TL;DR: Access decisions are drowning teams in volume, with median approval times of 15 minutes, some latencies over 24 hours, 43.5% unused access after 90 days, 2,300% growth in agents and NHIs, and 90% unreviewed access, according to Opal Security. The governance problem is not just speed: review-based IAM assumes access can be assessed slowly and still remain meaningful.
At a glance
What this is: This is Opal Security's analysis of AI-assisted access review, showing that manual approval workflows are struggling as agent and non-human identity access grows faster than review capacity.
Why it matters: It matters because IAM, IGA, and PAM teams need governance models that can handle high-volume, context-heavy access decisions for humans, NHIs, and agents without letting standing access and stale approvals accumulate.
By the numbers:
- Median approval time stretched to 15 minutes, and latencies at some enterprises ran over 24 hours.
- 43.5 percent of granted access went unused for more than 90 days.
- Agent and non-human identities grew 2,300 percent, and 90 percent of that access went unreviewed.
👉 Read Opal Security's analysis of AI review for access requests and NHI growth
Context
Identity governance breaks down when approval workflows cannot keep pace with the number of access decisions, especially as non-human identities and agents multiply. In this case, the primary issue is not whether teams can make correct decisions in theory, but whether they can make them with enough context and speed for the decision to still matter.
The article centres on AI-supported access review, where an AI reviewer gathers request context, compares it with policy, and escalates uncertain cases. That is relevant to IAM and IGA because the same approval bottlenecks now affect human requests, service accounts, and AI-driven workflows. The question is no longer whether review exists, but whether review can scale without degrading into delayed rubber-stamping.
Key questions
A: Use context-aware automation for routine, policy-conforming requests and reserve humans for exceptions. The goal is not to remove review, but to remove repetitive work that slows down obvious decisions. Teams should define the signals that make a request safe to auto-handle, then escalate anything that lacks ownership, purpose, or policy fit.
Q: Why do non-human identities require more than traditional IAM reviews?
A: Because traditional IAM reviews were built around people, stable employment relationships, and visible login activity. Non-human identities often live inside code, integrations, and automation where ownership is unclear and access is persistent. Review cycles that depend on human session patterns will miss the actual risk, which is hidden privilege and stale credential exposure.
Q: What do organisations get wrong about access that has not been used for months?
A: They often treat it as harmless because it is dormant, when it is still active privilege. Dormant access still expands blast radius and can be abused if the account, token, or agent is compromised later. If access has no recent business use, teams should treat it as a candidate for revocation or tighter scoping.
Q: How should security teams automate access governance without losing control?
A: Security teams should automate repetitive review and provisioning tasks, but keep policy ownership human-led. The model works when risk tiers, SoD rules, and approval thresholds are defined centrally, then enforced consistently in workflow. Automation should speed execution and evidence collection, not replace governance judgement or exception handling.
How it works in practice
Context-aware access review for IAM and IGA
Access review is a decision workflow, not just a ticket status. The reviewer needs request intent, existing entitlements, peer group access, resource sensitivity, and evidence of how similar access has been used before. When that context is scattered across Notion, Jira, ServiceNow, Slack, and incident systems, human reviewers either over-trust the request or spend too long reconstructing the case. AI-assisted review works by aggregating those signals and attaching a rationale to the recommendation, which makes the decision auditable rather than opaque.
Practical implication: model your access requests as context problems, then centralise the signals reviewers actually need before approval.
Why agent and NHI review needs different governance logic
Agents and NHIs change the access equation because they scale faster than human review and often carry broader entitlement sets. A service account or AI agent may not have a stable job description, a visible manager, or a clear lifecycle owner, which makes conventional recertification weak. The article's point is not that these identities are inherently uncontrolled, but that they are often described poorly and reviewed too late. Governance therefore depends on explicit context, ownership, and usage evidence, not on assuming a human-shaped access pattern.
Practical implication: require ownership and purpose metadata for every non-human identity before it enters the approval and recertification flow.
Graduated authority and policy-conforming automation
The underlying architecture is graduated authority. The system can recommend, decline, or escalate depending on confidence and policy fit, rather than forcing every request through a human. That matters because most access requests are routine, but the risky minority consumes disproportionate reviewer time. The control problem is to keep automation inside a narrow lane, with clear logging and escalation thresholds, so routine approvals can be accelerated without removing accountability from ambiguous cases.
Practical implication: separate routine policy-conforming grants from ambiguous requests and only automate the first category.
NHI Mgmt Group analysis
Access review is no longer the primary control for fast-moving non-human identities. Review cadences were designed for access that persists long enough to be examined. That assumption breaks when agents and NHIs are created, expanded, and used faster than the review queue can catch up. The implication is that identity governance has to stop treating review as the main safety net for high-velocity machine access.
