TL;DR: Identity incidents often begin with legitimate access, and Zluri argues that the real gap is full-lifecycle control across authentication, authorization, provisioning, reviews, and offboarding, with Microsoft reporting 600 million identity attacks per day and more than 99% password-based. The governance assumption that access stays stable long enough for manual review is breaking under real operating conditions.
At a glance
What this is: This evaluation guide frames identity security as a full-lifecycle control problem, arguing that the real failure mode is fragmented governance across sign-in, access changes, reviews, and offboarding.
Why it matters: It matters because IAM teams now have to govern identities that change faster than review cycles, and the operational gap between access approval and access removal is where incidents begin.
Context
Identity security is not only about proving who signed in. The governance gap emerges when access is granted, expanded, reviewed, and removed through disconnected workflows, so the programme loses track of why an identity has access and whether that access still belongs.
In practical terms, the article treats identity security as a lifecycle problem across humans and non-human accounts. That framing is relevant for IAM and IGA teams because the failure mode is usually not broken authentication alone, but access that remains active after role change or offboarding.
Key questions
Q: What breaks when identity governance is spread across too many vendor tools?
A: Lifecycle operations become inconsistent, audit trails become incomplete and deprovisioning becomes slower. That increases the chance that access remains active after it should have been removed, which is especially dangerous for high-value accounts, service identities and users with broad delegated access.
Q: Why do role changes create more risk than new joiner events?
A: Role changes are riskier because they often add new access without removing the old set. That is how permission accumulation starts. A clean joiner event is easier to control, but movers expose whether lifecycle logic can both grant and revoke in the same workflow. If cleanup is manual, the old access usually survives.
Q: Why do access reviews often fail to reduce real risk?
A: Access reviews often fail when they produce evidence without changing the underlying entitlement state. If the review process does not trigger revocation, privilege reduction, or exception handling, it documents risk rather than reducing it. That is why lifecycle enforcement matters more than a completed certification.
Q: Should organisations prioritise access governance before expanding automation?
A: Yes, because automation increases the speed at which access can be created, inherited, and forgotten. If governance is weak first, automation simply scales unmanaged privilege. Organisations should define ownership, review cadence, and revocation rules before allowing more automated provisioning.
Technical breakdown
Why full-lifecycle identity control matters
Identity security breaks when authentication, authorization, lifecycle management, and governance are treated as separate layers. Authentication answers whether an identity can sign in, but it does not decide whether access should exist, whether it is still needed, or whether it has been removed from every connected app. The article’s point is that mature programmes need a shared data model across those layers, otherwise access decisions and revocations drift apart. In SaaS-heavy environments, that drift becomes the real attack surface because manual handoffs create stale entitlements, orphaned accounts, and incomplete offboarding.
Practical implication: map your identity stack as one lifecycle chain, not as isolated tools with separate owners.
How access creep starts after role changes and offboarding
Permission creep usually begins with a legitimate change. A contractor moves teams, gets new access, and the old entitlements remain. Later, offboarding removes some accounts but leaves others active because the process depends on checklists and human availability. The article highlights bidirectional mover logic as the difference between simple provisioning and real lifecycle control: new access should be added and old access removed in the same event. Without that, access accumulates quietly until a dormant account or token becomes the easiest path in.
Practical implication: align joiner-mover-leaver workflows so every role change triggers both grant and cleanup actions.
Why continuous posture monitoring changes governance timing
Scheduled access reviews are useful, but they are inherently point-in-time controls. Identity Security Posture Management shifts that model toward continuous detection of over-privilege, orphaned access, and policy drift. That matters because many risky states only exist between review cycles, which means the governance programme can be formally compliant while still being operationally stale. The article’s broader message is that review evidence alone does not equal control effectiveness if remediation happens too late to prevent misuse.
Practical implication: pair periodic certification with continuous detection so drift is caught before the next review cycle.
Threat narrative
Attacker objective: The objective is to preserve usable access long after the business relationship or role change should have removed it.
- Entry begins with legitimate access granted through an informal request path, such as a Slack message without ticketing or workflow control.
- Privilege expands when a role change adds new access but the previous permissions are left in place, creating permission accumulation.
- Impact appears later when a still-active account or token continues authenticating after offboarding and is used from an unusual location.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity security now lives or dies on lifecycle coherence, not on isolated control strength. Authentication, authorization, provisioning, reviews, and offboarding are only effective when they share the same state model. When each layer is owned separately, the programme can look mature while still leaving access active beyond its intended lifespan. The practitioner conclusion is simple: governance has to follow the identity through its full lifecycle, not just at sign-in.
