TL;DR: Permission drift, standing access, and weak review cycles can turn ordinary role changes into security incidents and compliance failures, according to Soffid, which argues that access governance must be continuous rather than periodic. The core issue is that access reviews alone cannot contain privilege accumulation between review windows.
At a glance
What this is: This is an analysis of how access governance shifts permission management from a periodic administrative task to continuous security control, with the key finding that unmanaged access accumulation creates direct risk.
Why it matters: It matters because IAM, IGA, and PAM teams need governance processes that survive role changes, temporary access, and exceptions across human and non-human identities.
By the numbers:
- $13.1 million.
- 97% of non-human identities have excessive privileges.
👉 Read Soffid's article on access governance and continuous permission control
Context
Access governance is the discipline of deciding who should have access, for how long, and under what policy, then proving that those decisions remain valid as roles and systems change. In practice, the problem is not access creation alone. It is access persistence after the business reason has disappeared, especially in IAM environments that span human users, service accounts, and other non-human identities.
Soffid’s article frames the issue clearly: permissions become a security risk when reviews are periodic but governance is not continuous. That is the right lens for IAM, because privilege creep, temporary access, and exception-based approvals all create control gaps between review cycles. For teams building a stronger baseline, the NHI Lifecycle Management Guide helps connect revocation, rotation, and review into one operating model.
The article also reflects a broader identity trend. Modern IAM programmes cannot treat access reviews as a standalone event if they want to reduce exposure from role changes, left-behind accounts, and unnecessary privilege. The operational question is not whether access was once approved, but whether it is still justified today.
Key questions
Q: How should security teams turn access reviews into real risk reduction?
A: Security teams should use access reviews to remove dormant access, orphaned accounts, and privileges that no longer match the work being performed. The review should end with revocation or re-scoping, not just attestation. The goal is to reduce exposure, especially in production systems and high-risk applications where excessive access has immediate security impact.
Q: Why do temporary access and exceptions create so much identity risk?
A: Temporary access becomes dangerous when it outlives the event it was created for. Every exception that lacks an expiry date or an owner can turn into permanent privilege, especially after transfers, project completion, or staff changes. The risk is not the initial grant, but the failure to close it out.
Q: What breaks when governance relies only on quarterly access reviews?
A: Quarterly reviews miss the day-to-day drift that accumulates between certification cycles. By the time the review happens, the access graph may already have changed, so the programme validates yesterday’s state rather than today’s risk. That makes certification useful for assurance, but weak as a primary control.
Q: Who is accountable when stale group access causes a security incident?
A: Accountability usually sits with identity owners, application owners, and compliance leaders together, because stale group access is a governance failure rather than a single technical mistake. The practical test is whether the organisation can explain why the group existed, who approved it, and why it was still active.
Technical breakdown
Why periodic access reviews miss permission drift
Periodic access reviews are point-in-time checks. They can identify obsolete rights, excessive permissions, and inactive accounts, but they do not stop new exceptions from accumulating after the review closes. That gap matters because most identity risk is temporal: a permission that was valid last month can become unsafe after a role change, an urgent project, or a temporary assignment. Continuous access governance closes that window by making approval history, current role, and current necessity visible together, not in separate systems or spreadsheets.
Practical implication: treat reviews as evidence, not control coverage, and connect them to continuous entitlement monitoring.
How RBAC and least privilege need governance, not just design
RBAC and least privilege are only effective when the entitlement model is actively enforced. A role definition on paper does not prevent ad hoc exceptions, over-assignment, or permissions that survive an internal transfer. Access governance adds the missing operational layer by tying each permission to a reason, an owner, a duration, and a revocation path. Without that lifecycle context, RBAC often becomes a naming convention rather than a security control.
Practical implication: validate that every role has a revocation path and exception expiry, not just a job-title mapping.
Why traceability matters when access changes between reviews
Traceability is what turns access decisions into auditable control. If a permission can be granted, modified, or extended without a clear record of who approved it, why it exists, and when it should end, governance becomes guesswork during incident response and audit. In identity programmes that include human users and non-human identities, traceability also shows whether access was temporary, inherited, or still needed after a lifecycle event such as a transfer or departure.
Practical implication: require decision records for every access change and make review evidence queryable by identity, owner, and expiry.
Threat narrative
Attacker objective: The objective is to use unmanaged access persistence to reach higher privileges or sensitive resources without triggering timely governance controls.
- entry via routine access assignment, urgent exception, or left-over role privilege that is never removed.
- escalation through accumulated permissions, excessive access, or stale accounts that remain active after role change or departure.
- impact through privilege escalation, regulatory exposure, or security incidents caused by access that outlives its business purpose.
Breaches seen in the wild
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Permission persistence is the real control failure, not the initial grant. The article is strongest when it moves beyond onboarding and focuses on what happens after access is approved. In IAM and IGA programmes, risk usually emerges from role change, exception handling, and delayed revocation, not from the original permission request. Practitioners should treat lingering access as the governance failure mode to eliminate.
