TL;DR: Enterprise identity governance must now cover human users, non-human service accounts, and autonomous AI agents, because periodic access reviews cannot keep pace with access that changes in real time, according to Oleria Security. The core issue is not just scale, but the collapse of assumptions behind legacy IGA when AI-driven identities widen the governance gap daily.
At a glance
What this is: Oleria Security argues that identity governance must move from periodic certification to continuous access control as AI, non-human, and human identities now change access too quickly for traditional review cycles.
Why it matters: IAM and IGA teams need to treat AI-era access as a live governance problem, because point-in-time review models leave standing privilege and drift unaddressed across human and machine identities.
Context
Identity governance now has to deal with access that changes faster than traditional review cycles can certify. In plain terms, the control model is moving from periodic approval to continuous evaluation, because the enterprise identity set now includes human users, service accounts, and AI-driven actors.
The article frames this as a governance gap rather than a tooling refresh. Legacy IGA assumptions were built for access that is stable long enough to review, certify, and revoke on a schedule; AI-era operating models break that premise by changing access state in real time.
Key questions
A: Security teams should treat AI agents, service accounts, and integrations as first-class identities from the moment they appear. Governance must be continuous, not quarterly, with access scoped tightly, reviewed automatically, and revoked as soon as it is no longer needed. The key control is reducing the gap between identity creation, permissioning, and oversight so machine-speed deployment does not outrun human-speed process.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.
A: Common signs include excessive permissions, stale or orphaned accounts, outdated policies, unaccounted access points, and weak logging coverage. If teams must rely on manual exception handling more often, or if reviews repeatedly uncover settings that no longer match policy, the environment is drifting away from its approved security baseline and needs correction.
Q: What should organisations do when continuous access control and manual recertification conflict?
A: Use manual recertification for oversight, but let continuous controls make the real-time decision on whether access should remain active. If the two disagree, the runtime control should win for high-risk access because it reflects the current state. Recertification should validate policy, not act as the only enforcement point.
Technical breakdown
Why periodic access reviews no longer match AI-era identity changes
Periodic access reviews assume that entitlements remain stable long enough for a reviewer to see them, certify them, and act on them. That model works when identities move slowly, but it becomes brittle when service accounts, copilots, or autonomous workflows can gain and drop access dynamically during normal operation. Continuous access control shifts the decision point from the review cycle to the access event itself, which is the only moment when the current state is visible. The technical issue is not volume alone. It is the mismatch between certification timing and identity behaviour.
Practical implication: move governance controls closer to issuance and use-time evaluation, not just quarterly or monthly recertification.
How human, non-human, and autonomous identities change the governance problem
Human users, service accounts, and AI agents create different access patterns, but they now share the same governance surface. Humans are still reviewed through conventional IAM and IGA processes, while non-human identities introduce secrets, standing privilege, and lifecycle drift. Autonomous or semi-autonomous AI adds a further problem: access can be acquired, used, and discarded within a single runtime session. That collapses the old assumption that one identity, one owner, and one review cadence can govern all access types consistently. The architecture has to understand identity intent, duration, and revocation conditions by actor type.
Practical implication: segment governance rules by actor type instead of forcing one certification workflow across people, workloads, and AI systems.
What continuous governance means for standing privilege and visibility
Continuous governance does not simply automate access reviews. It evaluates whether access should still exist as conditions change, and it can remove standing privilege when that access no longer matches policy or risk. In practice, this requires live visibility into who or what is using access, what resource is being reached, and whether the entitlement still aligns with the approved purpose. Without that runtime context, the organisation only sees snapshots of state, not the drift that happens between snapshots. Legacy IGA tools were designed around the snapshot.
Practical implication: prioritise controls that can detect and remove standing privilege between review cycles, not after them.
NHI Mgmt Group analysis
Access certification is no longer the governing control it was built to be. Periodic access review was designed for stable entitlements that could be observed at rest and then certified on a schedule. That assumption fails when AI-driven identities and machine identities alter access continuously, because the state being reviewed may no longer exist by the time the review happens. The implication is that governance must be measured at the moment of use, not treated as a retrospective audit exercise.
