By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: Opal SecurityPublished July 21, 2026

TL;DR: Continuous access comparison is now generally available, letting identity teams compare any two users side by side, surface standing, unused, overprivileged, and irregular access, and trigger remediation such as UARs, expiration dates, or permission removal, according to Opal Security. The governance shift is from periodic review to continuous access optimisation, where the real question is why access differs at all.


At a glance

What this is: Opal Security says continuous access comparison helps teams identify why two users differ and take remediation action faster.

Why it matters: It matters because IAM teams need a way to move from periodic access review to continuous privilege reduction across human, NHI, and AI-driven access patterns.

👉 Read Opal Security's article on Access Comparison for outlier access


Context

Continuous access comparison is a governance control for spotting why one identity has different access from another, especially when standing, unused, or irregular permissions hide inside groups, roles, and application entitlements. For IAM and IGA teams, the issue is not just visibility. It is whether they can explain and act on access drift before it becomes normalised.

That matters for NHI governance as much as human access review. Service accounts, tokens, workload identities, and AI-adjacent access paths can accumulate exceptions that are hard to see in quarterly recertification cycles. The control problem is therefore not only who has access, but whether the organisation can continuously justify why access exists at all.


Key questions

Q: How should teams handle users who have access that does not match their peers?

A: Treat peer variance as a governance signal, not just a review note. Compare the user’s access against similar identities, identify the smallest unexplained differences, and route them into validation or removal workflows. The goal is to reduce unnecessary access continuously, not simply certify it at the next review cycle.

Q: Why is unused access still a security problem if no one is using it?

A: Unused access still expands the attack surface, creates audit noise, and preserves privilege that should have expired. A dormant entitlement can be hijacked later, especially when it is tied to shared accounts, exceptions, or stale approvals. Security teams should treat inactivity as a signal to reassess whether the access is still justified.

Q: What do teams get wrong about quarterly access reviews?

A: The most common mistake is treating every quarter as identical. Q1, Q2, Q3, and Q4 each surface different identity risks, so identical questionnaires and reviewer assignments produce blind spots. Teams also overestimate the value of a completed review when remediation is delayed for weeks afterward.

Q: How do organisations reduce excess access without slowing down operations?

A: Use exception-based workflows. Let comparison tooling surface the outliers, then trigger owner notification, access review, expiration, or removal only where the delta is unexplained. That keeps routine access intact while forcing remediation on the small subset of permissions that actually create risk.


How it works in practice

Why side-by-side access comparison changes governance work

Side-by-side comparison changes the unit of review from a single entitlement list to a relational question: what differs between two identities that should otherwise be peers? That matters because overprivilege is often hidden in the delta, not the baseline. Groups, inherited roles, and application-specific permissions can create access profiles that look ordinary in isolation but anomalous in comparison. The mechanism is simple but powerful: compare entitlements across systems, highlight exceptions, and let the reviewer focus on the smallest set of meaningful differences rather than reconstructing the entire permission chain.

Practical implication: use peer comparison to shorten review time and make outlier access visible before recertification starts.

Standing, unused, and irregular access are different governance signals

Standing access is privilege that persists without a time boundary. Unused access is privilege that remains assigned but is not exercised, which still expands attack surface and audit burden. Irregular access is access that does not match the role or peer group pattern the organisation expects, making it a strong signal for investigation even when the account is legitimate. These are not interchangeable categories. A mature programme should treat them as different remediation queues because each implies a different failure mode: retention, over-allocation, or exception drift.

Practical implication: route standing, unused, and irregular access into separate remediation workflows instead of treating all excess access the same.

Continuous access optimisation is stronger than quarterly certification alone

Quarterly access reviews are retrospective controls. They can validate existing assignments, but they rarely surface why access became excessive in the first place. Continuous access optimisation adds a live detection and correction layer between review cycles. That does not eliminate access certification, but it changes the governance cadence from episodic to operational. In practice, the strongest programmes use continuous comparison to detect drift, then use reviews only for the cases that require policy judgment, ownership confirmation, or risk acceptance.

Practical implication: pair continuous comparison with UARs so reviewers spend time on exceptions, not on reconstructing normal access.


NHI Mgmt Group analysis

Continuous access comparison is a control for access drift, not just a convenience feature. The reason it matters is that identity teams often know an account is excessive before they can explain why it is excessive. A comparison-first model reduces the distance between detection and remediation, which is where many governance programmes lose momentum. Practitioners should treat this as a shift from static review evidence to live entitlement reasoning.

