TL;DR: C1.ai argues that user access reviews were designed for slower, human-centric identity models, but they cannot keep pace with service accounts, bots, and AI agents whose access changes continuously and contextually. Retrospective review cycles now function as a validation layer, not the control plane, because modern risk is action-based rather than entitlement-based.
At a glance
What this is: This blog argues that user access reviews no longer provide meaningful governance in environments where access is ephemeral, contextual, and increasingly executed by non-human identities and AI agents.
Why it matters: IAM, IGA, and PAM teams need to treat access reviews as one signal in a broader control model, because entitlement recertification alone cannot govern fast-changing NHI and agentic access.
👉 Read C1.ai's analysis of why user access reviews are losing relevance in modern identity
Context
User access reviews were built for environments where identities changed slowly, entitlements were relatively stable, and a periodic check could still reflect reality. That assumption breaks when cloud workloads, service accounts, bots, and AI agents can gain, use, and shed access far faster than a review cycle.
The governance problem is not the mechanics of review execution. It is the mismatch between retrospective certification and modern identity behaviour, where the key question has shifted from who has access to what action is allowed right now under current context.
Key questions
Q: What breaks when user access reviews are the main identity control?
A: User access reviews break when access changes faster than the review cadence. They can confirm a historical state, but they cannot prevent ephemeral access, delegated machine actions, or short-lived privilege escalation from being used before the review happens. In modern environments, that makes UARs a validation artifact, not a control mechanism.
Q: Why do periodic access reviews fail to reduce identity risk in real environments?
A: Periodic reviews fail when access changes faster than the review cycle and when the organisation relies on manual evidence collection. By the time managers certify access, the snapshot is already stale. Continuous telemetry and event-driven lifecycle controls are needed to keep decisions aligned with current risk.
Q: What are the signs that a review-centric IAM programme is falling behind?
A: Common signs include frequent exceptions, access that changes between review windows, heavy reliance on manual attestation, and recurring audit evidence that does not match actual runtime behaviour. If the program cannot explain who acted, when, and under what policy, the review process is no longer enough.
Q: Should organisations prioritise continuous governance over quarterly access reviews?
A: For high-risk non-human identities and AI agents, yes. Quarterly reviews still matter for accountability, but they are too slow to catch access misuse that emerges during runtime, especially in cloud and SaaS environments.
Technical breakdown
Why periodic access review no longer matches identity behaviour
Periodic access reviews assume access persists long enough to be observed, assessed, and certified. That worked when users were human, roles changed infrequently, and permissions were mostly standing. In modern environments, access can exist for minutes, be delegated through workloads, and be consumed by automation or agents before a review window opens. The review process still has value as evidence, but it cannot function as the primary control when identity state is volatile and contextual rather than static.
Practical implication: move governance decisions closer to issuance and action time instead of relying on quarterly or monthly recertification alone.
Why action-based governance matters more than entitlement inventory
Entitlement inventory answers who can access something, but it does not answer why access was needed, what action was taken, or whether the activity was appropriate in context. That gap becomes critical when two identities carry the same permission set but produce very different risk because one is time-bound and the other is always on. Modern governance has to track permission scope, duration, approvals, and downstream effect, because the security question is no longer just access possession but permitted action.
Practical implication: evaluate access controls by what they allow an identity to do, not by whether the identity appears on a review spreadsheet.
How continuous enforcement replaces review as the control plane
A continuous model enforces policy when access is requested or an action is attempted, rather than after the fact. That can include just-in-time access, context-aware decisions, event-level logging, and automated expiry of high-risk permissions. Reviews still matter, but they become a validation and exception-tracking mechanism instead of the mechanism that keeps risk from accumulating unchecked. The operational shift is from retrospective confirmation to preventative control.
Practical implication: design access governance so risky states cannot persist, and use reviews to verify policy effectiveness rather than compensate for missing controls.
NHI Mgmt Group analysis
Access review governance was built for stable entitlements, and that assumption no longer holds. The classic model presumes access can be sampled after the fact without losing material context. That premise breaks when service accounts, bots, and AI agents can act, delegate, and change scope inside a single operational window. The implication is that certification cycles no longer define the control boundary for modern identity programmes.
