TL;DR: Most organisations only govern access changes that show up in HRIS, yet the source article argues that event-based work, projects, and temporary collaborations create the larger share of access creep by adding access with no clear end point. That gap leaves JML covering the visible minority while the invisible majority compounds silently, according to Zluri. The governance problem is not access review cadence alone, but the lack of cleanup triggers for access that begins outside employment changes.
At a glance
What this is: This article argues that access sprawl is split between visible role-change growth and a larger invisible share created by projects and temporary work that never cleanly ends.
Why it matters: It matters because IAM, IGA, and PAM programmes that only react to HRIS events will miss most access creep, leaving dormant access active across the workforce.
Context
Access sprawl is the accumulation of permissions beyond what a role or task still justifies. In identity governance terms, the article says the problem is not limited to joiner-mover-leaver events because temporary collaboration, emergency work, and project-based access also create long-lived entitlement growth.
The governance failure is that many programmes only see what HRIS can model. If access starts in a project, migration, or ad hoc collaboration, there may be no formal end event for cleanup, so access survives long after the business need has passed.
Key questions
Q: What breaks when access governance only follows HRIS events?
A: It misses the larger share of access growth that comes from projects, collaboration, emergency work, and other non-HRIS activity. That means access can expand without any lifecycle trigger, leaving JML focused on movers while static employees and temporary grants keep accumulating permissions outside the review path. The result is false confidence in governance coverage.
Q: Why does event-based access create more governance risk than role-change access?
A: Because it usually has a clear start but no reliable end. A promotion creates an HRIS trail, but a project or emergency request often ends informally, leaving no obvious moment for removal. That makes event-based access easier to grant and much harder to retire, which is why it compounds silently across the organisation.
Q: How do teams know whether unauthorized access controls are actually working?
A: Look for fewer standing credentials, lower lateral movement potential, and faster revocation when access is no longer needed. Good controls also reduce the number of identities that can reach sensitive systems without explicit approval. If access paths remain broad after a change, the control model is still too loose.
Q: What is the difference between role-based access growth and project-based access growth?
A: Role-based growth is tied to formal employment changes that HRIS can see, while project-based growth comes from temporary work that HRIS usually does not model. The first is visible and reviewable, even if poorly managed. The second is invisible until someone actively tracks end dates, ownership, and entitlement cleanup outside the HR workflow.
Technical breakdown
Scheduled-based access growth still leaves old access behind
Scheduled-based sprawl happens when promotions, department moves, and manager changes add new access but do not remove the old set. HRIS can see these changes, so the lifecycle event is visible, but visibility is not the same as governance. JML workflows often provision the next role and leave historical access in place, which turns every move into cumulative over-entitlement. The result is a role-history trail that looks controlled on paper but expands privilege in practice.
Practical implication: tie role-change workflows to removal logic, not just provisioning logic.
Event-based access sprawl escapes HRIS entirely
Event-based sprawl comes from work that HRIS does not model: projects, cross-functional collaboration, emergency access, tool migrations, and temporary coverage. These grants usually have a start point but no enforceable end point, so access survives because no system owns the cleanup trigger. That makes the problem structurally different from role-change creep. The entitlement is not wrong when granted, but it becomes stale because the governance model never records when the business reason ended.
Practical implication: create non-HRIS expiry and review triggers for temporary access.
The invisible majority is a lifecycle design problem, not a review problem
Quarterly access reviews can confirm that access exists, but they do not create the missing event that should have removed it. If the source of access growth is project work and informal collaboration, then recertification alone arrives too late and looks at the symptom rather than the cause. The article’s underlying point is that access governance must understand where access originates, how long it should live, and what event should end it. Without that lifecycle design, review cadence only audits accumulation after the fact.
Practical implication: move cleanup triggers closer to access issuance and task completion.
Breaches seen in the wild
- Millions of Misconfigured Git Servers Leaking Secrets: Nearly 5 million misconfigured Git servers expose sensitive secrets and credentials online.
- Massive Docker Hub Secrets Leak: 10,000+ Docker Hub container images expose hardcoded secrets and authentication keys.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Access sprawl is a lifecycle failure, not a staffing-change problem: The article shows that HRIS-driven JML only governs a minority of entitlement growth because much of it begins in project work, collaboration, and temporary operational needs. That means the control model is misaligned with how access is actually created and retained. The practitioner conclusion is that governance must follow the access source, not just the employee record.
