TL;DR: Access reviews often default to rubber-stamped approvals because reviewers lack unified access visibility, usage context, and HR signals, according to Oleria Security. The governance gap is not the review itself, but the absence of evidence that lets managers make defensible decisions without slowing the business.
At a glance
What this is: This is an analysis of why access reviews break down in practice and how context, usage data, and unified visibility change the quality of decisions.
Why it matters: It matters because IAM, IGA, and GRC teams cannot reduce privilege risk if reviewers are making approval decisions with incomplete data across human identities, NHIs, and delegated access paths.
👉 Read Oleria Security's analysis of context-aware access reviews
Context
Access reviews are meant to prove that people still need the access they have, but most programmes struggle because the decision data is fragmented across directories, SaaS applications, cloud platforms, HR records, and security logs. Without a single view of entitlement, usage, and role change, reviewers end up approving what looks normal instead of what is actually appropriate, which weakens IAM governance across the enterprise.
For identity teams, the core problem is not policy intent but evidence quality. When reviewers cannot see whether access is used, whether peers hold the same entitlement, or whether role changes have altered the need for access, the review becomes a compliance exercise rather than a control that meaningfully right-sizes privilege. That is a familiar failure mode in mature IGA programmes, and it applies across human access and other governed identity types where lifecycle decisions depend on context.
Key questions
Q: How should security teams improve access certification without creating reviewer fatigue?
A: Security teams should reduce the number of low-value decisions each reviewer sees by grouping stable access, prioritising unusual or privileged entitlements, and pre-classifying items that rarely change. The goal is to preserve human attention for access that is hard to justify. Certification works when reviewers can make informed decisions quickly, not when they are forced to process noise.
Q: Why do access reviews often become compliance exercises instead of risk controls?
A: Because the process usually asks people to approve or revoke access without enough evidence to judge risk. When reviewers cannot see usage, business context, or how access compares with peers, they default to the safest administrative option. That creates a documentation exercise, not a privilege-reduction control.
Q: What breaks when access reviews ignore the data behind an entitlement?
A: What breaks is prioritisation. Teams end up treating low-impact and high-impact accounts the same, so the most dangerous access paths can sit behind routine certification cycles while less relevant entitlements consume attention. That creates a false sense of coverage and weakens least-privilege enforcement where it matters most.
Q: What makes an access review process defensible in an audit?
A: A defensible access review process produces clear evidence of who reviewed each item, what decision was made, and what remediation followed. Auditors need a campaign record, not just a completion percentage. If decision history is fragmented across tools or messages, the governance trail is harder to prove.
Technical breakdown
Why access review campaigns become manual and slow
Access reviews slow down when entitlement data has to be stitched together from multiple systems before a reviewer can even begin. A single user can have accounts, groups, roles, permissions, and resource access spread across identity providers, SaaS apps, cloud services, and on-prem systems, each with different schemas and ownership models. That makes correlation work expensive and fragile. By the time teams assemble the evidence, the access picture may already have changed. The result is a lagging governance process that looks structured on paper but operates with stale state in practice.
Practical implication: reduce manual evidence gathering by building a unified access inventory before running review campaigns.
Why context changes reviewer decisions
A list of entitlements is not enough for a defensible access decision. Reviewers need usage evidence, peer comparisons, and role or department change signals to judge whether access is still appropriate. Without those cues, managers are forced to choose between approving access they cannot validate or revoking access they cannot confidently judge as unnecessary. That pushes people toward the safest-looking administrative answer, which is often rubber-stamping. Context is therefore not a nice-to-have feature. It is the difference between an access review that documents risk and one that actually reduces it.
Practical implication: enrich each entitlement with activity, peer, and HR context before asking approvers to decide.
How composite access graphs support governance decisions
A composite access graph links accounts, groups, roles, permissions, and resources into one operational view. That matters because access review is really a relationship problem, not a list problem. If a user is removed from one group but retains privileges through another path, the review has failed even if the visible entitlement was closed. A graph model helps surface hidden privilege chains and shows how access is inherited or duplicated across systems. For identity governance, that makes the campaign outcome more accurate and the remediation step less likely to leave residual access behind.
Practical implication: evaluate whether your IGA tooling can resolve indirect entitlements, not just direct assignments.
NHI Mgmt Group analysis
Access reviews fail when they are treated as enumeration exercises instead of evidence-based decisions. The article shows a familiar identity governance pattern: reviewers are handed entitlement lists without the context needed to decide whether access is still justified. That turns access review into a control that documents uncertainty rather than resolving it. The practitioner conclusion is simple: if the reviewer cannot explain the decision, the programme has not actually reduced privilege risk.
