TL;DR: Access reviews often prove activity happened without proving risk was removed, because managers receive entitlement inventories instead of decision-ready context, according to Offroad AI. The real failure is a governance model that treats quarterly certification as control, even though reviewer evidence, lifecycle gaps, and agentic access all demand continuous verification.
At a glance
What this is: This is an analysis of why access reviews often become approval exercises, with the key finding that missing context and lifecycle gaps let risky access survive certification cycles.
Why it matters: It matters because IAM, IGA, PAM, and NHI programmes all depend on review quality, and weak evidence turns recertification into documentation rather than risk reduction.
👉 Read Offroad AI's analysis of why access reviews fail to remove risk
Context
Access reviews are supposed to confirm that access still makes sense, but in many programmes they are built around entitlement lists rather than decision-ready evidence. When the reviewer cannot see usage, business purpose, approval history, dependency, and expiry expectations in one place, the safest answer is often to approve and move on. That leaves IAM teams with compliance artefacts but little reduction in actual access risk.
This problem extends beyond human access. Joiner, mover, and leaver failures feed stale access into the review process, while service accounts and AI agents can outlive the assumptions that created them. In that sense, the issue is not reviewer discipline alone. It is the governance model that asks people to certify access without enough identity context to make the decision meaningful.
Key questions
Q: What breaks when access reviews lack reviewer context?
A: Reviewers cannot distinguish legitimate access from unnecessary access if they only see a name and a checkbox. Without usage, role, ownership, and application context, certification becomes a formality, and risky access survives because the decision-maker has too little evidence to act confidently.
Q: Why do lifecycle gaps keep showing up in access review campaigns?
A: Because joiner, mover, and leaver failures are not resolved before certification begins. Temporary access, contractor departures, and orphaned service accounts flow into the review as unresolved cleanup work, which makes the campaign a backstop for identity operations that should have already removed the exposure.
Q: How should organisations use AI agents in access reviews without losing governance control?
A: Use AI agents as decision-support for routine requests, not as unbounded approvers. Keep policy ownership with IAM teams, require human override for high-risk access, and log the inputs that led to each recommendation. The goal is to reduce approval fatigue while preserving accountability, auditability, and least-privilege enforcement.
Q: What is the difference between access review completion and access risk reduction?
A: Completion means the campaign ran and decisions were recorded. Risk reduction means unnecessary access was actually removed, the effective permissions changed in the target system, and the remaining entitlements can be explained with current business context. An organisation can have one without the other, so both need separate measurement.
Technical breakdown
Why entitlement inventories fail as review inputs
An access review is only as useful as the evidence attached to each entitlement. A row that shows a user, application, group, and role name does not tell a business owner whether the access is active, why it exists, or what would break if it were removed. That forces the reviewer to reconstruct history from tickets, logs, HR data, Slack threads, and memory. The review platform has shifted from control point to research assignment, which biases decisions toward approval because rejection carries immediate operational risk.
Practical implication: feed reviewers usage history, approval rationale, dependency data, and expiry intent before asking for certification.
Why lifecycle gaps become review debt
Joiner, mover, and leaver failures do not disappear when the quarterly campaign starts. Temporary access without an expiry date, contractor access without a clean offboarding event, and service accounts without clear ownership all accumulate until the review becomes the first moment anyone looks closely. At that point, the campaign is compensating for upstream lifecycle failure rather than governing access in real time. The review is late by design, which is why it tends to clean up symptoms instead of preventing privilege creep.
Practical implication: tie access reviews to lifecycle triggers so offboarding and role changes remove exposure before certification begins.
Why periodic certification breaks for AI agents
Periodic certification assumes access persists long enough to be observed, evaluated, and then removed if needed. AI agents break that assumption because they can execute thousands of actions across connected systems before the next review window opens. Governance must therefore evaluate current task scope, delegated authority, and active tool use continuously rather than waiting for the next quarterly cycle. The point is not that audit evidence disappears. The point is that certification cadence cannot be the control boundary for actors that change state faster than the review process can observe.
Practical implication: replace quarterly-only certification with continuous policy checks for agent task scope, tool use, and delegated access.
Threat narrative
Attacker objective: The attacker objective is not just persistence, but preservation of excess access long enough to expand privilege, move laterally, or retain footholds across identity lifecycles.
- Entry occurs when access is granted through a joiner, mover, leaver gap, a temporary exception, or an overbroad entitlement that was never fully explained to the reviewer.
- Escalation happens when the entitlement survives certification because the reviewer lacks usage context, dependency data, or a credible removal path, so risky access remains active.
- Impact follows when stale or unnecessary access continues to exist for another cycle, preserving excess privilege across human, service account, or agent workflows.
Breaches seen in the wild
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Sisense breach — unauthorized GitLab access led to exfiltration of access tokens, API keys and certificates.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Access reviews are not control points when they lack decision-grade identity context. A spreadsheet of entitlements turns certification into a paperwork exercise, because the reviewer cannot see usage, purpose, dependency, or expiry intent. That shifts the burden from the system to the manager and rewards the least disruptive answer. The practical conclusion is that review quality depends on evidence orchestration, not just review cadence.