Outlier access is the governance smell that exposes weak entitlement boundaries. When two users in the same function have materially different access, the question is rarely theoretical. It usually reflects role entropy, exception accumulation, or stale approvals that never got revisited. That is why continuous comparison belongs alongside IGA and PAM workflows, not after them. Teams need a repeatable way to challenge access variance before it becomes accepted practice.

Named concept: identity variance analysis. Comparing two identities side by side turns access governance into a measurable difference problem rather than a documentation problem. That is valuable across human IAM and NHI programmes because the same access drift pattern appears in employees, service accounts, and automated workflows. The practitioner takeaway is to govern exceptions as variance, not as isolated tickets.

Continuous remediation is now part of access governance, not a downstream cleanup task. The article shows a model where notification, UAR triggering, expiration, and permission removal are coupled to discovery. That coupling matters because access review without correction simply records the problem. Organisations should align detection, approval, and enforcement so excess access is reduced while it is still visible.

This approach reinforces continuous least privilege as an operating model. Least privilege is not a quarterly state report. It is an ongoing reduction of unnecessary access as identities change, roles shift, and permissions accumulate. The discipline now extends beyond certification to active entitlement comparison, which is the only way to keep pace with access sprawl across modern identity estates.

From our research:

What this signals

Identity variance analysis: access governance is moving toward continuous comparison, where teams judge privilege by difference rather than by static assignment. That change matters because quarterly recertification cannot keep pace with the rate at which permissions accumulate across people, service accounts, and automated workflows. The practical signal is that review programmes need live delta detection, not just approval records.

AI and machine access patterns are already putting pressure on entitlement boundaries, with 70% of organisations granting AI systems more access than they would give a human employee performing the exact same job, per The 2026 Infrastructure Identity Survey. That should push identity teams to treat overprivilege as a comparative problem across every actor type, not a one-off access anomaly.

The next stage for mature programmes is to connect comparison, review, and remediation into one operating loop. When access drift is detected, the organisation should be able to validate, expire, or remove it without waiting for the next certification window. That is the difference between governance that observes risk and governance that actually reduces it.


For practitioners

  • Build peer-based access review paths Compare users in the same role, function, or application group before recertification begins so reviewers can focus on meaningful deltas instead of full entitlement inventories.
  • Separate standing, unused, and irregular access queues Route each access pattern into its own remediation path so expiration, owner validation, and permission removal are handled according to the specific failure mode.
  • Connect detection to enforcement Trigger UARs, expiration dates, and permission removal directly from comparison findings so remediation happens while the access variance is still current.
  • Extend comparison to non-human identities Apply the same entitlement-delta logic to service accounts, workload identities, and AI-related access paths where peer baselines are often missing but governance risk is the same.

Key takeaways

  • Continuous access comparison turns entitlement variance into a measurable governance problem rather than a manual investigation exercise.
  • Standing, unused, and irregular access are distinct risk signals and should flow into different remediation actions.
  • Least privilege becomes operational only when comparison findings drive reviews, expiration, and removal in the same workflow.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Access comparison supports least-privilege entitlement management.
NIST SP 800-53 Rev 5AC-6AC-6 aligns with limiting unnecessary privileges revealed by comparison.
NIST Zero Trust (SP 800-207)Continuous verification supports zero-trust access decisions.
OWASP Non-Human Identity Top 10NHI-03NHI-03 covers overprivileged non-human access and entitlement sprawl.

Extend comparison workflows to service accounts and workload identities that carry standing privilege.


Key terms

  • Access Comparison: A governance method that compares two identities side by side to reveal differences in roles, groups, and application permissions. It is useful when teams need to explain why one account has more access than a peer and whether that difference is justified.
  • Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.
  • Permission Drift: Permission drift is the gradual expansion of access beyond what was originally intended. It happens when roles, tokens, and service accounts accumulate unused rights over time, making cloud identities harder to review and more dangerous to compromise.
  • Continuous Least Privilege: A governance model that re-evaluates access as identity risk changes, rather than only at issuance or periodic review. In cloud environments, this means entitlements can be constrained or revoked when findings, posture, or behaviour indicate the access no longer fits the current state.

What's in the full announcement

Opal Security's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step workflow for comparing any two users across groups, roles, and application permissions
  • Operational examples of when to notify application owners, trigger UARs, or convert access to time-bound grants
  • Product-specific guidance on how Risk Center and Access Comparison are used together in the interface
  • Documentation-level detail on deployment and day-to-day use for teams already running the platform

👉 Opal Security's full post covers the comparison workflow, remediation actions, and product usage details.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org