Join our Newsletter — 33% off our NHI Course

What happens when access reviews cannot show downstream assignments?

The review process certifies only part of the access picture, which leaves inherited permissions and subordinate entitlements outside the approval decision. That creates a false sense of coverage because the reviewer has signed off on a simplified view of access, not the actual effective state.

Why Partial Access Reviews Create a False Approval Signal

When downstream assignments are hidden, the review is no longer validating effective access. It is validating a reduced representation of access, which means a clean approval can coexist with inherited permissions, nested roles, indirect group membership, or subordinate entitlements that were never actually examined. The operational problem is not the review itself, but the gap between what was attested and what is truly usable.

That gap matters because access reviews are often treated as evidence that access is under control. If the reviewer cannot see the full chain, the certification only confirms the visible layer. The result is a control that looks complete on paper while leaving real permissions untouched in the system.

In practice, this usually shows up where entitlement models are layered: a user may appear to hold a simple role, but the role expands into additional access through nested groups, app-specific mappings, or inherited permissions from a higher-level assignment. The approval decision then becomes a partial endorsement of a path, not a judgment about the actual effective state.

What Actually Remains Unreviewed

Downstream assignments are the part of the access graph that sits below the reviewer’s immediate view. They can include indirect entitlements, inherited roles, hidden app permissions, and any subordinate access that is activated by another assignment. If those objects are not surfaced, the reviewer cannot evaluate least privilege, separation of duties, or whether the person still needs the access in practice.

This is why the “reviewed” status can be misleading. A reviewer may correctly approve the top-level entitlement while the real risk lives lower in the chain, where access is more powerful, more persistent, or more difficult to spot. The review is then a governance checkpoint, not a reliable statement about actual authorization.

For that reason, access certification should be designed around effective access, not just assigned access. When the system cannot present the subordinate path clearly, the review output should be treated as incomplete and the missing dependency should be resolved before the certification is used as evidence of control.

How Review Gaps Change Governance Decisions

Once downstream assignments are invisible, you cannot safely use the review as a basis for clean attestation, audit evidence, or deprovisioning confidence. The practical consequence is that the review may reduce workload without reducing exposure, which is the opposite of what governance teams need. The more layered the entitlement model, the more likely a partial view will miss privilege creep and inherited access that persists after the original business need has expired.

That is why effective access visibility is a prerequisite for meaningful certification. Access Reviews and Certification Guide and IAM and IGA Basics both reinforce that reviews need to cover entitlements, not just the visible parent assignment. Where access is inherited or composed, the reviewer needs enough context to decide whether the effective result still fits the role, the function, and the risk appetite.

In identity governance programs, the main issue is not whether the review ran, but whether it produced a decision on the true access state. If subordinate entitlements remain out of sight, the control should be treated as incomplete until the review model or supporting inventory is fixed.

Risk and Threat Considerations

Hidden downstream assignments create a classic assurance failure: the organization believes access has been recertified, while the effective privilege remains unchanged. That increases the chance of privilege creep, unauthorized retention of access after role change, and missed toxic combinations that should have been removed.

Failure mechanism: The review only covers the parent entitlement, while inherited permissions, nested memberships, or subordinate grants continue to confer access outside the approval decision.

Impact: Attackers or insiders can retain more access than the certification record suggests, auditors may accept incomplete evidence, and remediation actions may leave the real exposure in place.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Access reviews depend on complete account and entitlement lifecycle oversight.
AC-6 — Least Privilege Hidden downstream grants can preserve excessive privilege after certification.
AU-6 — Audit Record Review, Analysis, and Reporting Certification evidence needs enough detail to support trustworthy review and remediation.
Recommendation — Ensure reviews cover effective access and remove unapproved subordinate entitlements. Review effective permissions and trim any access beyond business need. Use audit evidence to validate the full access path before attestation.
ISO/IEC 27001:2022 A.5.15 — Access control Access control requires decisions based on the actual access state, not a partial view.
A.8.3 — Information access restriction Visibility gaps can leave effective access broader than intended.
Recommendation — Verify that access reviews include inherited and subordinate permissions. Restrict access based on effective entitlements and remove hidden excess.

Practitioner Guidance

What to verify: Confirm that the review tool or process can expand each reviewed entitlement into its effective downstream access before you rely on the certification outcome. If it cannot, treat the result as a partial control and do not use it as sole evidence of least privilege or removal.

Decision rule: If downstream assignments cannot be shown in the same workflow, push the process toward effective-access reporting, remediation, or inventory reconciliation before the next certification cycle. If they can be shown, require reviewers to attest against the expanded view, not the parent object alone.

Practitioner takeaway: A review that cannot expose subordinate entitlements is not a full access decision, it is a narrow approval that should never be mistaken for complete governance.