By NHI Mgmt Group Editorial TeamBased on Pathlock: “From Certified Access to Certified Transaction: How Pathlock Nexus Changes the Game.” (June 3, 2026)

TL;DR: Traditional access management answers who can act, but ERP and business-critical environments increasingly need proof that each transaction was appropriate, continuous, and compliant, according to Pathlock’s webinar on Nexus. The governance gap is shifting from access certification to transaction-level assurance, especially where AI widens compliance blind spots.


At a glance

What this is: This webinar frames continuous transaction governance as the next control layer for ERP identity, where proving that each action was appropriate matters more than simply certifying access.

Why it matters: It matters because IAM and IGA teams increasingly need controls that follow execution inside business applications, not just at the account or role level, especially where compliance evidence is required.


Context

Traditional identity governance answers whether an account should have access. In ERP and other business-critical applications, that is only part of the control problem because a valid entitlement does not prove that a specific transaction was appropriate or compliant.

Pathlock positions the webinar around continuous transaction governance, meaning governance is applied during execution rather than only at certification time. For IAM and IGA teams, that shifts the question from access approval to evidence of control over each business action.

The event also ties that gap to AI-assisted compliance blind spots, which suggests the problem is not just overprovisioning. It is the absence of a continuous assurance model that can keep up with how transactions are executed and reviewed.


Key questions

Q: What breaks when access certifications are handled manually in complex ERP environments?

A: Manual certification processes tend to miss stale entitlements, overload reviewers, and slow remediation, especially when users span multiple systems and business units. That creates audit fatigue, inconsistent decisions, and delayed revocation of unnecessary access. In practice, manual review also makes it harder to prove control effectiveness because evidence is fragmented and difficult to reproduce.

Q: Why do ERP transactions need continuous assurance instead of periodic review?

A: ERP transactions often occur inside legitimate sessions, so the risky event is the action itself, not just the login. Periodic review is too slow when compliance evidence must reflect what happened at execution time. Continuous assurance makes the transaction, rather than the entitlement, the object of governance.

Q: What signs show that access governance is not enough for business applications?

A: A strong warning sign is when teams can say who had access but cannot explain why a specific transaction was allowed or whether it met policy. Another sign is heavy reliance on retrospective audit evidence after the fact. Those patterns mean governance is operating too far from runtime behaviour.

Q: How should security teams use AI to improve compliance in ERP systems without weakening internal controls?

A: Security and compliance teams should use AI to automate repetitive tasks such as data collection, audit documentation, and regulatory tracking, while keeping control design, approvals, and exception handling under human oversight. The goal is faster response and better consistency, not blind automation. AI should strengthen traceability, reduce manual error, and help teams keep controls aligned with changing requirements.


Background and context

Why access certification stops short in ERP controls

Access certification is designed to answer whether a user, role, or service account should retain access. In ERP environments, that control leaves a gap because many risks arise after authentication, when a legitimate identity performs an inappropriate transaction inside a business process. Continuous transaction governance extends the control boundary into runtime so the organisation can evaluate the action itself, not only the entitlement behind it. That matters most where audit evidence must show not just who had access, but whether the resulting business action was proper and compliant.

Practical implication: shift review design from entitlement recertification alone to transaction evidence that can be inspected after execution.

How continuous compliance changes the control model

Continuous compliance means governance is not a periodic checkpoint. It is a control pattern that evaluates activity as it happens, so the organisation can detect whether an action fits policy, role, and business context before the audit trail becomes the only proof available. In multi-ERP environments, that is harder because policy logic and business semantics vary across applications, so a single static rule set is usually too blunt. The technical requirement is therefore not just monitoring, but policy-aware evaluation of transactions in motion.

Practical implication: build policy logic that can evaluate business transactions in context across ERP systems, not just log them after the fact.

Why AI widens compliance blind spots in business applications

AI can widen compliance blind spots because it increases the speed, scale, and variability of decisions that affect business workflows. In governance terms, that means more actions may be generated or influenced faster than human review or conventional certification cycles can validate. The risk is not only automation, but opacity: if teams cannot explain why a transaction was allowed, blocked, or escalated, they lose assurance as well as control. Continuous transaction governance is meant to restore that missing line of sight.

Practical implication: require explainable transaction decisioning wherever AI influences ERP actions or compliance review paths.


