TL;DR: Most access review programmes still fail because reviewers approve rows without context and revocations often remain tickets, while AI agents and machine identities now belong in scope, according to Cakewalk’s 2026 field guide. The publisher says the real test is whether decisions execute and evidence assembles automatically, changing access review from audit theatre into lifecycle governance that must cover human and non-human identities alike.
At a glance
What this is: This field guide argues that most user access review tools still produce paperwork instead of real revocation, and that modern programmes must include AI agents and other non-human identities.
Why it matters: IAM, IGA, PAM, and NHI teams need reviews that change access in the system of record, not just certify it on paper, because audit evidence is only useful when it reflects actual entitlement removal.
By the numbers:
- Machine identities outnumber people 82 to 1 in 2026.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
👉 Read Cakewalk's field guide on the top 5 user access review tools in 2026
Context
User access review is the control that checks whether an identity still needs the permissions it holds. In practice, many programmes still rely on spreadsheet certification, which means reviewers approve rows without enough context and IT carries the actual revocation work later, if it happens at all. For IAM teams, that gap turns access review into documentation rather than governance.
The article also reflects a broader shift in identity programmes: reviews are no longer only about human users. Service accounts, OAuth grants, and AI agents now sit inside the same entitlement graph, which means lifecycle governance has to follow the identity subject rather than the tool used to manage it. That is a typical failure pattern, not an edge case.
For teams operating under SOC 2, ISO 27001, or similar audit pressure, the operational question is no longer whether reviews exist. It is whether they execute revocation, include unmanaged access, and produce evidence that matches reality across human and non-human identities.
Key questions
Q: What breaks when access reviews stop at approval and rejection decisions?
A: The control breaks because a review record is not the same as a revoked entitlement. If rejected access remains active in the target system, the organisation has only documented intent, not changed state. That creates audit exposure, leaves excess privilege in place, and makes certification metrics misleading.
Q: Why do access reviews need more context than a spreadsheet row?
A: Because reviewers cannot judge necessity from identity, app, and permission names alone. Usage, ownership, role, and peer data let approvers see whether access still matches the work being done. Without that context, managers approve blindly and auditors inherit weak evidence rather than a real governance decision.
Q: Should non-human identities be included in access reviews?
A: Yes. Non-human identities can hold persistent access, reach sensitive systems, and outlive the business purpose that created them. If they are excluded from review, organizations leave a major blind spot in governance. Service accounts, API keys, tokens, and certificates should be reviewed with the same ownership and risk logic used for human users.
Q: Who is accountable when access is approved for removal but not actually revoked?
A: Accountability should sit with the owner of the closed-loop workflow, because certification is not complete until the change is enforced in the target system. If removal depends on manual tickets or disconnected follow-up, the programme has a governance gap that auditors and attackers can both exploit.
Technical breakdown
Why spreadsheet-based access reviews fail
Spreadsheet review programmes break because they separate decision from enforcement. A manager can approve or revoke a row, but if the entitlement change is handed off to IT as a ticket, the control becomes asynchronous and fragile. That creates a gap between certification and the actual access state, which is exactly where stale access survives. The problem is not the row format itself. It is that the review has no direct binding to provisioning, discovery, or evidence capture, so the outcome can be recorded without being realised.
Practical implication: review tools must connect certification decisions to live entitlement change, not downstream ticket queues.
How context changes reviewer quality
Reviewers rubber-stamp when they lack decision context. Effective access review cards need role, department, last-used activity, peer comparison, and ownership data at the point of decision so the reviewer can judge whether the access still matches actual work. Context also matters for exceptions, because a dormant entitlement, a newly transferred employee, and an overbroad OAuth grant all require different action. Without that data, the campaign measures attendance, not judgement.
Practical implication: feed reviews with usage and ownership context before asking approvers to certify access.
Why non-human identities must be in scope
Access review scope now needs to include service accounts, OAuth grants, API tokens, and AI agents where they are acting on behalf of users or systems. These identities can outlive the person who requested them, inherit delegated privileges, or remain invisible if the tool only looks at the SSO catalog. If they are excluded, the certification only covers part of the effective access path. That is especially dangerous in delegated environments, where the human appears reviewed while the non-human access continues unchanged.
Practical implication: extend discovery and certification to the full entitlement graph, including delegated non-human access.
Threat narrative
Attacker objective: The objective is to preserve usable access after the organisation believes it has been reviewed and removed.
