TL;DR: Compliance automation tools improve evidence collection, monitoring, and audit readiness, but the article makes clear they do not govern who has access to what or whether that access is appropriate, according to Zluri. That makes access governance the missing layer when compliance programmes need defensible reviews, not just cleaner workflows.
At a glance
What this is: This article argues that compliance automation tools improve audit workflows but still leave access governance unresolved.
Why it matters: IAM, IGA, and compliance teams need a separate access governance layer because most frameworks ultimately depend on proving who has access, why, and whether it is appropriate.
Context
Compliance automation tools can reduce manual evidence gathering, monitoring, and reporting, but they do not answer the deeper governance question at the access layer. The article’s core point is that compliance frameworks still depend on proving who has access to what, whether that access is appropriate, and whether the decision trail is defensible.
That distinction matters for identity programmes because GRC workflows and access governance solve different problems. GRC platforms manage the evidence and control process, while access governance determines whether the underlying access data is accurate enough to support audits, reviews, and remediation.
Key questions
Q: What breaks when compliance automation does not have access governance behind it?
A: The programme can still produce clean audit evidence while leaving excessive or stale access untouched. That creates a false sense of control because the report is complete but the underlying entitlement state is not. In practice, the review may satisfy process requirements without reducing actual risk, especially when remediation does not reach the systems that grant access.
Q: Why do compliance frameworks still depend on identity governance?
A: Because most frameworks ultimately ask who has access, what level of access they hold, and whether that access is justified. Compliance automation can document the control, but identity governance determines whether the underlying access decision is actually valid.
Q: How can security teams tell whether privileged access reviews are actually working?
A: They are working when every privileged entitlement is inventoried, every decision is traceable, and revoked access is removed from all connected systems without delay. If the organisation can only show approvals but not downstream revocation, the review is administrative recordkeeping rather than governance. Proof of removal is the best maturity signal.
Q: How should organisations implement compliance automation without creating new governance gaps?
A: Start with a compliance audit, then map the highest-friction workflows, data sources, and regulatory obligations into automated controls. The strongest programmes use centralized dashboards, integration with core systems, and continuous monitoring so compliance is measured rather than chased. Engage compliance, IT, and leadership early, and keep refining workflows as regulations change. Automation should reduce manual error, not simply digitise the old process.
Technical breakdown
Why compliance automation stops at evidence workflows
Compliance automation tools are built to collect evidence, track controls, and maintain audit readiness across frameworks such as SOX, HIPAA, GDPR, PCI DSS, and ISO 27001. They are effective at workflow automation, but they are not designed to determine whether a user, app, or role should hold a specific entitlement. That is an access-governance problem, not a compliance-workflow problem. When programmes rely on the wrong layer for the wrong decision, they can appear organised while still carrying unresolved entitlement risk.
Practical implication: Use compliance automation for evidence and workflow control, but treat entitlement validity as a separate governance domain.
Why user access reviews need access intelligence
A defensible user access review depends on more than a spreadsheet of application names. Reviewers need to see actual entitlement depth, not just login presence, plus policy context that shows whether access is excessive or incompatible. The article highlights this by pointing to overprivileged accounts and toxic access combinations that need structured review and remediation. Without access intelligence, the review becomes a formality that can pass audit while missing inappropriate access.
Practical implication: Build reviews around entitlement-level data and policy context, not application-level presence alone.
How segregation of duties issues survive compliance tooling
SoD violations persist when compliance tooling tracks the control but does not understand the access combination underneath it. The article notes that toxic access combinations can be flagged and remediated automatically only when the access layer is visible to the system performing the review. That means compliance automation may document the control, but it cannot reliably enforce SoD unless it is fed authoritative access data from the identity layer.
Practical implication: Tie SoD review and remediation to authoritative access records rather than relying on audit evidence after the fact.
NHI Mgmt Group analysis
Compliance automation and access governance are not substitutes: one manages evidence, the other governs entitlement validity. The article is right to separate framework tracking from access decisions because an organisation can be audit-ready and still not know whether access is appropriate. For IAM and IGA teams, that means the compliance workflow should never be mistaken for the control itself.
Defensible review depends on entitlement intelligence, not control checkboxes: a user access review only has value if it can show what access exists at entitlement level and why it is acceptable. Application-level presence is too coarse for modern SaaS estates, where toxic combinations and overprivilege often hide inside layered permissions. Practitioners should treat access visibility as evidence quality, not just operational convenience.