NHI Mgmt Group analysis

Transaction-level assurance is becoming the real control boundary for ERP governance. Access approval tells you who may enter the system, but not whether a particular business action was justified. That distinction matters in ERP because compliance failures often occur inside legitimate sessions, not at login. The implication is that IAM and IGA programmes have to treat execution as a governed event, not just a granted entitlement.

Continuous governance exposes the weakness of periodic review as a control assumption. Access recertification assumes the meaningful question is whether access should remain in place over time. Pathlock’s framing shows that, in transaction-heavy environments, the more important question is whether each act can be continuously justified while it happens. That shifts assurance from calendar-driven review to evidence tied to runtime behaviour.

AI does not replace compliance judgement, but it does change the tempo of governance. When decision support or workflow automation accelerates transaction volume, manual certification windows become too slow to preserve evidence quality. That creates a governance gap where approvals remain technically valid yet practically unverifiable. The field needs assurance models that can keep pace with execution speed, not just entitlement lifecycle.

Continuous transaction governance is a named control concept worth formalising. It describes the gap between access governance and transaction assurance in ERP and similar business-critical systems. Once that gap is named, it becomes easier to assign ownership across IAM, IGA, audit, and application control teams. The practical conclusion is that governance must follow the transaction, not stop at the account.

Multi-ERP environments amplify policy fragmentation. The same user or role may behave differently across applications, so a single access model cannot reliably describe compliance risk. That is why transaction-level evaluation becomes more valuable than uniform access logic alone. Practitioners should assume the operating model, not just the tooling, must change when governance spans multiple ERP platforms.

What this signals

Continuous transaction governance is a useful way to describe the control gap between access approval and business execution. Identity programmes that stay focused on lifecycle reviews will miss the point if they cannot show how a transaction was governed in motion.

ERP and multi-ERP environments will keep pushing governance toward runtime assurance because auditability is now an execution problem as much as an entitlement problem. Practitioners should expect more pressure to align IAM, IGA, and application controls around transaction evidence rather than static access state.


For practitioners

  • Define transaction assurance as a control objective Treat business execution evidence as a governance requirement, not as an audit afterthought. Specify which transactions must be evaluated continuously and what constitutes acceptable proof.
  • Map governance checkpoints to runtime events Identify where access certification currently stops and where transaction evaluation should begin inside ERP workflows. Use that map to close the gap between entitlement review and execution control.
  • Prioritise high-risk ERP transactions Start with actions that have financial, compliance, or segregation-of-duties impact, because those are the transactions where continuous assurance will produce the most defensible control value.
  • Document AI-influenced decision paths Require explanation of how AI-assisted steps affect approvals, exceptions, and transaction outcomes so reviewers can reconstruct why a business action was permitted or blocked.

Key takeaways

  • ERP governance is moving from who has access to whether each transaction was appropriate at the moment it occurred.
  • The article’s core signal is that compliance blind spots now emerge inside legitimate sessions and business workflows, not just at the access layer.
  • Practitioners should treat transaction evidence, runtime review, and explainability as part of the governance model for critical business applications.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on moving beyond access state to governed transaction behaviour.
GV.RM-01 — Risk Management StrategyContinuous transaction governance is a risk strategy issue for business-critical applications.
Recommendation — Align ERP governance to PR.AA-05 by validating whether entitlements still match the actions users perform. Define a risk strategy that treats transaction-level assurance as part of governance scope.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article highlights that granted access alone does not prove appropriate execution.
Recommendation — Apply AC-6 to limit business actions to the minimum transaction scope required.
NIST AI RMFGOVERN — AI Governance and AccountabilityAI is described as widening compliance blind spots that require governance oversight.
Recommendation — Establish governance accountability for AI-influenced compliance decisions in ERP workflows.
ISO/IEC 27001:2022A.5.15 — Access controlThe webinar frames a control gap between access approval and transaction assurance.
Recommendation — Extend access control practice to cover transaction approval evidence in critical applications.

Key terms

  • Transaction Assurance: Transaction assurance is the set of controls that keep legitimate actions moving while stopping abusive or unsafe ones. It relies on adaptive response, behavioural evaluation, and policy thresholds tied to the specific transaction rather than to traffic origin alone.
  • Continuous Compliance: Continuous compliance is the practice of keeping controls and evidence current as the environment changes, rather than proving compliance after a review cycle. For identity and NHI programmes, it means access, logging, and revocation must operate together in real time.
  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 4, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org