By NHI Mgmt Group Editorial TeamBased on Zluri: “How Zluri Automates Identity Lifecycle Management to Reduce IT Friction” (June 26, 2025)

TL;DR: Manual onboarding, role changes, and offboarding create delays and errors that weaken identity lifecycle control, according to Zluri’s analysis. The core lesson is that lifecycle automation matters only when provisioning, approval, and deprovisioning are tied to centralized visibility and revocation discipline.


At a glance

What this is: This is a lifecycle management analysis showing that manual identity workflows fail when access changes must be tracked, approved and revoked at scale.

Why it matters: It matters because IAM, IGA and PAM teams cannot treat onboarding and offboarding as clerical work when delayed revocation and missing visibility directly expand access risk across human and non-human identity programmes.


Context

Identity lifecycle management is the set of processes that creates, changes and retires access as people move through joiner, mover and leaver stages. The article argues that manual handling, especially spreadsheet-based tracking and ticket-driven approvals, does not scale because it delays access decisions and increases the chance of missed revocation.

For IAM and IGA teams, the governance gap is not just speed. It is the absence of a centralized view that can prove who has access, when it changed and whether offboarding actually removed every active entitlement. That same discipline is increasingly relevant whenever lifecycle controls must be applied to service accounts, tokens or other NHI patterns as well.


Key questions

Q: What breaks when machine identity lifecycle management is still partly manual?

A: Manual lifecycle management breaks first at scale. Expiry handling becomes inconsistent, revocation is slow, and ownership is unclear when credentials are embedded across many applications and environments. In practice, that means outages, unrevoked access and weak auditability when trust assumptions change.

Q: Why does delayed deprovisioning create security risk even when SSO is in place?

A: SSO only governs authentication. If deprovisioning is delayed, the application can still hold active accounts or memberships after the user should have lost access. That extends the window for inappropriate use, makes offboarding harder to prove, and turns identity drift into a recurring control failure rather than an exception.

Q: How do IAM teams know whether lifecycle automation is actually working?

A: Look for fewer manual exceptions, faster role changes, and verified access removal after offboarding. More importantly, check whether downstream systems stay in sync with the authoritative source and whether review findings show declining entitlement drift. If those signals do not improve, the automation is only moving tickets faster.

Q: How should organisations balance self-service access with control?

A: Organisations should use self-service only for low-risk, pre-approved access paths where role and department already define acceptable entitlements. Sensitive or unusual access should remain exception-based and reviewable. The balance is not between speed and security. It is between routine requests that can be standardised and outlier requests that still need human judgment.


Technical breakdown

Why manual lifecycle management breaks at scale

Manual identity lifecycle management depends on people stitching together spreadsheets, tickets and disconnected admin actions. That works only while the number of joiners, movers and leavers stays small. As the article notes, onboarding slows down, approvals queue up and IT teams lose the ability to track access consistently. The real technical issue is not just effort. It is that access state becomes distributed across too many records to trust as a single source of truth.

Practical implication: replace fragmented tracking with a governed lifecycle workflow before access state becomes impossible to reconcile.

How centralized visibility changes provisioning and deprovisioning

A centralized lifecycle view gives IT teams one place to see granted access, pending changes and still-active entitlements. That matters because provisioning and revocation are two sides of the same control. If a team can create access quickly but cannot verify what remains active at offboarding, the system creates residual risk. The article also points to workflow-driven provisioning and deprovisioning as a way to standardize decisions instead of relying on ad hoc human recall.

Practical implication: tie provisioning and offboarding to the same lifecycle record so access changes are visible from start to finish.

Why approved app catalogs and role-based workflows reduce friction

The article’s self-service app model shows a useful pattern: pre-approved access pathways reduce ticket volume without removing governance. In practice, that means the workflow decides which apps are available by role, department or position, while exceptions still route through review. This is not the same as giving users free rein. It is a controlled access model that reduces waiting time while preserving authorization boundaries.

Practical implication: define pre-approved access paths for common requests and reserve manual review for exceptions.


Threat narrative

Attacker objective: The objective is to retain or abuse access that should have been removed, then use that lingering entitlement to reach sensitive systems or data.

  1. Entry occurs through routine identity change events such as onboarding, role change or offboarding, where manual handling leaves too much room for delay and omission.
  2. Credential or entitlement exposure happens when access records are incomplete, so active permissions remain in place after the user should have been deprovisioned.
  3. Escalation follows when missed revocation leaves ex-employees or stale accounts with ongoing access to apps, channels or sensitive data.
  4. Impact is unauthorized access, operational delay and the potential for breach, monetary loss or reputational damage.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity lifecycle governance fails when access state is managed as a task list instead of a controlled record: the article shows that spreadsheets, tickets and manual follow-up cannot reliably preserve who has access after onboarding, movement or exit. That is not a productivity issue alone. It is a governance failure because revocation and authorization drift become invisible once records are fragmented. The practitioner conclusion is that lifecycle control must be treated as an authoritative access state problem, not an HR admin process.