SoD failures are governance failures first and tooling failures second: the article’s example shows that compliance platforms can record that a review happened while leaving incompatible access intact. That is a structural gap in how organisations separate audit process from access control. The practical conclusion is that compliance posture is only defensible when the access layer is authoritative enough to drive remediation, not merely document it.
Access governance is the missing control plane in many compliance stacks: the article surfaces a wider market pattern where GRC tooling is asked to absorb identity decisions it was never built to make. That blurs responsibility across compliance, IAM, and security operations. The governance model that wins is the one that assigns entitlement decisions to the identity layer and evidence handling to the compliance layer.
Audit readiness is becoming a data-quality problem: if the access inventory feeding reviews is stale, incomplete, or app-level only, the resulting evidence may look clean while still being weak. That changes the role of identity governance in compliance programmes from a back-office task to a core assurance function. The implication is simple: practitioners need trusted access data before they can trust the audit trail.
What this signals
Access governance has become the control that determines whether compliance evidence is trustworthy: once reviews are built on incomplete access data, the resulting audit trail can look disciplined while still hiding entitlement risk. Practitioners should treat access visibility as a prerequisite for compliance credibility, not as a downstream enhancement.
Compliance automation will continue to matter for evidence collection and monitoring, but identity programmes now have to decide where the authoritative entitlement record lives. If that record is fragmented across tools, reviews become harder to defend and easier to game.
Access intelligence is the missing layer: the article exposes a common programme failure where the process is automated but the underlying decision remains manual or shallow. That is where IAM, IGA, and compliance responsibilities converge, and where governance discipline becomes measurable.
For practitioners
- Separate evidence automation from entitlement governance Map which controls your compliance tool can evidence and which controls require authoritative access data from the identity layer. Keep user access review, SoD validation, and privilege decisions outside generic GRC workflows when the tool cannot see entitlement depth.
- Validate access reviews at entitlement level Require reviewers to see what access a user actually holds inside each application, not just whether the user can log in. Use that view to flag overprivileged accounts and identify incompatible access combinations before sign-off.
- Build a remediation path for toxic access combinations Connect review findings to a workflow that can remove conflicting access immediately rather than only logging the issue for audit evidence. The article’s point is that compliance value increases when review findings change access state.
- Treat audit readiness as an output of data quality Check whether the access inventory feeding your compliance workflow is complete, current, and source-of-truth aligned. If the underlying identity data is weak, the audit trail will be defensible in format but fragile in substance.
Key takeaways
- Compliance automation improves audit workflows, but it does not by itself decide whether access is appropriate or excessive.
- The weak point is the access layer, where entitlement depth and toxic combinations can still hide behind clean-looking compliance evidence.
- Defensible compliance programmes pair workflow automation with authoritative identity governance so reviews actually change access state.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on excessive access and inappropriate entitlements hidden by compliance workflows. |
| NHI-01 — Improper Offboarding | Access review and remediation depend on accurate lifecycle governance across identities. | |
| Recommendation — Review entitlement scope against NHI-05 and remove access that exceeds business need. Tie access review findings to offboarding and revocation workflows before audit sign-off. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about proving who has access and whether those permissions are appropriate. |
| Recommendation — Use PR.AA-05 to anchor entitlement reviews in authoritative access data. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article discusses review, tracking, and remediation of active access across applications. |
| Recommendation — Apply CIS-5 to keep account inventories current and remove inappropriate access promptly. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The core issue is whether access control decisions are defensible across compliance workflows. |
| Recommendation — Map access review evidence to A.5.15 so compliance controls reflect actual access decisions. | ||
Key terms
- Access Governance: Access governance is the policy and workflow layer that manages how access is requested, approved, certified, and revoked. In SaaS environments it helps standardise control across many applications, reducing inconsistency between teams. It is most effective when it covers both human accounts and non-human identities.
- Entitlement Level: Entitlement level is the specific permission a user or system holds inside an application or platform, such as a role, privilege, or action right. It is more precise than simply knowing that access exists. For compliance and review workflows, entitlement-level visibility is what makes overprivilege and toxic combinations detectable.
- Toxic Access Combination: A toxic access combination is a set of permissions that becomes dangerous when granted together, even if each entitlement looks acceptable on its own. In identity governance, these combinations matter because they can enable misuse, separation-of-duties failures, or broader compromise.
- Audit Readiness: Audit readiness is the state where an organisation can produce current, traceable evidence that controls are designed and operating as intended. In practice, it depends on timely identity data, clean ownership, and workflows that preserve proof as changes happen, not after the fact.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org