TL;DR: Identity governance breaks down when organisations rely on periodic reviews while access changes continuously across cloud and hybrid environments, leaving misused or stale privileges in place long enough to become breach paths, according to SecurEnds. Quarterly certification alone is no longer sufficient when governance must prove ongoing oversight, not just scheduled approval.
At a glance
What this is: This is an explanation of why identity governance frameworks need continuous oversight, because periodic access reviews do not keep up with changing permissions, cloud sprawl, and lingering access.
Why it matters: IAM and IGA teams need to treat access review as an ongoing control, because delayed revocation and review fatigue let privilege creep survive long enough to create audit and breach exposure.
Context
Identity governance fails when access decisions are treated as one-time events instead of living records. In cloud and hybrid environments, accounts move, roles change, and access lingers after the business need has disappeared, which turns governance into a lagging control rather than an active safeguard.
The article separates IAM from governance in the right way: IAM grants and manages access, while governance checks whether that access should still exist. That distinction matters because the control problem is not account creation, but the failure to continuously validate entitlement, ownership, and removal.
For NHI, human IAM, and mixed enterprise environments, the same structural issue appears in different forms. Whether the subject is a user, contractor, or workload account, periodic certification cannot keep pace if the underlying access estate keeps changing between review cycles.
Key questions
Q: What breaks when identity governance depends on quarterly cycles?
A: Quarterly cycles break the assumption that access state stays stable long enough to review it later. In practice, permissions drift, secrets leak, and service accounts accumulate unnecessary privilege between review points. By the time the cycle ends, the risk may already have changed shape and become harder to reverse.
Q: Why do identity governance gaps create more breach risk than authentication failures?
A: Authentication only answers whether a subject can sign in. IGA decides whether that access should still exist, whether it has been recertified, and whether it should already have been revoked. When those governance controls lag, attackers inherit standing privilege, stale entitlements, and unmanaged non-human access that can be abused after sign-in.
Q: How can security teams tell whether privileged access reviews are actually working?
A: They are working when every privileged entitlement is inventoried, every decision is traceable, and revoked access is removed from all connected systems without delay. If the organisation can only show approvals but not downstream revocation, the review is administrative recordkeeping rather than governance. Proof of removal is the best maturity signal.
Q: Who should own privileged access governance in an identity programme?
A: Privileged access governance should be jointly owned by IAM, PAM, and the system owners who can define acceptable administrative actions. IAM sets the identity and policy model, PAM enforces the session controls, and system owners validate what tasks are truly necessary. Shared ownership prevents the common failure where elevated access is approved without operational accountability.
Technical breakdown
Why periodic access reviews miss entitlement drift
Identity governance relies on a snapshot model when reviews happen only at fixed intervals. Access can be granted, inherited, expanded, or forgotten long before the next certification cycle closes, especially in environments with cloud services, delegated administration, and frequent role changes. That creates entitlement drift, where the recorded access state and the real access state diverge. Governance then becomes retrospective documentation instead of active control. Continuous oversight matters because the risk is not only excess access, but excess access that persists long enough to be misused before anyone notices.
Practical implication: move review triggers closer to change events, not just calendar dates.
How identity governance differs from IAM mechanics
IAM is concerned with the mechanics of authentication and authorization, such as creating accounts, assigning permissions, and letting users log in. Identity governance adds the control layer that asks whether those permissions remain justified, policy-aligned, and auditable. This is why governance is not redundant with IAM. The two functions solve different problems: one enables access, the other tests legitimacy. Without that second layer, access can remain technically valid even after the business context that justified it has disappeared.
Practical implication: separate provisioning workflows from entitlement approval and revocation governance.
Why automation is necessary but not sufficient
Automation is useful because manual certifications and ticket-based removals cannot scale to hundreds of applications and changing personnel. But automation only helps if the underlying policy model is still accurate. If role design is poor, ownership is unclear, or exceptions are not tracked, the workflow simply accelerates bad governance. The article’s real point is that modern governance needs machine-assisted execution plus human accountability. That combination is what makes access review continuous rather than ceremonial.
Practical implication: automate repeatable review and deprovisioning tasks, but keep policy ownership explicit.