Invisible access accumulation is the harder control problem because it has no natural trigger: Role changes at least create an event that can be governed, even if the cleanup is incomplete. Event-based access has no comparable signal, so it persists by default unless another system creates one. The implication is that identity governance needs lifecycle controls that operate outside HRIS events and can revoke access when the business reason ends.
JML is necessary but structurally insufficient for modern access governance: The article does not argue that movers are harmless, only that movers are easier to see than static employees with project-driven access growth. That distinction matters because many programmes assume access creep is mostly a mover problem and therefore optimise the visible minority. Practitioners should re-centre governance on entitlement origin, duration, and offboarding trigger coverage.
Project-end offboarding gap: The article exposes a named failure mode where access granted for temporary work has no formal closure path, so it becomes permanent by inertia. This is not a provisioning weakness alone; it is a governance assumption that every meaningful access change will appear in HRIS. The practitioner conclusion is that access lifecycle ownership must extend to project and collaboration contexts, not stop at employment status.
What this signals
Access lifecycle ownership needs to move beyond HRIS-triggered events: If your governance model only knows how to react to promotions and transfers, it will continue to miss the larger pool of access that comes from temporary work. The practical shift is to govern the start and end of access, not just the change in job title.
Project-end cleanup is the missing control in many IGA programmes: Access granted for launches, migrations, coverage, and collaboration should not rely on users remembering to give it back. When no one owns the closure event, entitlement growth becomes cumulative by default and audit findings become inevitable.
For practitioners
- Map access sources by lifecycle trigger Separate access into HRIS-triggered, project-triggered, emergency-triggered, and migration-triggered categories so you can see which entitlements your current JML process can and cannot govern.
- Add expiry to temporary access Require every project, emergency, and temporary collaboration grant to carry an end date or review checkpoint at issuance, then automate revocation when that checkpoint passes.
- Build cleanup ownership into project closure Assign a named owner for removing access when a project ends, rather than assuming the employee's line manager will notice that the work has finished.
- Review static users for accumulated access Flag employees with no role change over long periods but a rising entitlement count, because they often accumulate access through repeated informal work that never clears out.
- Use dormant access as a removal signal Treat long periods of non-use as evidence that project, collaboration, or emergency access has outlived its purpose and should be removed or reapproved.
Key takeaways
- The article argues that access sprawl is not mainly a promotion problem, because temporary work and cross-functional activity create a larger hidden pool of stale access.
- HRIS-visible role changes are only part of the picture, while project-based grants often have no closure mechanism and therefore persist.
- Identity programmes need expiry, ownership, and cleanup triggers for access that starts outside HRIS, or JML will keep governing the visible minority.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Temporary access that never ends is the core failure pattern in this article. |
| NHI-05 — Overprivileged NHI | Access sprawl turns users into over-entitled identities regardless of role stability. | |
| NHI-09 — NHI Reuse | Repeated temporary grants accumulate because the same access is reused across many short-lived tasks. | |
| Recommendation — Track project and emergency grants as offboarding events so stale access is removed when the business need ends. Review entitlement growth against role baseline and remove access that no longer matches current need. Limit repeated re-use of the same broad access set across projects and force fresh approval for each new need. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about controlling entitlement growth and cleanup across the access lifecycle. |
| Recommendation — Align entitlement reviews to actual access lifecycle events so unused permissions are removed, not just approved. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle governance is central to stopping stale access from persisting after tasks finish. |
| Recommendation — Enforce account ownership, review, and deprovisioning controls for temporary and project-based access. | ||
Key terms
- Access Sprawl: The gradual accumulation of permissions across users, services, and integrations until no one can easily explain why access still exists. In NHI environments, it often appears when machine identities keep inherited rights long after their original business purpose has changed.
- Event-Based Access: Event-based access is temporary permission granted for a specific business activity, such as a project, emergency, or backup assignment. It should expire when the activity ends, but it often persists because no reliable end trigger exists in the governance process.
- Joiner Mover Leaver: Joiner Mover Leaver is the identity lifecycle process for creating, changing, and removing access as people enter, change roles, or leave an organization. It governs provisioning, modification, and deprovisioning across systems, ensuring access matches current job needs and reducing orphaned accounts, privilege creep, and residual access risk.
- Access Lifecycle Management: Access lifecycle management is the discipline of creating, changing, reviewing, and removing access over time. For NHI security, it is essential because machine credentials often lack natural offboarding points, so rotation and revocation must be engineered into the operating model, not handled ad hoc.
Deepen your knowledge
Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org