By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SaviyntPublished August 20, 2026

TL;DR: Access risk is no longer contained within single applications because workflows, entitlements, NHIs, and AI agents now span interconnected systems, making cross-application risk the real governance problem, according to Saviynt. Traditional app-centric reviews miss combinations of benign privileges that become toxic when identity follows the process across the enterprise, per Saviynt.


At a glance

What this is: This is an analysis of how cross-application access risk emerges when identities, NHIs, and AI agents accumulate permissions across multiple systems and create harmful privilege combinations.

Why it matters: It matters because IAM, IGA, and PAM teams must shift from per-application review to enterprise-wide effective access analysis if they want to catch SoD conflicts and hidden blast radius.

By the numbers:

👉 Read Saviynt's analysis of cross-application risk and continuous identity governance


Context

Cross-application risk is what happens when access decisions made in separate systems combine into an identity that can do more than any one owner expects. In practice, that means the control plane has shifted from the application to the identity, and most governance programmes have not caught up.

The primary gap is visibility. Application teams can usually explain access inside their own systems, but they often cannot see how a human user, service account, or AI agent behaves across the business process that connects those systems. That is why per-application SoD review now misses the real risk boundary.

This is especially relevant where AI agents and NHIs inherit access across SaaS, cloud infrastructure, privileged systems, and ticketing workflows. The resulting permission combinations are often individually defensible yet collectively dangerous, which is a typical modern enterprise pattern rather than an edge case.


Key questions

Q: How should security teams govern policy-based access control across multiple applications?

A: Start by inventorying every policy source, then map ownership, review cadence, and enforcement points into one control process. The goal is to stop authorization logic from drifting across SaaS, APIs, and data platforms. A single policy inventory makes exceptions visible and gives IAM teams a reliable basis for audit and recertification.

Q: Why do non-human identities increase data leakage risk?

A: Non-human identities increase leakage risk because they often have broad machine-to-machine reach, long-lived or reused credentials, and limited human review. Once access is granted, those identities can move data through pipelines, integrations, and AI services faster than traditional governance processes can inspect.

Q: What do security teams get wrong about separation of duties?

A: They often treat SoD as a role design problem instead of an effective permissions problem. A role may look compliant on paper while the underlying application access still allows conflicting actions. Teams need to test actual privilege paths, not just review job titles or role names.

Q: How do organisations know whether cloud access controls are actually working?

A: They know controls are working when discovery, classification, and remediation produce consistent outcomes across sanctioned and unsanctioned apps. If teams can identify risky services but cannot change access, quarantine data, or update policy, the control is reporting on risk rather than reducing it.


Technical breakdown

Why application-scoped SoD misses effective access risk

Segregation of duties is usually evaluated inside a single system, but effective access is created by the combination of privileges across systems. A user who can create records in one application and approve or pay in another may pass every local review while still being able to complete a prohibited business process end to end. That is why application access governance has to model the identity, the permission set, and the business process together. The failure is not missing entitlements in one app. The failure is that the risky action only exists when entitlements are combined.

Practical implication: model SoD at the business-process level, not only inside each application.

How AI agents and NHIs amplify cross-app risk

NHIs and AI agents change the pace and scale of access accumulation. They are often granted broad access for a task, then left with standing permissions across connected tools, APIs, and admin consoles. Because they can operate continuously, the effective permission set can expand much faster than a human governance cadence can review it. A read-only signal in a SIEM, a write path in ticketing, and admin access in endpoint tools can become a full control loop. That is not a single entitlement problem. It is a cross-system privilege composition problem.

Practical implication: treat machine and agent access as an enterprise-wide composition risk, not a per-tool entitlement list.

What unified visibility actually has to correlate

Unified visibility is not just inventory. It has to connect identities to applications, permissions to business functions, and systems to the workflows they support. Without that correlation, an access review can certify each entitlement as reasonable while missing the toxic combination they create together. Effective risk management also needs continuous recalculation, because the same identity may become risky when a new SaaS app, cloud role, or automation path is added. Cross-application governance is therefore a dynamic graph problem, not a static review exercise.

Practical implication: build controls that recalculate effective access continuously as new systems and entitlements are connected.


Threat narrative

Attacker objective: The attacker objective is to turn individually acceptable access into an enterprise-wide control path that bypasses SoD and enables fraud, persistence, or exfiltration.

  1. Entry occurs when an identity is granted legitimate access to multiple applications, cloud services, or AI-driven workflows that are reviewed in isolation rather than as one effective access set.
  2. Escalation happens when benign entitlements combine across systems, allowing the same identity to create, approve, move, or suppress actions that no single application owner can fully see.
  3. Impact follows when the identity uses those combined privileges to fraudulently move money, establish unauthorized access, exfiltrate data, or suppress alerts across the enterprise.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Cross-application risk is the new identity governance boundary. Traditional IGA was designed around a question that is now too small: who has access to this application? Modern enterprise risk emerges from what an identity can do across applications, infrastructure, and automated workflows. That means the real control boundary is no longer the app owner’s domain, and practitioners need enterprise-wide effective access analysis rather than isolated entitlement review.

