the cleanest path is to automate the removal of obsolete access first, then let exceptions go through a documented approval path. Joiner-Mover-Leaver (JML) Guide supports that approach because it ties identity lifecycle events to deprovisioning rather than leaving removals to periodic cleanup.

Risk and Threat Considerations

Manual access decisions create concentration risk: a small number of reviewers become the weak link between policy and actual privilege. When they lack full entitlement visibility, organisations can accumulate silent privilege drift, inherited access and outdated approvals that remain valid long after the original business need disappears.

Failure mechanism: incomplete inventory and slow revocation allow access to outlive the event that justified it, while reviewers continue to approve requests based on partial evidence. That can turn a nominally governed process into a durable path for excessive privilege, lateral movement and audit failure.

Impact: the organisation may retain access that should have been removed, certify the wrong entitlement set, and miss high-risk privilege combinations until a control test, incident or external audit exposes the gap.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CSA Cloud Controls Matrix IAM — Identity and Access Management Manual access decisions in cloud environments depend on governed identity and entitlement controls.
Recommendation — Centralise identity and entitlement governance before approving or revoking access.
NIST SP 800-53 Rev 5 AC-2 — Account Management Account lifecycle and revocation are central when access decisions remain manual.
AC-6 — Least Privilege Incomplete manual reviews often miss excess privilege and entitlement drift.
IA-5 — Authenticator Management Credential and access-material governance is part of reliable access control operations.
Recommendation — Automate account lifecycle triggers and remove access on defined events. Reduce standing access and right-size entitlements to least privilege. Track, rotate and revoke authenticators as part of the access lifecycle.
ISO/IEC 27001:2022 A.5.15 — Access control Access approval and revocation are governed by access control policy and enforcement.
Recommendation — Define access control rules that require complete entitlement review before approval.

Practitioner Guidance

What to prioritise: fix the identity data model before tuning the review workflow. If the approver cannot see ownership, source system, effective access and expiry state in one view, any downstream approval logic will stay noisy and incomplete.

What to verify: each access request should resolve to a single governed record, and each revocation should be event-linked so the team can prove when the entitlement was removed and why. If that evidence is missing, the process is still manual in the places that matter.

Common mistake: treating faster ticket approval as access governance. Speed helps only when the underlying decision is complete, traceable and reversible.

Practitioner takeaway: move the programme from reviewer-centred approvals to data-centred decisions, because the quality of the entitlement picture determines whether IAM and IGA are actually governing access or just recording opinions about it.