By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: SentraPublished January 19, 2026

TL;DR: DSPM improves visibility into where sensitive cloud data lives, but Sentra argues that discovery alone does not govern who can access it, what they can do, or how access should change across multi-cloud and SaaS environments, especially as 82% of organisations rank compliance as their top cloud concern. The governance gap is now about enforcing least privilege, just-in-time access, and auditability across users, services, APIs, and AI agents rather than relying on static snapshots.


At a glance

What this is: This article argues that cloud data security now needs Data Access Governance, not just DSPM, because visibility alone cannot control access or prove compliance.

Why it matters: For IAM, PAM, and data security teams, the shift matters because access governance now has to span human users, service identities, APIs, and AI agents across dynamic cloud estates.

By the numbers:

👉 Read Sentra's analysis of moving from DSPM to data access governance


Context

Cloud data security has moved beyond finding sensitive information and into governing access to it. Data security posture management can locate and classify data, but it cannot by itself answer who can use the data, whether permissions are still appropriate, or how access should be constrained in real time across multi-cloud and SaaS estates. That gap matters because data now moves faster than review cycles, and governance has to keep pace with both human and non-human identities.

In practice, the control problem is no longer discovery versus neglect. It is whether security teams can enforce least privilege, audit access continuously, and make access decisions that survive hybrid cloud complexity, service accounts, APIs, and AI-assisted workflows. That is a genuine identity governance issue, not just a cloud reporting issue, and most organisations are still adapting to it.


Key questions

Q: How should security teams govern access to cloud data beyond DSPM discovery?

A: They should pair discovery with continuous entitlement management, real-time audit logging, and time-bound access decisions. DSPM tells you where sensitive data is, but governance must answer who can reach it, whether that access is still justified, and how quickly it can be removed when risk changes. Without that second layer, visibility does not reduce exposure.

Q: Why does access control become harder in multi-cloud environments?

A: Multi-cloud environments split identity, protocol, and audit responsibility across different control planes. A tool that works well for one cloud-native path may not govern hybrid access, third-party access, or in-session activity consistently. The result is not just complexity but uneven visibility into who entered, what they touched, and how revocation is enforced.

Q: What breaks when data access reviews stay periodic in cloud environments?

A: Periodic reviews miss the fact that cloud permissions change faster than scheduled governance cycles. Temporary projects end, workloads shift, AI tools connect, and access often remains in place. The result is stale privilege, weak audit evidence, and a false sense of control. Continuous review is more defensible than snapshot-based governance.

Q: How can organisations prove compliance for both human and non-human access to data?

A: They need access evidence that is continuous, policy-linked, and identity-specific. That means logging which identity accessed which data, under what policy, and whether the permission was time-bound or standing. For regulated environments, this is the difference between asserting governance and actually demonstrating it during audit or investigation.


Technical breakdown

Why DSPM visibility does not equal access control

DSPM tools are designed to discover, classify, and monitor sensitive data. That helps teams understand where data exists, but it does not control the identity layer around the data. In cloud environments, access can be granted through users, service principals, APIs, temporary tokens, and delegated roles, each with its own lifecycle. A static inventory cannot enforce policy when permissions change continuously or when the same dataset is reachable through multiple clouds and SaaS applications. The technical boundary is clear: discovery tells you what exists, while governance determines who can reach it and under what conditions.

Practical implication: teams need access enforcement and lifecycle control, not just data inventory reporting.

Data Access Governance and just-in-time permissions

Data Access Governance extends beyond detection by continuously evaluating who can access data, how access is granted, and whether the privilege should exist right now. This is where just-in-time access and zero standing privilege become important design patterns. Instead of leaving broad data access in place, organisations can narrow exposure to task-scoped permissions and revoke them once the need ends. For identity teams, the challenge is to align data access policy with IAM and PAM controls so that access rights are not only approved but also time-bound, logged, and revocable across the cloud stack.

Practical implication: use time-bound access and revocation paths for both human and non-human identities.

Why AI agents and service identities change the data governance model

The article correctly highlights that data access governance must now account for AI agents as well as people. That matters because AI systems often access data through embedded service identities, orchestration tokens, or delegated application permissions rather than through conventional user accounts. Those access paths can be hard to distinguish from legitimate automation unless they are explicitly governed. As organisations adopt generative AI and agentic workflows, the access question shifts from 'who signed in' to 'which runtime identity is acting, what data can it touch, and how quickly can that privilege be changed?'.

Practical implication: inventory AI and workload identities as first-class data access subjects, not exceptions.


NHI Mgmt Group analysis

Discovery-first cloud security is now an incomplete control model. Visibility into sensitive data is necessary, but it does not establish whether the right identity can access that data at the right time. In cloud estates, permissions are the real control surface, because data risk often emerges from stale access, excessive delegation, or ungoverned service identities. Practitioners should treat DSPM as a prerequisite and Data Access Governance as the control layer that actually changes exposure.

