By NHI Mgmt Group Editorial TeamBased on Cerbos: “5 authorization blind spots auditors find, and how to fix them” (April 10, 2026)

TL;DR: Access control audits increasingly fail at the authorization layer, where enterprises can document roles and policies but still cannot prove who could do what, when, and why, according to Cerbos and the 2025 OWASP and Verizon findings cited in the article. The real governance gap is evidence of enforcement, not policy intent, and that gap spans human users, non-human identities, and AI agents.


At a glance

What this is: This is an analysis of why access control audits fail when teams can show policy but not enforcement evidence, with authorization rather than authentication emerging as the core weakness.

Why it matters: It matters because IAM, IGA, PAM, NHI, and AI agent programmes all depend on proving actual access decisions, not just describing intended roles or controls.

By the numbers:

  • Broken access control held the number-one spot on the OWASP Top 10 for two consecutive releases.
  • In the 2025 edition, every single application tested showed some form of broken access control.
  • The Verizon 2025 DBIR found that 22% of breaches began with stolen or compromised credentials.
  • The Verizon 2025 DBIR also found that 88% of basic web application attacks involved stolen or compromised credentials.

Context

Access control audits often expose a different problem from the one teams expect: the environment may be configured correctly, yet the organisation still cannot prove the actual decision trail behind access. In practice, the weakness sits in authorization, where policy intent and real enforcement diverge across applications, APIs, service accounts, and AI-driven workflows.

For identity leaders, that gap matters because auditors and boards increasingly ask for evidence of who could access what, when, and why, not just a role model or a policy document. When authorization is distributed across code and infrastructure without a central evidence trail, compliance becomes reconstruction after the fact rather than proof at the moment of decision.

The article argues that this is no longer just an application security issue. It is now an enterprise governance problem that touches human IAM, non-human identities, and emerging agentic systems that need context-aware decisions at runtime.


Key questions

Q: What breaks when access control audits can show policy but not enforcement evidence?

A: Audit assurance breaks because teams can no longer demonstrate what was actually permitted at decision time. That creates a gap between policy intent and provable control operation, which auditors treat as a failure of evidence, not just documentation. In practice, the organisation cannot defend access decisions after a breach or compliance review.

Q: Why does poor authorization create more breach risk even when authentication is strong?

A: Authentication only proves identity at login. Authorization controls what that identity can reach after the session starts. If permissions are too broad, stolen or misused credentials can move into sensitive systems that should have stayed out of reach. That is why least privilege, granular policies, and contextual checks matter in modern environments.

Q: Why do service accounts and AI agents need different controls from human users?

A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.

Q: How should security teams govern authorization across multiple applications?

A: Security teams should move access decisions into a centrally managed policy layer, then assign ownership for policy design, testing, and exception handling. That gives IAM a consistent control point for change management, audit evidence, and cross-application enforcement instead of relying on duplicated code paths in every service.


Technical breakdown

Why scattered authorization logic breaks auditability

Authorization logic is the code and policy layer that decides whether a request is allowed. When each application implements that logic differently, the organisation loses a single source of truth for access decisions. Some checks live in middleware, some in controllers, and some in stale configuration files, which means auditors cannot reliably trace how a decision was made or whether the same policy was enforced everywhere. Externalized authorization moves that logic into a central policy decision point with distributed enforcement, so the policy and the audit trail stay aligned across systems.

Practical implication: Centralize authorization policy and logging so every access decision can be traced to one governed decision point.

Why policy documents are not proof of enforcement

A policy document describes intended access. An audit evidence trail shows what was actually evaluated when a real request was made. Those are not the same thing. IAM and IGA tools often report roles, assignments, and approvals, but that does not prove which resource was accessed, which policy version was evaluated, or what action was taken in context. Without decision logging at the point of enforcement, teams end up inferring compliance from configuration rather than demonstrating it from evidence.

Practical implication: Log the full authorization context, including subject, resource, action, policy version, and decision outcome.

Why fine-grained authorization matters for service accounts and AI agents

Non-human identities and AI agents operate at machine speed, often with delegated or standing access that is far more dynamic than human access patterns. Role-based access control alone cannot express the context needed for these subjects, especially when tool calls, API requests, or workload actions must be judged in real time. Fine-grained authorization evaluates each request against current context, not just a preassigned role. That is the control model that can produce defensible evidence for machine identities and agentic workflows.

Practical implication: Move high-risk NHI and agentic access paths to context-aware, request-by-request authorization.


Threat narrative

Attacker objective: The objective is to exploit opaque authorization paths to reach actions or data that the organisation cannot later prove were properly restricted.

  1. Entry occurs when a compromised credential or over-permissioned identity can still reach the application because the authorization layer is weak or inconsistent.
  2. Escalation follows when scattered policy logic or missing decision logs prevent teams from proving which permissions were actually enforced at the time of access.
  3. Impact lands in the audit and incident review, where organisations cannot show who could do what, when, and why, which weakens both containment analysis and compliance defence.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Authorization evidence, not policy intent, is now the audit battleground: Many enterprises can document roles, group assignments, and access policies, yet still cannot prove the runtime decision that allowed or denied a request. That is a governance failure because auditors increasingly want evidence of enforcement at the moment of access, not a description of what the policy was supposed to do. Practitioners should treat this as a control-evidence gap, not a reporting gap.