Ephemeral approval windows create governance debt when unused access survives the decision that granted it. The article's 43.5 percent unused-access figure shows that many access grants outlive their operational need. That is not just waste, it is unresolved accountability, because the entitlement remains valid even after the decision context has gone stale. Practitioners should treat delayed revocation as governance debt, not admin backlog.
Agent entitlement sprawl is a named control problem, not an edge case. Opal Security's own data show agents holding 3x the entitlements of people and largely escaping review. That is a structural signal that human-centric approval models are being reused in a machine-heavy environment where entitlement density is much higher. The practical conclusion is that entitlement scope and reviewer context must be governed as one system.
Continuous access decisions will become the default governance pattern for mixed identity estates. As NHI and agent populations grow, teams will need to make decisions at the pace of request generation, not at the pace of committee review. That does not eliminate human oversight, but it does shift the control point closer to policy evaluation and automated escalation. Security programmes that still rely on periodic manual approval will remain exposed to standing privilege and stale grants.
Identity blast radius: the real risk is not how many requests arrive, but how much privilege each granted identity can accumulate before anyone notices. The article makes clear that access volume, entitlement size, and review latency are now coupled. Once that coupling exists, every delayed decision expands potential blast radius across human, NHI, and agent workflows. Teams should focus on limiting cumulative entitlement, not just speeding up approvals.
From our research:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
- For a broader governance baseline, see Ultimate Guide to NHIs , 2025 Outlook and Predictions for how identity programmes are adapting to agentic growth.
What this signals
Approval latency is becoming an identity control risk, not just an operations metric. When a request can sit for hours before a decision, the access context that justified it may already have changed. Teams should connect approval SLA monitoring to standing privilege reduction, especially where service accounts and AI agents are involved.
Agent entitlement density will force IAM teams to think in terms of privilege load, not just request volume. If each agent holds materially more access than a person, the control objective shifts from processing more tickets to limiting how much access can accumulate in one identity. That is the point at which a single approval can meaningfully increase blast radius.
Identity blast radius becomes the practical measure of whether access governance is keeping up. Even with our research showing 85% of organisations lack full visibility into third-party OAuth connections, the deeper issue is whether each granted identity can still be explained, bounded, and revoked quickly enough to matter.
For practitioners
- Map request context to every access workflow Collect requester identity, peer access, resource sensitivity, and prior usage evidence before any approval is made. Put the same context into human, service account, and agent requests so reviewers are not reconstructing the case manually.
- Set escalation thresholds for ambiguous requests Define which combinations of policy conflict, unusual entitlement scope, or missing ownership metadata must be escalated to a human reviewer. Keep the automation lane narrow and explicit so the system only handles clear policy-conforming cases.
- Track unused access as governance debt Review grants that remain unused after 90 days and treat them as stale entitlements that still enlarge blast radius. Tie revocation to usage evidence, not just to annual recertification cycles.
- Require purpose and ownership metadata for NHIs and agents Do not allow non-human identities into approval flows without a named owner, explicit purpose, and lifecycle record. That metadata is what makes recertification and incident response possible later.
Key takeaways
- The article shows that manual approval workflows are losing pace as non-human identities and agents multiply.
- The clearest evidence is operational, with long approval latencies, large amounts of unused access, and agent entitlements outgrowing human ones.
- Practitioners should treat access decisions as a context problem and automate only the routine cases with strong escalation rules.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centres on governance for non-human identities and stale access decisions. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions and least privilege are the core governance issue here. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator and credential governance underpins reviewable access for NHIs and agents. |
| NIST Zero Trust (SP 800-207) | The article aligns with continuous verification and policy-based access decisions. |
Use zero trust principles to evaluate each access request in context rather than relying on standing trust.
Key terms
- Context-Aware Access Review: A decision process that evaluates access requests using request intent, existing entitlements, resource sensitivity, and operational evidence. In identity programmes, it reduces blind approvals by forcing reviewers or automation to weigh the real circumstances behind the request, not just the ticket itself.
- Agent Entitlement Density: The amount of privilege accumulated by an AI agent or non-human identity relative to a human user. High entitlement density increases blast radius and makes manual review less effective because each identity can carry more potential impact than the reviewer expects.
- Governance Debt: The accumulation of unresolved identity control weaknesses created when teams prioritise speed over lifecycle design. In NHI environments, it shows up as accounts with unclear ownership, undocumented purpose, stale credentials, and no reliable retirement path, all of which make later security work harder.
What's in the full announcement
Opal Security's full article covers the operational detail this post intentionally leaves for the source:
- How Paladin gathers request context from connected systems before making a recommendation
- The approval and escalation flow for routine, risky, and ambiguous access requests
- Examples of how role mining and policy suggestions are applied in live access governance
- The specific integrations the platform reads from and how the review lane is configured
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org