Continuous access control is becoming the practical boundary between governance and drift. Once access can change in real time, the main question is not whether an entitlement existed, but whether it remained appropriate at the instant it was exercised. This shifts IGA from a record-keeping discipline to an operating control. Organisations that keep treating review as the primary safeguard will keep certifying yesterday's access while today’s exposure expands.
AI-era governance exposes a cross-actor control gap, not a single-technology failure. The same programme now has to govern humans, service accounts, and AI agents without collapsing them into one review pattern. That is why identity blast radius becomes a better management concept than access list size: the more actor types share the same weak governance cadence, the more quickly one missed entitlement can propagate across the estate. Practitioners should reframe governance around actor-specific risk rather than one-size-fits-all certification.
Legacy IGA assumed access was reviewable because it was persistent. That assumption held when human and workload access changed slowly enough for governance cycles to catch up. It breaks when AI agents and dynamic service accounts can acquire, use, and retire privileges faster than a reviewer can certify them. The implication is that identity governance must be redesigned around lifecycle events and runtime state, not periodic attestations.
Identity blast radius is the right concept for AI-era access governance. The enterprise problem is no longer just how many identities exist, but how much damage each identity can reach before governance notices. When access is continuously changing, blast radius is controlled by visibility, scope, and revocation timing, not by the number of review meetings held. Practitioners should treat this as an operating model shift across IAM, IGA, and NHI governance.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
What this signals
AI-era governance requires actor-specific policy design. Treating humans, service accounts, and autonomous AI as a single access-review population creates blind spots that become more dangerous as access changes faster. The programme now needs different control timings for different identity types, or it will keep certifying the wrong thing.
Continuous evaluation is becoming the governing control, not a monitoring enhancement. Once access decisions change during runtime, review-based governance only reports on past state. Practitioners should expect IAM and IGA operating models to converge on event-driven controls that can revoke standing privilege before exposure compounds.
For practitioners
- Map governance by actor type Separate human, non-human, and AI identity workflows so review cadence, approval logic, and revocation conditions match how each actor actually uses access.
- Shift review from snapshots to runtime Add continuous checks at issuance and use time so access decisions reflect current context instead of stale certification evidence.
- Target standing privilege first Identify the highest-risk entitlements that persist between reviews and remove or constrain them before expanding broader governance automation.
- Create separate controls for AI-driven identities Define owner, purpose, and expiry conditions for AI-driven access so autonomous behaviour does not inherit human review assumptions.
Key takeaways
- Identity governance breaks down when review cycles cannot keep pace with access that changes continuously across human, non-human, and AI identities.
- The core failure is not simply scale. It is the mismatch between a snapshot-based control model and runtime access behaviour.
- Practitioners need actor-specific governance and continuous enforcement for high-risk access, or certification will keep lagging behind reality.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on standing privilege that outlives review cycles across non-human identities. |
| NHI-01 — Improper Offboarding | Continuous governance must also remove access when AI or service identities no longer need it. | |
| Recommendation — Reduce overprivileged NHI access by shifting enforcement from periodic review to runtime entitlement checks. Tie identity offboarding to current access state so stale privileges are revoked as soon as purpose changes. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about controlling permissions and authorizations as they change. |
| Recommendation — Apply PR.AA-05 to review, constrain, and continuously validate entitlements across all identity types. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The post argues that static least-privilege assumptions fail when access changes in real time. |
| Recommendation — Enforce least privilege dynamically so high-risk access is removed when runtime conditions change. | ||
| MITRE ATT&CK | TA0004; TA0006 — Privilege Escalation; Credential Access | Standing privilege and identity drift are the access conditions attackers exploit for escalation. |
| Recommendation — Track privilege escalation and credential access patterns to find identities that retain more access than they should. | ||
Key terms
- Continuous Access Control: Continuous access control is the practice of evaluating identity permissions and behaviour in real time instead of relying only on periodic certification. It is especially important for autonomous and machine identities because their access patterns can change faster than quarterly governance cycles can detect.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Identity Drift: Identity drift is the gap between the access path originally approved and the behavior that exists later. For browser extensions, drift can appear through updates, remote configuration, publisher changes, or permission expansion, turning a trusted integration into a materially different risk.
- Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 28, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org