TL;DR: User access review programs are often completed on time but fail in practice because repetition, missing context, and overloaded reviewers turn certification into a mechanical exercise, according to SecurEnds. The result is a governance model that preserves audit evidence while steadily weakening real decision quality.
At a glance
What this is: This is an analysis of review fatigue in user access reviews, showing how repetition, thin context, and broad campaigns turn certification into a compliance task rather than a risk decision.
Why it matters: IAM and IGA teams need to treat review quality as a governance control, because completed certifications that do not change access still leave privilege creep, audit exposure, and decision fatigue in place.
Context
User access reviews are intended to validate whether access still makes sense, but that control breaks down when campaign volume rises faster than the human ability to judge it. In this article, review fatigue is the governance gap: the review process still happens, but the decision quality degrades as lists grow, context shrinks, and the same entitlements reappear cycle after cycle.
For IAM and IGA programmes, the problem is not simply manual effort. It is a mismatch between review design and operating reality, where SaaS sprawl, cloud permissions, and role churn create more access than reviewers can meaningfully assess. Once approvals become repetitive, certification stops functioning as a risk signal and becomes evidence production.
Key questions
Q: What breaks when access reviews become repetitive and low-context?
A: The control stops producing judgment. Reviewers begin approving long lists to clear tasks, not to validate whether access still makes sense. That creates audit evidence without real risk reduction, and privilege creep continues because the programme is measuring completion instead of decision quality.
Q: Why do high approval rates not prove that access reviews are working?
A: Because near-universal approval often signals fatigue, not flawless access hygiene. If reviewers lack usage data, context, or enough time to challenge entitlements, approvals become a default response. The programme may look healthy in reports while failing to remove unnecessary access.
Q: How can organisations tell that certification overload is hurting governance?
A: Look for long-running campaigns, repeated approvals of unchanged access, low remediation rates, and constant IT clarification requests. Those signals show that reviewers are overwhelmed and that the review process is no longer separating routine access from risky access.
Q: Should access reviews be tied to lifecycle events instead of fixed cycles?
A: Yes, when the goal is meaningful governance rather than simple compliance. Reviews tied to onboarding, role change, or exit preserve context and reduce repetition. Fixed cycles still have a place for oversight, but they should not be the only trigger for certification.
Technical breakdown
Why repeated access reviews stop producing risk decisions
User access reviews depend on human judgment, but judgment degrades when the same entitlements are presented over and over without new context. Reviewers need to see what changed, how access is used, and whether the risk has shifted since the last cycle. When the list is long and the signal is thin, people default to approval because that is the fastest way to clear the queue. The technical failure is not the review workflow itself. It is the loss of decision context, which turns certification into a repetitive clerical action rather than an access control checkpoint.
Practical implication: scope reviews to the entitlements that changed or carry elevated risk, and attach usage and ownership context to each decision.
How certification overload hides privilege creep
Certification overload occurs when a review campaign treats every entitlement as if it deserves the same attention. That design buries high-risk access inside long, flat lists of routine permissions, so reviewers spend time on low-value items and miss the changes that matter. Privilege creep then accumulates because unchanged access is repeatedly re-certified instead of being challenged. The result is a control that preserves audit activity but loses control value. This is especially common in environments where access reviews are run on a fixed cadence rather than triggered by change in role, system, or entitlement behavior.
Practical implication: separate routine access from privileged or sensitive access so reviewers spend attention where the risk actually changes.
Why manual review workflows collapse at scale
Manual workflows rely on email, spreadsheets, reminders, and follow-up questions to make certification happen. That can work in small environments, but it fails when SaaS tools multiply and access changes constantly. The mechanics create latency, stale evidence, and reviewer dependence on IT for simple clarifications. Once reviewers need translation just to understand the entitlement, the review has already lost momentum. The process still closes, but it closes late, with weak evidence and little meaningful remediation. The underlying technical issue is not only volume. It is the absence of structured scoping, usage signals, and lifecycle linkage.
Practical implication: replace manual routing with lifecycle-linked review triggers and structured evidence so the reviewer is deciding, not deciphering.
Breaches seen in the wild
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Review fatigue is a control-quality problem, not a people problem. The article makes clear that managers are not failing because they are careless; they are failing because the control asks humans to repeatedly certify access without enough signal to distinguish risk from noise. In identity governance terms, the review no longer changes the state of access, so completion becomes a paperwork outcome rather than a security one. The practitioner conclusion is that review design must be judged by decision quality, not by closure rate.