Full lifecycle control is the named gap this article exposes. The article’s central concept is not simply identity governance, but the gap between granted access and retired access. That gap grows in SaaS-heavy environments because every manual step creates a new place for ownership to fail. The implication for teams is that the real control boundary is continuity of state across request, change, review, and removal.
Manual lifecycle processes are a structural weak point, not an execution detail. The article shows how a checklist can leave accounts and API tokens alive after a leaver event, which means the governance assumption that offboarding is a single completed action is false. This is exactly the kind of failure that creates durable access residue. Practitioners should treat incomplete deprovisioning as a governance defect, not just an operational miss.
Continuous review only matters when it is tied to action. Access reviews that identify orphaned or privileged accounts are useful only if they feed remediation in the same control plane. If revocation still depends on tickets or separate follow-up, the programme has not reduced risk, it has merely documented it. The analyst conclusion is that governance value comes from closure, not visibility alone.
The identity security market is converging around lifecycle orchestration, not point solutions. The article reflects a broader shift away from stacks of specialists that do one stage of identity well but do not coordinate with the others. For practitioners, that means evaluating whether the current architecture can govern a contractor, a role changer, and a leaver through one auditable lifecycle. If not, the stack is fragmenting accountability by design.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: NHI Lifecycle Management Guide
What this signals
Full lifecycle control is becoming the practical test for identity security maturity. Teams should assume that point-in-time reviews will miss some risk unless provisioning, mover logic, certification, and deprovisioning are all connected to the same state model. The operational question is no longer whether an organisation has identity controls, but whether those controls preserve continuity from request to removal.
Manual offboarding is where identity programmes most often leak accountability. When leavers are processed through HR alone and downstream apps are handled inconsistently, the identity state becomes fragmented. That fragmentation is what allows dormant accounts and tokens to remain usable after the organisation thinks access has ended. The programme lesson is to treat deprovisioning as a closure control, not an administrative step.
For practitioners
- Rebuild the joiner-mover-leaver workflow Tie provisioning, entitlements, and deprovisioning to the same lifecycle event so role changes remove old access as well as add new access.
- Unify access requests and approvals Replace ad hoc requests in chat or email with a governed request path that records approval context before access is granted.
- Close offboarding residue Verify that leaver processes remove all app accounts and tokens, including non-human credentials that can still authenticate after HR offboarding.
- Move from periodic to continuous drift detection Use posture monitoring to flag orphaned access, privilege accumulation, and policy violations between review cycles, then trigger remediation in the same workflow.
Key takeaways
- Identity incidents often start with legitimate access and worsen when lifecycle controls are fragmented across separate tools and teams.
- The article’s core governance problem is access that remains active after role changes or offboarding, creating stale entitlements and orphaned credentials.
- Programmes that want lower identity risk need connected request, review, and removal workflows, not only better sign-in controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article centers on leavers retaining access after HR offboarding. |
| NHI-05 — Overprivileged NHI | Mover events and stale access create persistent over-privilege across SaaS apps. | |
| NHI-07 — Long-Lived Secrets | The article notes API tokens that continue authenticating after the human owner exits. | |
| Recommendation — Audit offboarding paths so every app account and token is revoked when the identity leaves. Review mover logic for stale entitlements and remove access that no longer matches role need. Rotate or revoke long-lived tokens that remain valid beyond the identity's business need. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about controlling and continuously validating who can access what. |
| DE.CM-01 — Monitoring for Unusual Activity | The article uses unusual-location sign-in and drift detection as governance signals. | |
| Recommendation — Align entitlements with current business need and continuously validate authorizations. Monitor identity activity for drift and unusual access that indicates stale control states. | ||
Key terms
- Full-lifecycle identity control: The practice of governing an identity from request through active use to offboarding and revocation. It ensures that access, entitlements, and audit evidence stay aligned as people or non-human identities change role, context, or employment status.
- Mover logic: The workflow logic that handles role changes by granting new access and removing outdated access in the same event. In mature identity programmes, mover logic prevents permission accumulation and reduces the gap between business change and access correction.
- Orphaned Access: Orphaned access is credentialed access that still works even though no clear business owner can justify or manage it. It usually appears after system changes, reorganisations, or integrations, and it is especially dangerous because it can remain active long after the original purpose has disappeared.
- Identity Posture Management: Identity posture management is the continuous discovery, assessment, and monitoring of identity risk across an environment. In NHI contexts, it focuses on exposure, privilege, ownership, and drift, so teams can find risky access before it becomes an incident or an audit gap.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org