TL;DR: Legacy role repositories often miss fine-grained entitlements, leaving organisations unable to see privilege creep, toxic combinations, or who can do what across systems, according to SafePaaS. That makes role governance a visibility and policy problem, not just an administration task.
At a glance
What this is: This is a policy-based role governance analysis showing that legacy repositories create blind spots by failing to expose fine-grained entitlements and cross-system access relationships.
Why it matters: IAM and IGA teams need this because role governance only works when they can see what users can actually do across systems, not just broad job titles or coarse permissions.
Context
Role governance breaks down when access decisions are made from incomplete entitlement data. In this model, a repository that only shows broad permissions cannot answer who can do what, why they have it, or whether access still matches the job they perform.
The article focuses on identity governance for human users, contractors, and project teams in sprawling enterprise environments. The core problem is not just role assignment, but the loss of visibility into privilege creep, toxic combinations, and change tracking across systems.
Key questions
Q: What breaks when role repositories only show broad permissions?
A: Broad permission views hide the entitlement detail needed to judge actual user capability. That means teams cannot reliably spot privilege creep, toxic combinations, or access that no longer matches the job. The result is a governance process built on assumptions, not evidence, which leaves risky access in place until a problem appears.
Q: Why do policy-based access reviews reduce governance risk?
A: They reduce risk because the decision is based on current conditions, not a stale role assignment. When access is evaluated against identity, context, sensitivity, and recent changes, teams can catch inappropriate access earlier and reduce the time that toxic or unnecessary entitlements remain active.
Q: What do security teams get wrong about AI-driven role mining?
A: They often assume it can produce a correct least-privilege model on its own. In reality, role mining reflects observed access, including inherited excess and historic drift. The output is useful for investigation and cleanup, but it still needs policy validation, exception handling, and business context before it becomes a control.
Q: How should organisations govern access when business conditions change continuously?
A: They should shift from periodic attestation to event-driven policy evaluation. Access should be recalculated when source systems report a relevant change, then reconciled against the target state. That makes certifications a validation layer, not the primary mechanism for discovering stale access that should already have been removed.
Technical breakdown
Why legacy role repositories miss the real access picture
A role repository that stores only names, departments, and broad permissions does not describe effective access. Fine-grained entitlements show the actual actions a user can take in each system, including export, approve, view, and administer functions. Without that detail, access review becomes an exercise in guessing whether a role is safe rather than validating it against business context. The technical failure is not simply poor reporting. It is the absence of entitlement-level inventory across HR, IAM, ERP, cloud apps, and legacy systems.
Practical implication: build a unified entitlement view before relying on role recertification or access reviews.
How policy-based access governance changes role control
Policy-based access governance replaces static role assignment with rule-driven decisions that account for segregation of duties, context, and risk. Instead of treating a role as a fixed bundle, the control evaluates whether a user may hold or exercise a privilege based on business rules and current conditions. That matters because toxic combinations often emerge only when multiple entitlements are considered together. Risk simulation adds another layer by previewing the impact of a proposed change before it is deployed, which reduces the chance of accidental escalation or audit surprises.
Practical implication: evaluate role changes against policy and SoD conflict rules before they are committed.
Why role mining is the control that closes blind spots
Role mining is the process of extracting role and entitlement data from multiple sources and reconciling it into a usable model. In practice, it converts scattered access records into business roles and technical roles that can be governed together. That unified model is what lets teams spot privilege creep, remove unnecessary access, and keep pace with reorganisations or project churn. Without it, least privilege remains a slogan because the organisation cannot reliably see the access surface it is trying to reduce.
Practical implication: mine roles continuously so access governance can keep pace with organisational change.
Breaches seen in the wild
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Policy-based role governance is now the control plane for access visibility, not just an administrative wrapper. When organisations cannot see fine-grained entitlements, role ownership becomes an assumption rather than an operating fact. That is why privilege creep and toxic combinations persist in environments that believe they already have role management. The practical conclusion is that governance quality is limited by entitlement visibility, not by the number of roles in the repository.
Legacy IAM tooling fails when the business asks questions it was never built to answer. Broad permissions and directory labels do not reveal who can export customer data, approve transactions, or combine privileges across systems. That gap creates governance debt because reviews are performed against incomplete evidence. Practitioners should treat incomplete entitlement data as a control failure, not a reporting inconvenience.
Role mining is not a cleanup project, it is the mechanism that makes least privilege governable at scale. A unified role model across HR, ERP, cloud, and legacy systems gives policy engines something real to evaluate. Without that foundation, policy-based access governance cannot reliably distinguish safe assignment from risky accumulation. The implication is straightforward: if the entitlement model is fragmented, the governance model will be fragmented too.
Business-contextual access decisions reduce the distance between security policy and operational reality. Static roles age quickly when staff move, contractors exit, and project access lingers. Policy-based controls tie permissions back to current business need, which is what keeps access from drifting into permanent excess. The practitioner conclusion is that access governance must be treated as a living control surface, not a periodic cleanup task.
From our research library:
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
What this signals
Role blind spots are a governance problem, not just a directory problem. When entitlement data is fragmented, access reviews become backward-looking and incomplete. Teams should expect that any role model without system-wide entitlement visibility will miss privilege creep until a business change or audit exposes it.
Policy-based access control only works when the organisation can simulate the impact of change. The useful shift here is from assigning roles to evaluating whether a proposed assignment creates a SoD conflict, excess privilege, or an ownership gap. That moves access governance closer to decision-time control and further from after-the-fact cleanup.
For practitioners
- Unify entitlement inventory Bring together role and permission data from HR, IAM, ERP, cloud applications, and legacy systems so governance decisions are based on complete access evidence.
- Simulate role changes before deployment Use automated risk simulations to test the effect of new assignments, hierarchy changes, or policy updates before they reach production.
- Map toxic combinations explicitly Define and review segregation-of-duties conflicts across the permissions that matter most, including export, approve, and administer actions.
- Track ownership and change history Assign clear role owners and maintain traceable snapshots so access decisions can be reviewed quickly when business responsibilities shift.
- Rebuild least privilege around business roles Use role mining to reconcile abstract business roles with technical roles, then remove unnecessary access that persists after organisational change.
Key takeaways
- Legacy role repositories fail because they obscure the entitlement detail needed to govern real access decisions.
- Policy-based governance matters because it makes access decisions testable against business rules and segregation-of-duties conflicts.
- Role mining and traceable change control are the practical foundations that keep least privilege aligned with organisational change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on excess access and privilege creep, even though the actors are human users. |
| Recommendation — Use entitlement review and policy checks to remove excessive access before it becomes persistent privilege creep. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing permissions and entitlements across systems. |
| Recommendation — Apply PR.AA-05 to maintain accurate entitlement inventories and enforce access decisions from current policy. | ||
| CIS Controls v8 | CIS-5 — Account Management | Role governance here depends on accurate account ownership, access change tracking, and timely revocation. |
| Recommendation — Use CIS-5 to keep account assignments, ownership, and revocation workflows aligned with business change. | ||
Key terms
- Policy-Based Access: Policy-based access grants or denies access by evaluating rules about context, workload state, and intended action at the moment of request. For AI systems, this is more useful than static roles alone because the same workload may need different privileges across different tasks and environments.
- Role Mining: Role mining is the process of analysing entitlement patterns to infer reusable access roles from existing assignments. In mature IAM programmes, it can reduce manual modelling effort, but it only works well when the source data is clean, policy-aligned, and not already distorted by exceptions or oversharing.
- Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org