Scattered authorization logic creates identity technical debt that auditors will eventually surface: When access decisions are embedded across codebases, middleware, and application-specific conditionals, no one can prove that the same rule was applied consistently. This is not just inconvenient. It means the organisation cannot test, log, or certify authorization centrally, which makes the control hard to govern across human users, service accounts, and AI agents.

Fine-grained authorization is becoming the governance layer for machine identities: Service accounts and AI agents do not fit cleanly into coarse role reviews because their permissions are contextual, delegated, and often time-sensitive. The named concept here is authorization evidence gap, the difference between saying access should be controlled and proving the decision that controlled it. Practitioners should assume that any identity able to act at runtime without decision evidence is already outside the audit envelope.

Access reviews that inspect roles but not permissions are a false comfort control: Quarterly certification can confirm assignments, but it does not tell you what an identity could actually do on a specific resource at a specific moment. That matters most where privilege is overbroad, stale, or delegated across systems. Security leaders should treat resource-level authorization evidence as the real input to recertification, not a checkbox report.

The next audit failure will likely involve AI agents unless authorization is designed for delegation chains now: Agentic systems invoke tools, APIs, and downstream services in ways traditional IAM was not built to explain cleanly. The implication is not simply to add another control. It is to rethink what counts as proof when the subject is non-human, the action is delegated, and the decision must be traceable across a runtime chain.

From our research library:

What this signals

Authorization evidence gap: Enterprises are moving into an era where proof of enforcement matters more than policy documentation. When access decisions are distributed across applications and runtime systems, governance teams need a way to show what was allowed at the exact moment of decision, or audit confidence will keep eroding.

Human, NHI, and agentic access now share the same governance requirement: decision traceability. The practical shift is from reviewing who was assigned access to proving which access requests were actually evaluated, approved, or denied in context.

For regulated programmes, this changes the shape of IAM backlog. The priority is no longer another report from the IGA stack, but an authorization model that can emit evidence across applications, service accounts, and AI-driven workflows.


For practitioners

  • Inventory authorization decision points Map where access decisions are made across applications, gateways, APIs, and data services, then separate auditable enforcement points from code paths that cannot produce evidence.
  • Capture decision-level audit logs Record the subject, resource, action, policy version, and allow-or-deny outcome for every sensitive authorization event so audits are based on proof, not reconstruction.
  • Rework access reviews around permissions Use resource-level entitlements and actual allowed actions in certification workflows instead of approving abstract role names that hide privilege drift.
  • Apply context-aware controls to NHIs and agents Prioritise service accounts, API keys, and AI agent tool calls for fine-grained authorization where standing access or delegated runtime action creates the largest evidence gap.

Key takeaways

  • The core audit problem is not whether policies exist, but whether teams can prove how access was enforced in context.
  • Distributed authorization logic, role-only reviews, and missing decision logs all weaken the evidence auditors expect.
  • Centralized, fine-grained authorization is the control pattern that makes access decisions defensible across humans, non-human identities, and AI agents.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article shows standing and overbroad access in service accounts and API keys.
NHI-10 — Human Use of NHIThe article highlights human governance over machine identities and delegated access.
Recommendation — Review NHI entitlements for overprivilege and reduce standing access to the minimum auditable scope. Separate human ownership from machine execution so NHI access decisions remain traceable and reviewable.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about proving authorization decisions and their enforcement.
Recommendation — Document and verify access permissions so every sensitive decision can be proven at audit time.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeRole drift and overprovisioning are central to the access review failures described.
Recommendation — Enforce least privilege at the resource level and remove permissions that are not actively needed.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article cites credential-driven breaches where weak authorization expands attacker reach.
Recommendation — Map credential abuse and movement paths to privileged access that lacks enforcement evidence.

Key terms

  • Authorization Evidence: Authorization evidence is the documented proof that a system meets security and compliance requirements before and during operation. For AI agents, evidence must extend beyond platform certification to show behavioural controls, monitoring coverage and containment for runtime actions.
  • Externalized Authorization: A design pattern where access decisions are removed from application code and handled by a separate policy layer. This makes authorization easier to govern, test, audit, and reuse across services, especially when roles, attributes, and request context change frequently.
  • Decision Point: A decision point is the place in a system where access is explicitly allowed or denied by policy, outside the model itself. It provides an auditable enforcement step that can be logged, reviewed, and tested. For AI agents, moving checks to the decision point is critical for proving governance and preventing prompt-driven ambiguity.
  • Fine-Grained Authorization: Fine-grained authorization is access control that evaluates specific resources, actions, and context rather than granting broad application-level permission. For AI agents, this is the difference between merely connecting to a system and being limited to the exact data or action the task requires.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org