By NHI Mgmt Group Editorial TeamBased on Zluri: “7 Identity & Access Management Risks” (June 26, 2025)

TL;DR: SaaS sprawl, manual provisioning, delayed deprovisioning, excessive permissions, weak data access controls, inconsistent access reviews, poor policy design, and weak authentication all expand enterprise exposure, according to Zluri’s overview of seven identity and access management risks. The core issue is not a lack of tools but the failure to govern identity lifecycle, access scope, and review discipline together.


At a glance

What this is: This is a Zluri analysis of seven IAM risks in SaaS environments, centred on visibility gaps, manual access handling, over-permissioning, weak review discipline, and authentication weaknesses.

Why it matters: It matters because SaaS identity sprawl turns access governance into a lifecycle problem, so IAM, IGA, and PAM teams need controls that keep provisioning, deprovisioning, reviews, and policy enforcement aligned.


Context

SaaS identity risk grows when organisations lose sight of who has access to which app, what level of permission they hold, and whether that access still matches the role behind it. In that situation, identity and access management stops being a point control and becomes a lifecycle governance problem across onboarding, change, review, and offboarding.

Zluri’s article frames seven recurring failure modes in SaaS environments: visibility gaps, manual provisioning, delayed revocation, excessive permissions, weak data access controls, inconsistent access reviews, poor policy design, and weak authentication. The practical lesson for IAM teams is that these risks compound when identity governance, access scope, and review discipline are managed in separate silos rather than as one operating model.


Key questions

Q: What breaks when SaaS discovery is incomplete?

A: Incomplete discovery leaves shadow apps, duplicate subscriptions, and employee-purchased tools outside the control model. That means invoices cannot be matched cleanly, renewal decisions are based on partial data, and ownership remains ambiguous. In practice, the organisation pays for services it cannot reliably govern or retire.

Q: Why do manual SaaS provisioning workflows create risk?

A: Manual provisioning creates risk because access decisions slow down, vary by operator, and often miss the exact permission scope a role requires. The longer the workflow takes, the more likely users receive excess access at onboarding or retain it after role changes, which increases privilege creep and residual access exposure.

Q: How do teams know whether SaaS access reviews are actually working?

A: Look for reduction in orphaned accounts, faster revocation after role change, and fewer exceptions repeated across successive review cycles. If the same overprivileged access returns every quarter, the review process is documenting risk rather than removing it. Effective reviews change the entitlement baseline, not just the spreadsheet.

Q: When should teams prioritise authentication over access cleanup?

A: Teams should not treat authentication and access cleanup as separate tracks. Strong authentication reduces account-entry risk, but it does not fix overprivilege or delayed revocation. The better priority is to align authentication, provisioning, deprovisioning, and review so each control reinforces the others across the SaaS lifecycle.


Technical breakdown

Why SaaS visibility gaps break identity governance

SaaS sprawl creates a discovery problem before it becomes an enforcement problem. If teams cannot reliably see which users, groups, apps, and permissions exist, they cannot govern access lifecycles or prove who can reach what. That is why manual inventories, spreadsheet-driven reviews, and disconnected app knowledge fail at scale. Visibility is the control plane for everything that follows, from access assignment to certification and revocation. In SaaS environments, identity governance depends on aggregating entitlement data from IdPs, HR systems, app integrations, and usage signals into one decisioning view.

Practical implication: build a single access inventory before attempting policy enforcement or review automation.

How manual provisioning and deprovisioning create exposure windows

Manual lifecycle handling slows down the two moments that matter most: granting only the access required at joiner time and removing access when the user leaves or changes role. In SaaS environments, that delay creates both privilege creep and residual access risk. The issue is not just efficiency. It is that human-operated workflows often miss edge cases, apply inconsistent permissions, and leave accounts active after business need ends. Automation matters here because the lifecycle state of the identity must track the lifecycle state of the worker, contractor, or internal move.

Practical implication: automate onboarding and offboarding workflows so access follows role changes and departure events without delay.

Why overprivilege and weak access reviews persist in SaaS

Overprivilege happens when teams grant more access than the job requires, often to reduce friction or avoid repeated approvals. In SaaS, that convenience becomes durable risk because permissions accumulate across apps, groups, and shared datasets. Irregular access reviews then make the problem harder to correct, since reviewers often lack fresh context on actual usage and business need. Effective review processes need entitlement data, activity context, and clear ownership. Without those inputs, certifications become a checkbox exercise that leaves excessive permissions untouched.

Practical implication: use contextual access reviews tied to actual app usage and business role, not static entitlement lists.


Threat narrative

Attacker objective: The objective is to obtain and retain unintended SaaS access that can be used to reach data, actions, or administrative paths beyond legitimate business need.

  1. Entry begins when SaaS access is granted too broadly or without proper identity verification, giving the wrong subject a usable path into app data.
  2. Credential or permission exposure then persists because manual provisioning, delayed deprovisioning, or weak authentication leaves standing access in place longer than intended.
  3. Escalation occurs when overprivileged accounts, weak policy design, or poor review discipline let the actor reach data and functions beyond the original business need.
  4. Impact follows as sensitive SaaS data, admin functions, or external sharing paths become accessible without effective governance or timely revocation.
  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
  • CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity governance in SaaS breaks first at the visibility layer. If teams cannot see the full entitlement picture across apps, they are forced to govern by exception instead of by design. That makes access review, least privilege, and offboarding all less reliable because the control inputs are incomplete. The practitioner conclusion is simple: no access governance programme is stronger than its inventory.

