Copy-access is the practice of giving a new starter the same access as a predecessor or peer. It is fast, but it bakes old exceptions into new accounts and usually increases privilege sprawl unless the organisation continuously trims the inherited permissions.
What Copy-Access Really Changes
Copy-access is not a new permission model, it is a provisioning shortcut. The practical change is that access becomes inherited from a prior role holder, so the starting point for a new account is historical privilege rather than a clean, role-validated baseline.
This matters because the shortcut tends to preserve exceptions, one-off grants, and stale entitlements that were never intended to become a template. Over time, the pattern can make access reviews harder and obscure which permissions are actually needed for the job.
Why Organisations Use It
Teams use copy-access because it is fast, familiar, and easy to explain to managers and approvers. In environments with frequent onboarding, it can reduce provisioning delays and help a new starter become productive quickly.
The trade-off is that speed can replace design. If the copied access set is not compared against a current job function, location, system ownership, and segregation-of-duties requirements, the process turns into permission cloning rather than least-privilege assignment.
Where It Breaks Down
Copy-access breaks down when the predecessor’s access was already inflated, temporary, or shaped by a special project. It is especially risky when the organisation uses broad business roles, shared application bundles, or informal approvals that hide how much access is really being transferred.
That is why access assignment should be tied to current entitlement rules rather than personal history, and why inherited permissions need a trimming step before they become permanent. CIS Controls v8 and NIST Cybersecurity Framework 2.0 both reinforce the need to govern account access, while NIST Privacy Framework is useful when access inheritance could expose sensitive personal data.
How Copy-Access Differs From Proper Entitlement Design
Proper entitlement design starts with the role or task, then assigns only the permissions that support that need. Copy-access starts with a person and their existing access, which makes it a people-centric provisioning pattern rather than a control-centric one.
In mature environments, the copied set should be treated as a draft, not a decision. That draft should be reviewed against role standards, privileged access rules, and any application-specific constraints before it is approved.
Risk and Threat Considerations
Copy-access increases the chance that excess permissions, dormant access, and inherited exceptions spread from one account to the next. It also makes it easier for attackers to benefit from overprivileged accounts if a copied baseline includes more access than the new starter should have.
Failure mechanism: The access template carries forward old grants, so each new account can inherit unnecessary system reach, including permissions that were created for a prior exception, not for the new role.
Impact: This can expand blast radius, complicate offboarding and recertification, and raise the chance of unauthorized access, lateral movement, or policy drift across many accounts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-6 — Access Control Management | Copy-access directly affects account entitlement and least-privilege control. |
| Recommendation — Review copied access sets against least-privilege requirements before activation. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Authorizations and Associations are Managed | Copy-access is an access-assignment practice that must be governed and trimmed. |
| GV.PO-01 — Policy for Cybersecurity Risk Management | The practice needs policy boundaries so shortcuts do not become default access governance. | |
| Recommendation — Validate inherited permissions against current job needs and remove excess access. Define when copied access is permitted and require review before approval. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Copy-access is an access-control process that must enforce least privilege and review. |
| A.8.2 — Privileged access rights | Copying privileged accounts can propagate elevated rights if not tightly checked. | |
| Recommendation — Use access-control policy to prevent copied entitlements from becoming standing privilege. Separate privileged access from standard onboarding and require explicit approval. | ||
Practitioner Guidance
Governance implication: Treat copy-access as a temporary provisioning aid, not as the final access model. The copied set should always be reconciled to a role, a task, or a documented exception owner before it becomes active in production.
What to watch for: Repeated copying from the same predecessor, especially when that predecessor has unusual access, is a strong sign that inherited privilege is becoming normalised. Copy-access is safest when the organisation can prove that the copied permissions were reviewed and intentionally kept, not just repeated.
Related resources from NHI Mgmt Group
- Non-Human Identity Access Management
- What breaks when organisations copy legacy access into a new ERP system?
- Why does third-party privileged access create the same risk pattern as standing NHI privilege?
- How do security teams detect when a machine identity is being used outside its normal access pattern?