Context-first governance is the real control gap, not reviewer diligence. Security teams often assume the problem is that managers do not care enough, but the deeper issue is that the review workflow does not supply the right decision inputs. Usage, peer norms, and HR changes are the minimum evidence set for making removal decisions defensible. The implication for IAM and IGA leaders is that governance quality depends on data completeness before it depends on reviewer intent.
Composite access modelling creates a more accurate picture of effective privilege. A user’s actual access often comes from several paths at once, and entitlement-by-entitlement review can miss residual permissions after a cleanup action. That is why hidden privileges survive even when a campaign appears complete. The field should treat access graphing as a governance requirement, not just a reporting convenience, because campaign outcomes are only as good as the identity relationships they can see.
Auditor-ready reporting should be the output of governance, not a separate evidence scramble. When review decisions, justifications, and remediation actions are captured as part of the campaign, compliance evidence becomes a byproduct of control execution. That aligns IAM, GRC, and security operations around a single workflow instead of a late-stage documentation exercise. Practitioners should measure whether their review process produces defensible evidence automatically, because manual evidence assembly is usually a sign that the control is already failing.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- Access governance failures are not limited to one identity class, and our Ultimate Guide to NHIs , Key Challenges and Risks explains why visibility and privilege context remain persistent control gaps.
- As access programmes mature, teams should compare identity review quality against the control expectations outlined in the NIST Cybersecurity Framework 2.0 and close the gap before approvals become ritual.
What this signals
Context-aware access reviews will become the baseline expectation for mature IAM programmes. Once reviewers can see usage, peer norms, and HR changes in one place, manual approval behaviour becomes much easier to challenge. Teams that still depend on opaque entitlement lists will find their governance process producing noise, not assurance.
Composite access visibility is a governance pattern that will matter beyond human access. The same evidence logic increasingly applies wherever identity decisions depend on lifecycle state, inheritance, or delegated access. For practitioners, the practical shift is toward evidence-rich review workflows that can support audit, remediation, and business continuity at the same time.
For practitioners
- Build a unified access inventory first Correlate accounts, groups, roles, permissions, and resources across IdPs, SaaS, cloud, and on-prem systems before opening a review campaign. If reviewers do not start from a single access picture, they will miss inherited and duplicate entitlements.
- Add usage and peer context to every entitlement Show recent activity, similar-role access patterns, and department or role changes next to each privilege so approvers can decide with evidence instead of intuition. That context should be visible in the review workflow, not buried in separate tickets or reports.
- Prioritise higher-risk reviewers and access sets Start campaigns with employees whose roles, departments, or access paths indicate elevated risk, then sequence the remaining population based on governance impact. That reduces reviewer fatigue and focuses attention where revocation decisions matter most.
- Evaluate hidden privilege after every revocation Treat removal from a group or role as incomplete until you verify that no alternate entitlement path still grants the same access. Campaign closure should confirm the full effective privilege state, not just the visible entitlement that was changed.
Key takeaways
- Access reviews fail when reviewers are asked to decide without the context required for a defensible answer.
- The operational problem is fragmented identity data, hidden privilege paths, and review fatigue, not simply low reviewer effort.
- Programmes that combine unified visibility with usage-aware evidence can turn access review from a checkbox into a real governance control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access reviews and least privilege align directly with identity entitlement governance. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management covers access review, authorisation, and ongoing entitlement control. |
| ISO/IEC 27001:2022 | A.5.18 | Access rights management aligns with periodic review and authorisation of user privileges. |
| NIST SP 800-63 | SP 800-63C | Federated identity context matters where access review spans multiple identity sources. |
Use SP 800-63C to preserve trustworthy federation context when entitlement decisions cross systems.
Key terms
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Composite Access Graph: A composite access graph is a unified model that connects accounts, groups, roles, permissions, and resources across systems. It helps identity teams see effective privilege paths, including inherited or duplicated access that entitlement-only reviews can miss.
- Usage-Aware Recommendation: A usage-aware recommendation is a decision prompt that combines activity data, peer comparisons, and role context to suggest approval or revocation. For identity governance, it turns review from a guess into a structured decision with evidence attached.
- Effective Privilege: Effective privilege is the real access an entity can exercise after inheritance, delegation, token scope, and connected-system trust are applied. It is often broader than the permissions shown in an identity repository, which is why runtime validation matters.
What's in the full article
Oleria Security's full post covers the operational detail this analysis intentionally leaves for the source:
- Composite access graph implementation details for unifying IdP, SaaS, cloud, and on-prem entitlement data
- Reviewer recommendation logic and the contextual inputs used to support approve or reject decisions
- Campaign orchestration options for reassignment, reminders, escalation, and mid-cycle edits
- Auditor-ready reporting structure for review decisions, justifications, and remediation actions
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org