Manual lifecycle handling turns routine identity work into an exposure window. Joiner, mover, and leaver activity is the point where SaaS permissions either stay aligned or drift out of bounds. When provisioning and deprovisioning depend on tickets and human follow-through, residual access becomes normal rather than exceptional. The implication is that lifecycle discipline, not isolated tooling, determines whether SaaS identity risk is containable.

Excessive permissions in SaaS are a policy failure, not just an authorization mistake. Teams often grant extra access to reduce operational friction, then rely on reviews to clean up later. That approach assumes reviewers can still reconstruct intent after the fact, which is rarely true at scale. The practitioner conclusion is that policy design must prevent privilege accumulation before review ever enters the picture.

Weak SaaS authentication should be treated as an identity binding problem. If an account can be entered without strong assurance of who is behind it, every downstream entitlement becomes harder to trust. MFA, SSO, and robust authentication only matter when they are part of a broader governance model that also controls app scope and access lifecycle. The practical takeaway is that authentication strength and entitlement control have to be governed together.

SaaS IAM risk now behaves like a composite governance gap. Visibility, provisioning, deprovisioning, access review, policy design, and authentication all fail together when they are managed separately. That is why the security question is no longer whether a tool exists, but whether the operating model keeps identity state, permission state, and business state synchronised. Practitioners should treat SaaS IAM as continuous governance, not periodic cleanup.

What this signals

Identity governance for SaaS now has to operate as a continuous control loop. Static reviews and periodic cleanups cannot keep pace with app sprawl, role change, and shadow access patterns. Teams need lifecycle-triggered provisioning, revocation, and certification if they want the permissions state to reflect the business state.

Composite access risk is the real SaaS problem. The article’s seven risks are not separate failures so much as linked symptoms of the same governance gap: incomplete visibility, slow lifecycle handling, and weak policy enforcement. That means practitioners should assess their SaaS programme end to end, not app by app.

Authentication only matters when it is tied to entitlement governance. MFA and SSO reduce account compromise risk, but they do not correct overpermissioning or stale access on their own. For IAM leaders, the stronger question is whether identity assurance, provisioning, and review are being governed as one control system.


For practitioners

  • Build a complete SaaS entitlement inventory Aggregate app, IdP, HR, directory, and usage data into one view of who has access to what, at what level, and through which app connection.
  • Automate joiner, mover, and leaver workflows Trigger provisioning and deprovisioning from authoritative identity and HR events so access changes follow role changes and departures without manual lag.
  • Tighten privilege grants to job need Replace broad default access with role-specific permissions and require explicit justification for exceptions that exceed the baseline job function.
  • Run contextual access reviews Combine entitlement data with recent activity and business ownership so reviewers can certify only access that still matches real use.
  • Harden SaaS authentication and policy enforcement Require strong authentication for SaaS apps, restrict API access, and align policy design with approved roles, devices, and network conditions.

Key takeaways

  • SaaS IAM risk is driven by governance drift across visibility, lifecycle management, and access review rather than by a single missing tool.
  • Manual provisioning, delayed revocation, and excessive permissions combine to create durable exposure windows in SaaS environments.
  • The practical response is to unify entitlement inventory, lifecycle automation, contextual reviews, and authentication policy into one operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingDelayed revocation and departing-user access are central risks in the article.
NHI-05 — Overprivileged NHIThe article repeatedly warns about excessive permissions in SaaS accounts.
Recommendation — Review offboarding workflows against NHI-01 and revoke SaaS access when the identity exits or changes role. Map excessive SaaS permissions to NHI-05 and remove standing access that exceeds job need.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article's core governance issue is overprovisioning and access scope control.
Recommendation — Apply AC-6 to constrain SaaS entitlements to the minimum permissions required for each role.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on entitlement visibility, review, and authorization control.
Recommendation — Use PR.AA-05 to keep SaaS entitlements current and aligned to business role.
CIS Controls v8CIS-5 — Account ManagementThe article centres on account provisioning, deprovisioning, and access review.
Recommendation — Use CIS-5 to standardise account lifecycle handling across SaaS applications.

Key terms

  • SaaS Visibility: SaaS visibility is the ability to identify which software services, tenants, and accounts exist in an environment and who controls them. In identity governance, it is the prerequisite for review, offboarding, and cost control because hidden applications cannot be certified or revoked reliably.
  • Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
  • Contextual Access Evaluation: Contextual access evaluation is the practice of assessing whether access is appropriate by using surrounding information such as user role, patient condition, location, and care relationship. It is designed to distinguish legitimate clinical work from suspicious or unnecessary access, especially where simple rule sets are too blunt.
  • Lifecycle-Driven Deprovisioning: The practice of removing SaaS access automatically when identity events such as departure or role change occur. It matters because delayed revocation leaves accounts active after business need ends, which expands residual access risk and complicates auditability.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org