Data Access Governance is the identity bridge between cloud security and compliance. This is not just a data issue or a reporting issue. It is an IAM and PAM issue because access to data is mediated by identities, privileges, and runtime permissions that must be reviewed, constrained, and revoked. The organisations that can prove access state in real time will be better positioned for auditability, especially where GDPR obligations and cloud access evidence intersect.

Zero standing privilege is becoming a data security requirement, not just an infrastructure preference. Cloud data stores and SaaS applications do not stay static long enough for periodic access reviews to be sufficient on their own. A named concept here is access governance drift: the gap between approved permissions and the access that actually exists at runtime. Once that drift becomes normal, compliance evidence and least-privilege design both weaken. Practitioners should assume that access drift is the default failure mode.

AI access to data must be governed as a first-class identity problem. The article's strongest signal is that AI risk is now part of cloud data governance, not a separate concern. AI agents and automation tools often operate through service identities that can expand data exposure quietly if they are not included in access policy and monitoring. The practical conclusion is that data governance programmes must extend identity controls to machine actors, or they will miss the fastest-growing access paths.

Unified governance is replacing tool silos as the operating model. Organisations do not need more isolated discovery, review, and response tools if those tools cannot share an authoritative view of access. A unified approach matters because it shortens the time between finding data, understanding who can use it, and changing that access when risk shifts. Practitioners should optimise for control continuity across discovery, enforcement, and audit evidence.

What this signals

Access governance is becoming the practical control layer between cloud security and identity security. Teams that already run IAM, PAM, and data security programmes should expect more demand for evidence that links permissions to actual data use. The governance model needs to move from periodic attestation toward continuous access state, especially where service identities and AI workflows can touch sensitive datasets.

Access governance drift is the condition where approved permissions and real runtime access diverge faster than review processes can correct them. That drift will increasingly determine whether cloud data programmes can satisfy auditors, support incident investigations, and control AI-era exposure. Practitioners should align this with the NIST Cybersecurity Framework 2.0 and the access-control guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls.

The next programme-level question is not whether the team can find sensitive data, but whether it can prove that access is current, minimal, and reversible across every cloud and SaaS path. That requires joining DSPM, IAM, and non-human identity governance into one operating picture, with particular attention to the NHI Lifecycle Management Guide where machine identities are part of the access chain.


For practitioners

  • Map access paths, not just data locations. Build an inventory of who and what can reach sensitive cloud data, including users, service accounts, APIs, and AI-enabled workflows. Tie that inventory to access logs and entitlement sources so the team can answer access-state questions during audit or incident response.
  • Enforce just-in-time data access. Replace broad standing permissions with task-scoped access that expires automatically and is approved through IAM or PAM workflows. Prioritise datasets with external sharing, regulated content, or high automation volume.
  • Extend governance to non-human identities. Treat workloads, orchestration tokens, and AI agents as governed data subjects by reviewing their permissions, logging their activity, and revoking access when workflows change. This is essential where service identities can reach sensitive SaaS or multi-cloud stores.
  • Use real-time audit evidence for compliance. Replace manual evidence gathering with continuous audit logs that show who accessed which dataset, when, and under what policy state. This reduces reliance on point-in-time screenshots and helps validate GDPR and internal control requirements.

Key takeaways

  • Discovery-only cloud security leaves the real control problem unsolved because it does not govern who can use sensitive data.
  • Cloud data access governance must cover human users, service identities, APIs, and AI agents if organisations want defensible compliance evidence.
  • The operational shift is from periodic visibility to continuous, revocable access control across multi-cloud and SaaS environments.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Cloud data access governance depends on managing permissions continuously.
NIST SP 800-53 Rev 5AC-6Least privilege is central to governing who can reach cloud data.
ISO/IEC 27001:2022A.5.15Access control policy is directly implicated by continuous cloud data governance.

Use A.5.15 to formalise access rules for cloud data, including review and revocation responsibilities.


Key terms

  • Data Access Governance: Data access governance is the practice of deciding who or what should reach specific data based on sensitivity, business purpose, and observed access paths. It combines classification, entitlement analysis, and review workflows so access decisions reflect exposure, not just permission status.
  • Access review drift: Access review drift is the gradual loss of consistency between policy and execution during certification cycles. It appears when reviewers lack current context, systems classify identities differently, or evidence is assembled manually, causing the same control to produce different outcomes across the environment.
  • JIT — Just-in-Time Access: A security approach that grants access permissions only for the duration needed to complete a specific task, then automatically revokes them. JIT access eliminates standing privileges for NHIs, dramatically reducing attack surface.
  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.

What's in the full article

Sentra's full article covers the operational detail this post intentionally leaves for the source:

  • A closer look at how Sentra positions DSPM, DAG, and DDR together across AWS, Azure, GCP, and SaaS.
  • The platform workflow for policy-as-code enforcement of least-privilege access and real-time detection.
  • The specific access-management and compliance functions the vendor says are combined in a single workflow.
  • The business-facing arguments around audit readiness, remediation speed, and reduced tooling overhead.

👉 Sentra's full article covers the platform view of continuous access control, auditability, and cloud data protection

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management in practical terms. It helps identity and security practitioners connect access control, lifecycle discipline, and governance across modern cloud environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org