Action-based governance is the more durable control model for modern identity risk. Standing entitlements are only one part of the picture, because the real exposure is what an identity can do under current conditions. This reframes governance around issuance, duration, approvals, and permissible actions rather than static ownership of access. Practitioners should treat reviews as evidence of policy operation, not proof that risk is contained.
Non-human identities turn access reviews from governance into archaeology. When identities outnumber humans and many of them are ephemeral, the question is not whether a person should still have access. It is whether a workload, bot, or agent should have been able to perform that action at all. That is why NHI governance, IGA, and PAM now have to converge on runtime enforcement.
Runtime control plane: This post’s central concept is that entitlement review is no longer the place where identity risk is governed. Continuous enforcement, policy-as-code, and time-bound access records now carry the operational burden that retrospective certification once claimed. Practitioners who keep review as the main control are governing yesterday’s identity model.
Audit defensibility increasingly depends on operational evidence, not spreadsheet recertification. The article’s core point is that auditors need assurance, not a ceremonial review cycle. Policy-as-code, consistent enforcement, and expiry controls provide a stronger record of control than a periodically signed access list. Teams that can show access could not persist unchecked are better positioned than teams that only show it was later reviewed.
From our research library:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
What this signals
Runtime control plane: identity programmes that still treat recertification as the main governance event are optimising for a world of stable entitlements. When access is ephemeral and action-driven, control has to move to issuance time and session time, not the next review cycle.
For NHI-heavy environments, the practical shift is to govern service accounts, bots, and AI agents with time-bound access, contextual policy, and action logging. Access reviews still have a place, but only as corroborating evidence that the real control set is working.
For practitioners
- Replace review-first governance with policy-at-request controls Enforce access decisions at the moment access is requested or action is taken, especially for cloud, SaaS, and NHI workloads where permissions change rapidly.
- Use just-in-time access for high-risk permissions Limit standing privilege wherever possible so elevated access expires automatically after the task, session, or approved window ends.
- Treat access reviews as validation, not control Use recertification to confirm whether policy enforcement is working and to find exceptions, not as the mechanism that prevents risky access from existing.
- Track actions, not only entitlements Log who or what took each action, under what context, and with what downstream effect so governance can follow actual behaviour rather than static permission lists.
- Tie NHI governance to lifecycle and offboarding Make sure service accounts, bots, and AI agents are inventoried, time-bounded, and removed when no longer needed so access cannot outlive its purpose.
Key takeaways
- User access reviews no longer match the pace or shape of modern identity risk, especially where non-human identities and automation can change state faster than a review cycle.
- The article’s central evidence is conceptual rather than numerical: entitlement inventory is not enough when the operational question is what an identity is allowed to do right now.
- Continuous enforcement, just-in-time access, and action-level logging provide stronger governance than retrospective certification alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on standing privilege that outlives its useful window. |
| NHI-01 — Improper Offboarding | The post stresses that non-human access must not outlive the identity's purpose. | |
| Recommendation — Reduce standing privilege for service accounts, bots, and agents and enforce expiry on elevated access. Remove NHI access when the workload, bot, or agent is no longer needed and verify offboarding. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The article argues that entitlement minimisation must happen at action time, not only in reviews. |
| Recommendation — Apply least privilege continuously by constraining actions as access is issued and used. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | CSF 2.0 access control aligns with the article's shift from point-in-time review to live authorisation. |
| Recommendation — Align entitlement governance with runtime authorisation decisions instead of relying on retrospective certification. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The article's risk model covers delegated access paths and fast-moving machine-to-machine use of permissions. |
| Recommendation — Map high-risk delegated access to credential access and lateral movement patterns in detection and review. | ||
Key terms
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Action Governance: Action governance is the practice of controlling what an AI system can do at runtime, not just reviewing what it is capable of in theory. It combines policy enforcement, access scoping, logging and escalation so each action stays within approved boundaries.
- Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
- Control Plane: The control plane is the set of actions that create, configure, or manage a service. For AI workloads, it covers deployment and administration of the model platform, while data-plane permissions govern what the service and its identities can read or process.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- How to shift from entitlement recertification to policy enforcement at request time
- Examples of just-in-time access patterns for cloud, SaaS, and non-human identities
- How to use access reviews as validation evidence for auditors rather than as the primary control
- Operational distinctions between standing access, delegated access, and action-based governance
👉 C1.ai's full post covers the shift from retrospective access review to real-time governance detail.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org