Lifecycle failure is the real source of review debt. Joiner, mover, and leaver gaps push unresolved identity decisions into the next certification cycle, where they become harder to unwind and easier to approve. Temporary access, contractor access, and orphaned service accounts are not review problems first. They are lifecycle problems that show up in reviews because offboarding and ownership were never completed. Practitioners should treat certification as a backstop, not a cleanup process.
AI agents invalidate periodic review assumptions because access is no longer stable enough to certify later. The assumption that access persists long enough to be reviewed was designed for human-paced governance. That assumption fails when an agent can acquire and discard effective access within a single task window and can operate across multiple systems before the next review cycle. The implication is that identity governance must shift from retrospective certification to continuous verification for autonomous behaviour.
Coverage percentages can hide a weak denominator. A review programme may certify only the applications that were easy to integrate while excluding older platforms, local roles, contractor access, and shadow systems with the highest residual risk. That creates a false sense of control because the metric measures process completion, not enterprise exposure. The practical conclusion is that coverage reporting must be tied to the full identity estate, not just the reviewed subset.
From our research:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Only 44% of developers are reported to follow security best practices for secrets management, which helps explain why governance controls often outpace day-to-day behaviour.
- For the broader lifecycle angle, see NHI Lifecycle Management Guide for how provisioning, rotation, and offboarding reduce review debt before certification begins.
What this signals
A mature review programme now has to prove more than process completion. The practical test is whether access context, lifecycle events, and effective revocation are tied together closely enough that certification changes the live identity state rather than just the audit trail.
Review debt: when unresolved identity decisions are pushed into certification cycles, the campaign becomes the place where upstream failures are discovered instead of prevented. That is why NHI lifecycle discipline and review quality now have to be measured together, not as separate programmes.
When agentic access enters the estate, the governance model must move from periodic attestation to continuous verification. Human-paced review cycles cannot keep up with actors that can change privilege and execute actions within a single operational window.
For practitioners
- Attach evidence before certification begins Give reviewers recent usage, business purpose, approval history, expiry intent, and downstream dependency data for each entitlement so they are evaluating a decision, not reconstructing one.
- Link reviews to lifecycle triggers Start certification from joiner, mover, and leaver events so role changes, contractor exits, and temporary access exceptions are resolved before the next review cycle.
- Close the denominator gap Inventory excluded applications, local roles, shared accounts, and orphaned access paths so coverage reporting reflects the actual identity estate rather than the easiest integrations.
- Verify that revocation completed Treat approved removal as incomplete until the effective access state changes in the target system and the evidence is recorded for audit and exception handling.
- Apply continuous governance to agent access For AI agents, monitor task scope, delegated authority, and active tool use continuously because quarterly certification cannot observe access that changes within a single session.
Key takeaways
- Access reviews fail when reviewers are asked to certify entitlements without enough evidence to judge business necessity or operational impact.
- Lifecycle gaps and orphaned access turn certification into cleanup work, which preserves unnecessary privilege instead of removing it.
- AI agents require continuous governance because periodic review cannot reliably observe or constrain access that changes faster than the review cycle.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-07 | The article centers on reviewable NHI access, lifecycle gaps, and persistent entitlement risk. Map review findings to NHI-07 and remove access that lacks current business justification or ownership. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions management is the core control area behind review effectiveness. Use PR.AC-4 to ensure access changes are reviewed, approved, and enforced in the target system. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege and access enforcement are directly implicated by unnecessary entitlement retention. Apply AC-6 to reduce standing privilege and verify removals after certification decisions. |
| NIST Zero Trust (SP 800-207) | Continuous verification is relevant where periodic review is too slow for active access decisions. Use zero trust principles to reassess access dynamically instead of relying on quarterly attestation alone. | |
| NIST AI RMF | MANAGE | Agentic access governance requires ongoing operational management rather than periodic review only. Apply MANAGE to monitor agent scope, delegated authority, and active access continuously. |
Use zero trust principles to reassess access dynamically instead of relying on quarterly attestation alone.
Key terms
- Access Review Debt: Access review debt is the gap that builds when certification processes lag behind the actual state of permissions. The longer reviews depend on manual cycles and stale reports, the less assurance they provide, because the organisation is validating yesterday’s access instead of today’s risk.
- Decision-Ready Context: The minimum evidence a reviewer needs to make a meaningful access decision without reconstructing the access history manually. It includes usage, business purpose, approval basis, expiry intent, and downstream dependencies, all assembled before certification starts.
- Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
- Continuous Verification: A Zero Trust practice that re-evaluates trust during the session instead of relying on a single successful login. The control is stronger when context signals are available in real time and when the identity programme can act on those signals without creating excessive exceptions.
What's in the full article
Offroad AI's full analysis covers the operational detail this post intentionally leaves for the source:
- How Offroad AI's agentic workflow assembles entitlement context from tickets, logs, HR records, and application data before a reviewer sees it.
- The end-to-end campaign flow for routing decisions, executing approved changes, and verifying that effective access actually changed.
- How the system handles unresolved lifecycle cases such as contractor exits, temporary access, and orphaned accounts.
- The review evidence trail used to support audit and exception handling after certification closes.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org