By NHI Mgmt Group Editorial TeamBased on Lumos: “Click Fatigue is Killing Access Reviews—Here’s What to Do About It” (March 26, 2025)

TL;DR: Manual user access reviews are turning compliance work into repetitive approval traffic, and Lumos argues that dynamic access controls, JIT access, AI-driven prioritisation, and workflow automation can reduce the burden while preserving audit evidence, according to Lumos. The deeper issue is that review volume is outpacing governance design, so access control must become more adaptive upstream.


At a glance

What this is: This is a commentary on why manual user access reviews are failing at scale, with click fatigue turning a governance control into a high-volume approval exercise.

Why it matters: Identity, IGA, and compliance teams need to redesign review scope and evidence flows so that access certification remains a control rather than a checkbox.


Context

User access reviews are the periodic checks used to confirm that people still need the access they have. In practice, the control only works when reviewers have enough context, time, and accurate entitlement data to make meaningful decisions.

The article’s core governance problem is that review volume is growing faster than the process design around it. When hundreds or thousands of line items are pushed through a manual cycle, the control degrades into a compliance exercise instead of a risk-reduction mechanism.

That makes access review fatigue an identity governance problem, not just an operational nuisance. The pressure lands on IGA teams, app owners, and auditors at the same time, which is why the control needs to be redesigned upstream rather than defended at the point of approval.


Key questions

Q: What breaks when user access reviews become too large to manage manually?

A: Manual access reviews stop functioning as a meaningful control when reviewers cannot process the volume with enough context or time. The result is delayed certifications, inconsistent decisions, and rubber-stamped approvals. The practical failure is that governance turns into evidence collection after the fact rather than a reliable way to remove unnecessary access before risk accumulates.

Q: Why do access reviews stall in larger identity programmes?

A: Access reviews stall when reviewers lack context, administrators cannot see bottlenecks, and the workflow forces people to jump between tools to decide. As scale grows, those small delays compound into backlogs. The practical fix is not more reminders alone, but better visibility into progress, ownership, and unresolved items.

Q: How do organisations know if access certification is actually working?

A: Look for shrinking numbers of standing privileges, faster revocation after review decisions, and fewer orphaned or overprivileged accounts over time. If campaigns finish but access sprawl remains unchanged, the programme is producing documentation rather than governance. Working certification changes the entitlement baseline, not just the audit record.

Q: What should security teams do after a reviewer approves removal of access?

A: They should ensure the removal is enforced in the downstream systems that actually hold the entitlement and that the action is captured as audit evidence. A review decision that is not executed everywhere it matters leaves residual access in place. Governance should therefore connect certification, deprovisioning, and reporting in one controlled workflow.


Technical breakdown

Why manual access review campaigns break down

Manual user access reviews rely on human reviewers reading entitlement lists, checking business context, and deciding whether access remains justified. At enterprise scale, that model becomes fragile because the volume of identities, applications, and entitlements rises faster than reviewer capacity. The failure mode is not ignorance, it is overload. When the process asks the same people to re-evaluate thousands of items repeatedly, quality drops, evidence gathering slows, and approvals become routine rather than deliberate. That is why access certification often becomes a paper trail exercise instead of a control that meaningfully reduces risk.

Practical implication: reduce the number of items that ever reach manual certification.

How dynamic access controls change the review problem

Dynamic access controls shift governance from reviewing every entitlement equally to governing policy first. In practice, that means role-based access control and attribute-based access control are used to make access more adaptive as users move, join, or leave. The important mechanism is upstream simplification: if access is granted through consistent policy and reviewed policies can be auto-certified, fewer exceptions remain for human review. This does not remove governance. It changes the control point from repetitive line-item approval to policy design, policy enforcement, and exception handling.

Practical implication: standardise policy-driven access so only exceptions need human review.

Why just-in-time access and automation improve evidence quality

Just-in-time access reduces standing access by making privileges time-bound and request-based, so the review burden shrinks along with the blast radius. Automation then closes the loop by revoking or modifying access consistently across systems and preserving evidence for auditors. The key technical point is that a review decision is only useful if downstream systems enforce it and log the outcome. Without that, certification and remediation drift apart, leaving auditors with paperwork and security teams with residual access.

Practical implication: tie certification outcomes to automated remediation and audit evidence capture.


