By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Clarity SecurityPublished January 29, 2025

TL;DR: Governance fails when IGA tools miss trusts, temporary privilege, and cross-boundary access paths, according to Clarity Security. The Enterprise Access Model helps answer who should hold Tier 0 and Tier 1 access, but it does not reveal all the nested, federated, and unmanaged permissions already in play.


At a glance

What this is: This is an analysis of how the Enterprise Access Model can guide privileged access governance, with the key finding that it still misses nested and federated access hidden outside typical IGA coverage.

Why it matters: It matters because IAM and PAM teams cannot govern Tier 0 and Tier 1 risk effectively if they cannot see the trusts, linked accounts, and temporary access paths that actually grant control.

By the numbers:

  • 30% of all access is nested or federated through trusts and outside the scope of typical controls.

👉 Read Clarity Security's analysis of the Enterprise Access Model and privileged access governance


Context

The Enterprise Access Model is a practical way to think about privileged access, but it only works if the organisation can see every path that leads to Tier 0 and Tier 1 control. In identity governance terms, the problem is not just whether access is formally assigned, but whether nested trusts, federated permissions, and cross-account links have slipped beyond review.

That is why this topic matters to PAM, IAM, and IGA teams at the same time. A governance model can define who should have access, but it cannot by itself discover unmanaged access, confirm scope, or prove whether temporary elevation really ends when the task is complete.


Key questions

Q: What breaks when Tier 0 access is hidden behind nested or federated trusts?

A: Governance breaks because review tools see the parent identity, not the effective control path. That means excessive privilege can persist outside recertification, separation of duties checks, and routine PAM review. The practical result is that Tier 0 access looks compliant in one system while remaining fully exploitable in another.

Q: Why do nested and federated access paths create more risk than direct assignments?

A: They create risk because they can bypass the normal access model that teams think they are governing. A direct assignment is visible, but inherited privilege often sits inside group chains, trusts, and cloud links that do not surface cleanly in standard governance reports. That makes review and revocation slower and less reliable.

Q: How should security teams govern emergency Tier 0 access?

A: Treat it as a privileged workflow with explicit approval, expiry, and post-event validation. Emergency access should be scoped to the incident, isolated from routine administration, and revoked as soon as the task is complete. Without that discipline, temporary elevation becomes standing privilege by another name.

Q: Who should be allowed to use Tier 0 or Tier 1 access in practice?

A: Only identities that have a documented operational need, a defined scope, and an independently reviewable access path should be allowed to use those tiers. That includes dedicated administrators, tightly governed response teams, and rare vendor exceptions. If the path cannot be reviewed, it should not be trusted.


Technical breakdown

Tier 0 and Tier 1 access boundaries in the Enterprise Access Model

The Enterprise Access Model divides critical systems into tiers so organisations can treat control plane access differently from business system access. Tier 0 covers the administrative layer that can reshape identity, infrastructure, and trust. Tier 1 covers systems that run business operations but should not be able to alter the core control plane. The model is useful because it forces separation, but it is only as strong as the underlying identity graph. If a lower-tier account can inherit control through trust, federation, or nested permissions, the tier boundary becomes a policy statement rather than a real boundary.

Practical implication: Map Tier 0 and Tier 1 entitlements against the actual trust graph, not only the directory view.

Nested and federated access that bypasses normal IAM visibility

Nested access means privilege is inherited through another account, group, or trust relationship instead of being assigned directly. Federated access means identity assertions move across systems, clouds, or directories through configured trust. Both patterns are operationally common and governance-light because many IGA tools only see the parent identity, not the effective entitlement created downstream. That creates a blind spot where access appears ordinary in the source system but becomes highly privileged at the destination. The result is hidden over-provisioning, especially in cloud linkages, cross-forest trusts, and legacy authentication paths.

Practical implication: Review effective privilege at the destination system, not only the source identity record.

Temporary elevation and separation of duties in privileged access governance

Just-in-time elevation and separation of duties are meant to stop standing privilege from becoming permanent control. In practice, both controls fail when temporary access is granted too broadly or when review processes treat escalation as an exception instead of a governed lifecycle. The article’s Tier 0 guidance reflects a deeper identity governance truth: privileged access is not safe because it is temporary, it is safe only when scope, duration, and accountability are all explicit. That applies equally to human admins, contractors, and response teams.

Practical implication: Require task-scoped approval, expiry, and post-use review for every privileged access grant.


Threat narrative

Attacker objective: The objective is to reach control plane access that can be used to expand privilege across the environment and weaken identity governance.

  1. Entry occurs through over-trusted nested or federated access that is invisible to standard governance views, giving the attacker a path into higher-value control tiers.
  2. Escalation follows when Tier 0 or Tier 1 privileges inherit across trusts, links, or legacy authentication paths without being independently reviewed.
  3. Impact lands in control plane compromise, where access to identity or infrastructure tiers can be used to reshape permissions, persist, and move laterally.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Tier-based governance only works when the effective identity graph is visible. The Enterprise Access Model is a useful policy frame, but policy is not discovery. If nested trusts, federated permissions, and linked cloud accounts are outside the review surface, then the organisation is governing a diagram rather than actual access. The implication is simple: access tiering must be validated against effective privilege, not only assigned privilege.