Certification overload is the name for what happens when every entitlement is treated as review-worthy. Large campaigns flatten the difference between dormant read-only access and sensitive privilege, which is exactly how high-risk items get hidden inside routine work. That creates a false sense of control because the programme produces activity, reports, and audit artefacts while leaving privilege creep untouched. The practitioner conclusion is to redesign scope so that review effort follows risk, not inventory size.
Access reviews lose governance value when they are detached from lifecycle events. The article shows that reviews become more meaningful when they occur closer to onboarding, role change, or exit, because the reviewer still has the context to judge necessity. Fixed cycles convert a governance control into a calendar exercise, which is why the same access keeps getting certified without scrutiny. The practitioner conclusion is to tie certification to identity change, not just to the quarter.
Human judgment needs machine context to stay reliable. Reviewers cannot sustainably evaluate access they do not use, do not assign, and cannot observe in action. Usage data, entitlement history, and role context are not embellishments; they are what keeps the control from collapsing into auto-approval. The practitioner conclusion is that IAM governance should measure whether reviewers had enough evidence to make a real decision.
Review fatigue is the visible symptom of a broader IAM and IGA design failure. The article shows a programme trying to solve scale by adding more review work, which only increases overload. That pattern tells us the control model is still built around human attention as the primary security resource. The practitioner conclusion is to move from volume-based certification to exception-based governance that preserves reviewer attention for genuinely material access.
From our research library:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
What this signals
Access review fatigue is a signal that the governance model is overfitting to calendar cadence. When the same entitlements reappear in every campaign, human attention becomes the scarce control resource and the review stops distinguishing routine access from material risk. The better design is to let lifecycle changes and entitlement context decide when a human decision is actually needed.
Certification has to shift from volume management to exception management. Broad campaigns train reviewers to approve quickly because they cannot reasonably scrutinise every item. Programmes that preserve reviewer attention for privileged, unusual, or changed access are more likely to produce real governance outcomes than programmes that simply increase the number of reviews.
Review fatigue exposes a larger identity governance issue: the control is asking people to compensate for missing context. IAM and IGA teams should assume reviewers need usage history, ownership, and recent change signals to make a credible decision. Without that evidence, even a completed review can become a weak control.
For practitioners
- Prioritise review scope by risk and change Split routine entitlements from privileged or sensitive access, then route the highest-risk items to reviewers who can act on them with context.
- Attach usage evidence to each certification Present last-use, change history, and owner context beside every access decision so reviewers are not forced to approve blind.
- Tie reviews to lifecycle events Trigger certification when roles change, users move, or access is granted rather than waiting for a broad calendar campaign.
- Reduce repetitive low-risk approvals Auto-certify unchanged, low-impact access where policy allows, and reserve human review for exceptions that alter risk.
Key takeaways
- Review fatigue turns user access reviews into a completion exercise, so the programme records approvals without reliably challenging risk.
- The article shows that overload, repetition, and thin context are what weaken governance, not a lack of effort from managers.
- Access reviews work better when they are scoped by change and risk, with usage evidence and lifecycle triggers reducing the amount of noise reviewers must process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about controlling and recertifying access entitlements. |
| Recommendation — Scope access reviews to material entitlements and verify that approvals reduce excess access. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Review fatigue lets unnecessary access persist and weakens least-privilege enforcement. |
| Recommendation — Use AC-6 to challenge standing access that review fatigue keeps re-certifying. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article centres on account review, approval, and remediation at scale. |
| Recommendation — Apply CIS-5 to formalise account review ownership and remove stale or excessive access. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | Privileged rights are part of the review fatigue problem because they get buried in broad campaigns. |
| Recommendation — Review privileged access separately under A.8.2 so high-risk entitlements are not diluted by routine approvals. | ||
Key terms
- Approval Fatigue: The point at which repeated approval requests cause users to stop evaluating each one carefully. In agent governance, this is a control failure mode because the human reviewer becomes desensitised, making the oversight layer ineffective even though the workflow still appears compliant.
- Certification Fatigue: The point at which access reviewers are asked to approve so many permissions that they stop evaluating them carefully. It usually appears when the entitlement list is long, the context is thin, and the reviewer lacks clear signals about which access rights are unusual. That turns governance into routine approval.
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
Deepen your knowledge
NHI governance, IAM, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org