Centralized visibility is the control boundary, not a convenience layer: without a single view of entitlements, offboarding cannot prove that every app, channel and account has been removed. This is the practical reason manual methods keep creating zombie access and delayed removals. The implication for IAM and IGA teams is that lifecycle assurance depends on a record of current state, not on whether a ticket was eventually closed.

Pre-approved workflows reduce friction only when they preserve authorization discipline: the article’s self-service model is useful because it removes delay while keeping app access bounded by role and business need. That said, the governance value comes from the approval structure, not the automation itself. The practitioner lesson is to separate low-risk routine access from exceptions that still require human review.

Standing access after departure: this article is a clear example of a failure mode where access outlives the identity event that justified it. Once a leaver still has active permissions, the control problem is no longer onboarding speed. It is incomplete identity retirement, and that pattern matters across human identities and any other governed access object with a lifecycle.

Lifecycle automation becomes more valuable as identity sprawl grows: the article’s core signal is that manual methods collapse under scale because access changes happen faster than humans can validate them one by one. The broader market implication is that identity programmes need lifecycle orchestration that can reconcile grant, change and revoke decisions across systems. Practitioners should measure whether lifecycle automation actually reduces residual access, not just ticket volume.

What this signals

Lifecycle governance is only as strong as the offboarding record behind it: when access changes are managed manually, the control question is not whether the request was approved. It is whether the entitlement was actually removed everywhere it existed. That is why lifecycle programmes need a single state view across directories, apps and collaboration tools.

Standing access after employment changes is the failure mode this article exposes: once a mover or leaver keeps permissions that no longer match the business relationship, the issue has moved from convenience to exposure. IAM and IGA teams should treat residual access as a measurable governance defect, not an inevitable by-product of growth.


For practitioners

  • Standardise lifecycle workflows Define joiner, mover and leaver workflows that use the same approval and revocation logic across core applications, directories and collaboration tools.
  • Eliminate spreadsheet-led tracking Move access state into a centralized lifecycle record so IT can see current entitlements, pending removals and account status without reconciling multiple files.
  • Build offboarding checks around active entitlements Require deprovisioning workflows to confirm every application, channel and group membership is removed before closing the leaver case.
  • Separate routine access from exceptions Pre-approve low-risk application requests by role or department, but keep exception paths for privileged or sensitive access under manual review.

Key takeaways

  • Manual lifecycle processes create delay and error because access state is split across tickets, spreadsheets and individual admin actions.
  • The main control failure is incomplete offboarding, where active entitlements survive after the identity event that should have closed them.
  • Lifecycle automation is only effective when it produces a current record of access and proves that revocation actually happened.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centers on missing revocation when employees leave.
NHI-05 — Overprivileged NHIManual provisioning and mover changes can leave excess access in place.
NHI-07 — Long-Lived SecretsThe same lifecycle weakness applies when credentials or tokens survive longer than intended.
Recommendation — Map offboarding gaps to NHI-01 and verify that every account, app and group is removed on exit. Review lifecycle workflows for entitlements that remain broader than current role needs. Track credential age and revoke stale secrets when identity events change the trust basis.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing access permissions through the lifecycle.
Recommendation — Align lifecycle workflows to PR.AA-05 so permissions are granted, changed and removed consistently.
CIS Controls v8CIS-5 — Account ManagementAccount provisioning and deprovisioning are the core controls discussed.
Recommendation — Implement account lifecycle procedures that remove access promptly when employment status changes.

Key terms

  • Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
  • Deprovisioning: Deprovisioning is the removal of access when a user changes roles or leaves an organisation. For security teams, it is the point where stale accounts, tokens, and permissions should disappear. Weak deprovisioning leaves residual access that can outlive the business need that created it.
  • Centralized Visibility: Centralized visibility is the ability to see security findings, assets, and control status through one coherent view. It gives practitioners a consistent picture across multiple tools and environments, which supports better triage, prioritization, and policy enforcement. Without it, teams are more likely to miss relationships between issues and lose control of risk.
  • Employee App Store: An employee app store is a governed self-service channel for requesting approved applications and access. Its value comes from policy enforcement, traceability, and approval logic, not from convenience alone, because it can reduce shadow IT only when requests are tied to current role and risk.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org