NHI Mgmt Group analysis

Click fatigue is an access governance failure, not a reviewer discipline problem. The article shows that manual certification breaks down when volume overwhelms the humans expected to validate it. That means the control is being asked to do more than its design can support, so errors and rubber-stamping become predictable. The practitioner conclusion is that review capacity must be engineered into the governance model, not assumed.

Review-based governance becomes weak when access design stays static. A policy model that depends on repeatedly rechecking the same entitlements is already compensating for poor upstream design. Dynamic access policy, time-bound access, and automated enforcement reduce the amount of stale entitlement state that certification has to clean up. The practical conclusion is that access reviews should become exception handling, not the primary control plane.

Adaptive access policy is the named concept that matters here. Static RBAC treated as a yearly certification target cannot keep pace with expanding entitlements and audit scope. The problem is not merely that the review is manual, but that the access model itself is too rigid for the volume it generates. The practitioner conclusion is to design access so that routine approvals shrink before the review cycle begins.

Evidence quality collapses when certification and remediation are separated. The article notes that reviewers need evidence that access changes were actually removed and tracked. That is the governance hinge: if approval, removal, and audit proof live in different systems or different workflows, the control loses credibility. The practitioner conclusion is that access governance must preserve a single chain from decision to enforcement to evidence.

Click fatigue is a symptom of identity governance maturity gaps. When entitlements expand faster than policy automation, organisations end up using human attention as the control. That is not sustainable across SOX, SOC 2, HIPAA, PCI-DSS, or ISO-aligned programmes. The practitioner conclusion is that mature access governance should reduce reviewer load while increasing assurance, not trade one for the other.

From our research library:

What this signals

Adaptive access governance is the pressure point here: organisations that still treat access certification as a once-a-year clean-up exercise will keep paying for reviewer attention instead of reducing entitlement risk. The better model is to shrink the review surface before the campaign begins, then reserve human judgment for exceptions and edge cases.

Access reviews also expose a deeper programme signal. When manual certification volume rises faster than policy automation, the organisation is using human approval as a compensating control for weak access design, which is a maturity problem rather than a workflow problem.


For practitioners

  • Prioritise policy-level access governance Review roles and attributes first, then certify only the exceptions that cannot be resolved through policy design or automated rules.
  • Reduce standing access with time-bound grants Shift sensitive access to request-based, time-limited approvals so routine entitlements do not accumulate into every review cycle.
  • Automate remediation after review decisions Connect review outcomes to provisioning and deprovisioning workflows so approved removals are enforced across SaaS, cloud, and on-prem systems.
  • Track evidence in the same workflow Preserve reviewer decisions, access changes, and audit artefacts in one governed process so certification evidence is available without manual reconstruction.
  • Flag only the highest-risk entitlements for human review Use contextual prioritisation to surface new access, role anomalies, over-privileged access, and segregation-of-duties violations instead of forcing equal attention to every line item.

Key takeaways

  • Manual user access reviews fail when review volume, context gathering, and remediation all depend on the same overworked human approval loop.
  • A large enterprise described one million certifications in a single year, which shows how quickly access review programmes can outgrow manual governance.
  • The fix is to reduce standing access, govern policy upstream, and automate enforcement so certification becomes exception handling rather than routine labour.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementManual access reviews and remediation are core account management controls in this article.
Recommendation — Strengthen account management so review decisions translate into timely removal of inappropriate access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing entitlements and certification outcomes at scale.
Recommendation — Apply entitlement governance to reduce review volume and keep authorisations current.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article argues for reducing unnecessary access before it reaches certification cycles.
Recommendation — Enforce least privilege so review campaigns have fewer standing entitlements to process.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe same access sprawl logic applies to non-human identities and other privileged actors.
Recommendation — Limit excess privilege so governance does not rely on repeated manual certification to catch overreach.

Key terms

  • User Access Review: A user access review is a periodic check that confirms each account still needs the access it has. In identity programs, the control is used to reduce excess privilege, support compliance, and catch access that has outlived its business need.
  • Change Fatigue: A condition where staff become less receptive to new tools or processes after repeated organisational change. In healthcare, it can reduce enthusiasm for mobile adoption even when the technology is useful. Teams must address communication, training, and early buy-in to prevent resistance from undermining rollout.
  • Dynamic Access Control: Dynamic Access Control is an access decision model that changes permissions in real time based on current context. It evaluates signals such as user risk, device posture, location, time, resource sensitivity, and behavior, then grants, limits, or revokes access continuously. It is commonly implemented with policy engines and identity telemetry.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org