Access governance is the operating layer that RBAC by itself cannot provide. RBAC can describe intended access, but it cannot enforce duration, justify exceptions, or remove stale entitlements when business context changes. That is why the article’s emphasis on centralised visibility, traceability, and ongoing revocation aligns with modern identity governance rather than static role design. Teams should evaluate whether their RBAC model is actually governed or merely documented.
Continuous review is now a security control, not a compliance ritual. The article correctly frames access reviews as one component of a broader model. A standalone review finds problems after they have already accumulated, while continuous governance reduces the time a dangerous entitlement can exist. Security and compliance teams should judge access review programmes by how quickly they remove risk, not by how many certifications they complete.
Access governance must span human and non-human identities because privilege does not respect identity type. The article briefly notes human and non-human identities in a single dashboard, which reflects where governance is heading. Service accounts, API credentials, and user accounts all create exposure when permissions outlive the business need. Practitioners should unify lifecycle and recertification logic across identity classes instead of maintaining separate control theories.
Privilege creep is a named governance problem, and the article points to the right operational concept: access duration debt. Every temporary grant that stays active, every exception that is never re-reviewed, and every old permission left in place becomes deferred security debt. That debt compounds between access reviews and shows up later as audit findings, lateral movement opportunity, or incident scope. Teams should measure how much access is active only because nobody has revisited it.
From our research:
- 97% of non-human identities have excessive privileges, according to The 2024 ESG Report: Managing Non-Human Identities.
- From our research: 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected, according to the same report.
- Use NHI Lifecycle Management Guide to connect expiry, rotation, and revocation into a single control model for access governance.
What this signals
With 97% of non-human identities already carrying excessive privileges, the practical problem is not whether access drift exists but how quickly your programme can detect and remove it. A continuous entitlement model, supported by the NIST Cybersecurity Framework 2.0, is now the difference between governance and paperwork.
Access duration debt: temporary grants, exceptions, and inherited entitlements create a hidden backlog of risk when no one is tracking how long access has remained in place. Teams should measure revocation latency, not just approval volume, because the delay between business change and permission removal is where exposure compounds.
The next maturity step is to unify access reviews, offboarding, and exception expiry across human users and non-human identities. That means aligning IAM operations with the NIST SP 800-53 Rev 5 Security and Privacy Controls so the organisation can prove access is not just assigned correctly, but removed on time.
For practitioners
- Map every permission to an owner and expiry Require each access grant, exception, and temporary entitlement to carry a named owner, business reason, and review date. Remove permissions that cannot be tied to a current need, and make exceptions automatically expire unless renewed through a documented workflow.
- Convert access reviews into continuous entitlement monitoring Use periodic certifications only as one checkpoint in a broader control loop that watches role changes, dormant accounts, and new exceptions between review cycles. Prioritise high-risk permissions first, especially privileged access and credentials tied to sensitive systems.
- Enforce least privilege through revocation, not just assignment Build revocation into role change, transfer, and offboarding workflows so access is removed as part of the identity lifecycle. Check that temporary access cannot become permanent simply because no one reopens the approval record.
- Centralise visibility across human and non-human identities Create a single entitlement view for users, service accounts, API keys, and other non-human identities so review teams can spot inherited access, stale permissions, and duplicate entitlements. If you cannot query access centrally, you cannot govern it continuously.
Key takeaways
- Access governance becomes a security control when it continuously removes permissions that no longer have a business purpose.
- Periodic access reviews can detect privilege drift, but they cannot stop new exceptions from becoming hidden risk between review cycles.
- The most effective governance programmes tie every permission to an owner, an expiry, and a revocation path across human and non-human identities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | The article is about controlling and reviewing access permissions over time. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is a direct fit for the article's access control focus. |
| OWASP Non-Human Identity Top 10 | NHI-03 | The article's NHI references align with excessive privilege and governance drift. |
| NIST Zero Trust (SP 800-207) | Continuous verification and least privilege align with the article's governance model. |
Review NHI entitlements against NHI-03 and prioritise stale or over-privileged identities for remediation.
Key terms
- Access Governance: Access governance is the policy and workflow layer that manages how access is requested, approved, certified, and revoked. In SaaS environments it helps standardise control across many applications, reducing inconsistency between teams. It is most effective when it covers both human accounts and non-human identities.
- Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
- Access duration debt: Access duration debt is the backlog created when permissions outlive the event, role, or exception that justified them. In governance terms, it is deferred revocation risk that compounds between reviews and becomes harder to audit, explain, and remove over time.
What's in the full article
Soffid's full article covers the operational detail this post intentionally leaves for the source:
- How its IGA approach centralises visibility into identities, access types, and review cycles.
- How access review automation is positioned alongside PAM, AM, and IRC inside a converged IAM platform.
- How traceability is maintained for approvals, exceptions, and revocations across the identity lifecycle.
- How the article links continuous governance to regulated-environment evidence and audit readiness.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org