Hidden inheritance is the real Tier 0 problem, not just excessive assignment. The article’s 30% nested or federated access figure captures a structural governance gap. Access that arrives through trusts and nested paths often escapes standard IGA reporting, which means the strongest permissions are sometimes the least visible. Practitioners should treat inherited control as a first-class privileged access risk, because it is where entitlement drift hides.

Dedicated Tier 0 accounts reduce risk only when account separation is matched by lifecycle discipline. A separate admin account is not a governance outcome by itself. If those accounts are not reviewed, time-bound, and isolated from lower-tier work, they become durable privilege containers with broad blast radius. The discipline here is not just to create admin accounts, but to keep them from becoming permanent identity shortcuts.

Temporary elevation becomes governance debt when incident access and vendor access are treated as informal exceptions. Incident response teams and third-party vendors may need Tier 0 or Tier 1 access, but that does not make the access low risk. The moment access is granted for convenience, accountability weakens and review delays begin. The practical conclusion is that emergency and external access must be managed as tightly as standing privilege, not as an operational afterthought.

From our research:

What this signals

Tier-based models are becoming necessary, but they are not sufficient. As access patterns spread across directory, cloud, and federated identity boundaries, programme owners need a control view that follows the effective entitlement rather than the nominal owner. The organisations that close this gap will be the ones that can prove who really controls Tier 0, not just who is listed there.

Only 5.7% visibility into service accounts shows why this problem will not be solved by the IDP alone. Identity programmes need to assume that the directory is an input, not the full control plane, and build review processes around trusts, links, and inherited permissions. That shift changes both audit posture and incident readiness.

Dedicated admin accounts, JIT elevation, and federation review need to be managed as one programme. If those controls live in separate teams, the gaps between them become the path an attacker follows. The governance priority is to collapse the seams between IAM, PAM, and IGA before those seams become privilege inheritance routes.


For practitioners

  • Catalogue every trust path into Tier 0 Inventory cross-forest trusts, federated access, nested group membership, cloud account linkages, and legacy authentication dependencies that can produce Tier 0 control. Reconcile the catalogue against the identities and systems your IGA tool can actually see.
  • Review effective privilege at the destination system Do not rely on the source directory or IDP to describe who really has access. Validate what permissions are inherited once the trust or federation is resolved, especially for control plane and admin accounts.
  • Time-box every privileged exception Use just-in-time elevation for Tier 0 and Tier 1 tasks, require a stated business purpose, and force expiry plus post-use review. Apply the same discipline to incident response teams and external vendors.
  • Separate admin work from lower-tier operations Create dedicated Tier 0 administrator accounts that are never used for Tier 1 or Tier 2 activity. Enforce separation of duties so no single identity can both administer and audit the same critical system.

Key takeaways

  • The Enterprise Access Model is useful for thinking about control tiers, but it does not replace effective identity visibility.
  • Nested trusts and federated paths are the governance blind spot that can turn apparently isolated access into Tier 0 control.
  • IAM, PAM, and IGA teams need the same operating picture of inherited privilege, or tiered governance will miss the access that matters most.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Hidden and poorly rotated privileged access sits at the centre of this article's governance gap.
NIST CSF 2.0PR.AC-4The article focuses on access permissions, trust boundaries, and privilege governance.
NIST Zero Trust (SP 800-207)Section 2.1Tiered control and continuous verification align with zero-trust access boundaries.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control principle underlying Tier 0 and Tier 1 governance.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral Movement; TA0004 , Privilege EscalationThe article's access paths map to how adversaries move from credential exposure to broader control.

Use ATT&CK to model how inherited access becomes credential access, escalation, and lateral movement.


Key terms

  • Enterprise Access Management: Enterprise access management is the set of policies and controls used to govern who can access which systems and under what conditions. In healthcare, it has to balance authentication assurance, clinical speed, auditability, and role changes across multiple connected applications and devices.
  • Nested Access: Access that is inherited through another account, group, trust, or linked system rather than assigned directly. This matters because the effective privilege can be much broader than the visible entitlement, especially when directory records do not expose the downstream control path.
  • Federated Access: A delegated access model that lets an AI client act through controlled identity flows instead of embedded long-lived secrets. For agentic systems, federation improves accountability because credentials can be scoped, tracked, and revoked more cleanly.
  • Tier 0 Access: The highest-value administrative access in an environment, usually tied to identity infrastructure, cloud control planes, or other systems that can reshape the estate. Because this access can alter permissions and trust itself, it demands the strictest separation, review, and lifecycle control.

What's in the full article

Clarity Security's full article covers the operational detail this post intentionally leaves for the source:

  • The article walks through Tier 0 and Tier 1 examples across IAM, cloud control planes, and business systems.
  • It expands the recommended review focus to cross-forest trusts, federated permissions, and legacy access paths.
  • It describes how teams can structure recurring access reviews for privileged accounts and vendor exceptions.
  • It explains where most organisations miss hidden access because the IDP does not know everything.

👉 Clarity Security's full article covers tier examples, trust review priorities, and the access paths most teams miss.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org