Breaches seen in the wild
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
- Salt Typhoon telecom intrusions 2025: Salt Typhoon breached US telecoms mainly with stolen logins, then harvested SNMP strings and TACACS/RADIUS keys to spread and persist for years.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Quarterly certification is no longer a sufficient governance assumption. The article shows that access changes continuously while review cycles remain periodic, which means governance can only ever describe a past state. That assumption was designed for slower identity estates with stable roles and fewer applications. The implication is that identity governance must be understood as continuous validation of entitlement, not scheduled approval theater.
IAM and IGA solve different failure modes, and conflating them creates blind spots. IAM can create accounts and enforce logins, but it cannot determine whether the entitlement is still justified. Governance exists to challenge that assumption of ongoing legitimacy. Practitioners should treat access legitimacy as a separate control objective, not as a by-product of provisioning.
Privilege creep is a lifecycle failure, not just an access review problem. The article correctly points to joiner-mover-leaver gaps, where permissions survive role changes and offboarding delays. That is not merely an operational backlog; it is evidence that identity lifecycle governance is not being enforced at the point where access changes. The practitioner conclusion is to govern the full entitlement lifecycle, not only the review event.
Continuous oversight is the right named concept for this category shift: governance is moving from periodic attestation to ongoing entitlement validation. That shift matters because cloud and hybrid estates generate access movement faster than human review rhythms can track. The implication is that organisations need governance models that treat access as a live state, not a quarterly artifact.
Audit readiness now depends on provable access removal as much as access approval. The article ties governance to compliance, but the deeper point is that records of who approved access mean little if removal is late or inconsistent. This is where auditable revocation becomes a governance requirement, not a nice-to-have. Practitioners should measure whether removal is as controlled as granting.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
What this signals
Continuous oversight is becoming the practical baseline for identity governance because cloud and hybrid environments change entitlement state faster than quarterly attestations can capture. Organisations that still treat certification as a periodic paperwork exercise will keep discovering that their governance record is accurate only at the moment it was signed.
The named concept here is continuous oversight: access governance that follows entitlement change rather than calendar rhythm. That shift matters across human, NHI, and mixed identity programmes because the question is no longer who approved access once, but whether the access state is still defensible right now.
For practitioners
- Shorten the entitlement review cycle Replace once-a-quarter certification with event-driven reviews for role changes, contractor exits, privilege increases, and application onboarding. The goal is to reduce the time between access change and governance action.
- Separate IAM administration from governance approval Map which teams create access, which teams approve it, and which teams are accountable for later recertification and removal. That separation prevents provisioning workflows from being mistaken for governance control.
- Track privilege creep as a lifecycle signal Monitor whether old entitlements remain after movers, project exits, and leaver events. If access remains intact after the business need has changed, the governance process is failing at lifecycle enforcement.
- Automate revocation evidence Capture who approved removal, when the entitlement was disabled, and which systems confirmed deletion or deprovisioning. That evidence matters for audits and for proving that review is more than documentation.
Key takeaways
- The article’s core warning is that identity governance fails when review cadence is slower than entitlement change.
- Its evidence base is operational rather than theoretical: stale access, privilege creep, and missed offboarding accumulate when governance is only periodic.
- The practical fix is to govern access as a live lifecycle, with explicit ownership for approval, review, and removal.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | This article is about governing who still should have access, not just granting it. |
| GV.RM-01 — Risk Management Strategy | The post frames continuous oversight as an enterprise governance and risk issue. | |
| Recommendation — Apply PR.AA-05 to continuously validate entitlements and remove access that is no longer justified. Align identity governance reviews with risk strategy so review cadence reflects current exposure. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The article repeatedly argues that old permissions and privilege creep must be eliminated. |
| Recommendation — Use AC-6 to trim stale privileges and enforce least privilege across changing roles. | ||
| CIS Controls v8 | CIS-5 — Account Management | The subject is lifecycle control over user and system accounts across joiner-mover-leaver events. |
| Recommendation — Apply CIS-5 to manage account lifecycle, review access, and remove lingering accounts promptly. | ||
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org