Cross-app identity correlation is now a governance requirement, not a reporting nicety. If a programme cannot connect human accounts, service accounts, and AI agents to the business processes they participate in, it will certify safe-looking access that is unsafe in combination. The named concept here is effective access drift: the steady growth of an identity’s real power as new entitlements accumulate across systems. Practitioners should treat that drift as a standing risk condition.

AI agents expose the limits of per-application controls faster than humans do. The article’s strongest implication is that machine-speed access changes break governance cadence. An agent that can observe, write, and act across tools can create a full control loop that no single domain owner can see. Cross-application governance must therefore be identity-agnostic and continuous across human, NHI, and agentic access.

SoD that lives only inside one system creates false assurance. Segregation rules still matter, but only when they are evaluated against the combined permissions that matter to the process. The risky combination is often not illegal inside any one platform, which is why the control gap is structural rather than procedural. Practitioners should assume that cross-system combinations will defeat local checks unless they are modeled centrally.

The market is moving toward effective-access governance because the old control model cannot keep pace. This is not simply a feature request for better dashboards. It is a recognition that identity governance must understand relationships between identities, permissions, and business processes across the enterprise. Teams that keep app-scoped reviews as their primary control will keep missing the risk that actually matters.

From our research:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which explains why cross-application effective access is so hard to govern.
  • The next step is to pair lifecycle control with cross-app correlation, using Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs to close the review gap.

What this signals

Effective access is now the programme-level unit of control. Teams that keep measuring access only inside each application will continue to miss the combinations that matter most. The governance shift is from entitlement review to relationship review, which means identity graphs, process context, and continuous recalculation must become part of the operating model.

Cross-application governance will increasingly collapse human and machine controls into one operating view. That does not mean the controls are identical, but it does mean the review plane has to be unified. When AI agents, service accounts, and humans can all participate in the same business workflow, the old separation between app governance and machine governance stops being useful.

With 97% of NHIs carrying excessive privileges, the hidden risk is not just over-provisioning but over-composition across systems. That is why Top 10 NHI Issues remains relevant here: the issue is not one bad entitlement, it is the way many reasonable entitlements combine into a dangerous effective-access profile.


For practitioners

  • Model effective access across systems Build review workflows that evaluate what an identity can do when permissions are combined across ERP, SaaS, cloud, ticketing, and privileged tools. Use business process mapping so reviewers can see the dangerous end state, not just isolated entitlements.
  • Correlate human, NHI, and agent access Create one identity graph that ties users, service accounts, API keys, and AI agents to the applications they touch. This lets you detect accumulated access, duplicated privileges, and hidden SoD conflicts before they become executable paths.
  • Recalculate risk continuously Move from quarterly certification to continuous risk scoring when new applications, roles, or automations are connected. Cross-app access risk changes as soon as a new entitlement lands, so the control must update at machine speed.
  • Expand SoD rules beyond single applications Write SoD policies around business outcomes such as create, approve, pay, and disable, then test those outcomes across systems. The control should fail when separate systems collectively enable a prohibited workflow, even if each app looks compliant alone.
  • Use the Ultimate Guide to NHIs for lifecycle context Anchor access governance decisions in lifecycle processes that cover provisioning, rotation, and offboarding for non-human identities. The governance gap often starts when access is granted once and never re-evaluated across the broader enterprise context.

Key takeaways

  • Cross-application risk is what happens when isolated entitlements combine into a real business capability that no single owner fully sees.
  • AI agents and NHIs make the problem harder because access accumulates faster than point-in-time governance can review it.
  • Continuous effective-access analysis is the practical response, because the control must follow the process across systems rather than stop at the app boundary.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05Cross-app entitlement sprawl and over-privilege are central to this article.
NIST CSF 2.0PR.AC-4The article focuses on access management and least privilege across an enterprise.
NIST Zero Trust (SP 800-207)The post argues for continuous verification across connected systems.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control challenge behind cross-application risk.

Apply continuous verification to identities whose access spans multiple applications and workflows.


Key terms

  • Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
  • Cross-Application Risk: Risk that emerges only when access and workflow data from multiple systems are evaluated together. A user or service account may appear compliant in one application while still creating a toxic combination or fraud path when combined with privileges in another system.
  • Application-Aware Access Governance: Application-Aware Access Governance is identity governance that understands the rules, data, and workflows of a specific business system. It goes beyond generic provisioning by connecting entitlements to process context, transaction behaviour, and cross-system evidence needed for defensible decisions.
  • Identity Graph: An identity graph is a relationship map that connects identities, assets, data, and permissions so teams can see how access actually flows. In NHI programmes, it helps explain which agent is related to which owner, which system, and which policy boundary.

What's in the full article

Saviynt's full blog post covers the operational detail this analysis intentionally leaves for the source:

  • The specific application access governance framing and the vendor's examples of effective access across business workflows
  • The product-level way the source describes cross-application identity correlation and continuous monitoring
  • The operational model for enterprise-wide SoD analysis across human users, NHIs, and AI agents
  • The vendor's explanation of how application access governance differs from traditional IGA in day-to-day use

👉 Saviynt's full post covers the examples, governance model, and cross-app risk patterns in more detail

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org