- Entry occurs through unmanaged or forgotten delegated access, such as OAuth grants, API tokens, or service accounts that were never brought into the review scope.
- Escalation happens when the access review certifies the human identity but leaves the non-human entitlement untouched, preserving standing access behind a false approval.
- Impact follows when stale or delegated access remains available after role changes or offboarding, allowing continued application access and audit exposure.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Access review only works when revocation is the outcome, not the follow-up task. The article correctly separates tools that document decisions from tools that change access. That distinction is the difference between a control and a record of intent. Practitioners should treat any certification workflow that hands revocation to a ticket queue as incomplete governance, because the access state can survive the review unchanged.
Context, not volume reduction, is what turns certification into judgement. Reviewers cannot make meaningful decisions from person-app-permission rows alone. When usage, ownership, and role context appear at the point of review, the programme starts measuring necessity instead of compliance theatre. The implication is that identity governance quality depends on the quality of the decision surface, not just the cadence of campaigns.
Non-human identities now belong in the same governance model as human access. Service accounts, OAuth grants, and AI agents all create certification blind spots when access review tools only follow the employee record. The market is moving toward identity graphs that span people and machines, and practitioners should re-evaluate whether their current review scope matches actual access paths.
Audit evidence is a byproduct of execution, not a separate project. When campaigns capture who reviewed what, what changed, and when the change executed, the audit package becomes a natural output rather than a reconstruction exercise. That is the model SOC 2 and ISO 27001 programmes need if they want reviews that are defensible under scrutiny.
From our research:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
- Forward look: Review programmes that ignore revocation latency should also examine the Ultimate Guide to NHIs , Key Challenges and Risks for the broader lifecycle failure pattern.
What this signals
Identity review programmes are moving from certification exercises to live lifecycle controls. The organisations that keep winning audit confidence will be the ones that can show revocation, not just approval, across human and non-human identities. That makes discovery, provisioning, and evidence capture part of one workflow rather than three disconnected teams.
Audit pressure is forcing teams to re-scope access governance around actual entitlement paths. When AI agents and delegated access sit outside the review boundary, the programme remains blind to the identities that matter most. Teams should expect auditors to ask not only who approved access, but also whether the non-human side of the access chain was included.
With NHI governance now tied to broader identity lifecycle risk, the practical next step is to review where offboarding, recertification, and privileged access controls still depend on manual follow-up.
For practitioners
- Bind certification to enforcement Remove the ticket handoff between reviewer decision and entitlement change. If a revoke is approved, the access state should change in the provisioning layer with a timestamped record.
- Expand scope beyond the SSO catalog Use discovery feeds from apps, OAuth grants, service accounts, and AI agents so the campaign reflects the full entitlement graph instead of only what the identity provider already knows.
- Add decision context to every review card Show last-used activity, role, department, ownership, and peer comparison before the approver clicks certify. That reduces rubber-stamping and creates better evidence for auditors.
- Treat non-human access as first-class review scope Include delegated tokens, API keys, service accounts, and agent access in the same campaign as human users so offboarding and recertification cover the identities that actually act.
Key takeaways
- Most access review programmes still fail at the point that matters most, which is revoking access rather than collecting approvals.
- The scope problem has expanded beyond employees, because service accounts, OAuth grants, and AI agents now sit inside the same governance boundary.
- Teams should choose tools that bind review decisions to live entitlement change and produce audit evidence from the workflow itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access review quality maps directly to managing permissions and entitlement scope. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management governs certification, review, and removal of unnecessary access. |
| NIST Zero Trust (SP 800-207) | Zero trust depends on continuous verification and least-privilege access reassessment. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centers on unmanaged non-human access and incomplete review scope. |
Align access review scope to continuously verified identities rather than static permissions.
Key terms
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
- Entitlement Graph: A mapped view of who or what has access to which systems, roles, and privileges. It provides the operational basis for review, certification, and segregation-of-duties analysis. Without it, teams rely on disconnected reports that cannot reliably prove control effectiveness.
What's in the full article
Cakewalk's full field guide covers the operational detail this post intentionally leaves for the source:
- Side-by-side feature comparison of the five tools, including fit, pricing posture, and implementation style.
- Concrete examples of how each platform handles campaign execution, discovery, and revocation workflows.
- Tool-specific commentary on AI agent coverage, Slack workflow support, and audit evidence packaging.
- Evaluation notes on where enterprise IGA depth matters versus where mid-market review automation is sufficient.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org