By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SaviyntPublished September 2, 2026

TL;DR: Periodic access reviews were built for human-centric, single-application identity models, but Saviynt argues they miss cross-application risk, standing privilege, dormant access, NHIs, and AI agents because modern entitlements now change continuously across SaaS, cloud, and hybrid environments. The core issue is not review cadence but fragmented visibility that leaves systemic exposure unmeasured between certification cycles.


At a glance

What this is: This is a governance analysis of why periodic access reviews no longer capture modern identity risk, especially when NHIs, AI agents, and cross-application entitlements change faster than review cycles.

Why it matters: It matters because IAM, IGA, and PAM teams need to govern human, non-human, and autonomous access in one control model, not as isolated application-level snapshots.

By the numbers:

👉 Read Saviynt's analysis of why access reviews miss application risk


Context

Periodic access reviews were built for a world where identity risk was mostly human, changes were slow, and business logic sat inside a single application. That model breaks once access spans SaaS, cloud, and hybrid environments, where entitlements combine across systems and the business impact of access is no longer visible in one entitlement list.

The primary identity governance gap is context, not effort. Reviews can confirm that someone or something has access, but they often cannot explain what that access enables, how it combines with other permissions, or whether the identity is human, non-human, or autonomous.

For NHI and AI agent governance, the problem is more acute because access can appear, expand, and disappear between certification cycles. That makes periodic review a lagging control unless it is fed by continuous visibility and cross-application correlation.


Key questions

Q: What breaks when reviews only cover one application at a time?

A: Cross-application risk stays hidden. A permission that looks acceptable in one system can become dangerous when combined with access elsewhere in the process. That is especially true for ERP, SaaS, cloud, and infrastructure workflows, where the harmful condition is created by the combination, not any single entitlement.

Q: Why do periodic access reviews miss the real NHI risk?

A: Periodic reviews miss the real risk because they measure entitlement state at a point in time, while NHI exposure can change between cycles. A service account, token, or OAuth app may remain valid long after its purpose has shifted. Continuous visibility and action matter more than retrospective certification.

Q: How can organisations tell whether access review is actually reducing risk?

A: Organisations should look beyond campaign completion and measure downstream removal, reopened exceptions, and the number of high-risk roles still present after review. If rejected access does not disappear from the target system, or if repeated cycles keep certifying the same excess entitlements, the programme is not reducing risk effectively.

Q: Should teams keep using access reviews for human users while treating NHIs differently?

A: Yes, but only if the governance model separates identity types. Human reviews still fit slower JML patterns, while NHIs and AI agents need continuous, event-driven oversight tied to ownership, usage, and lifecycle changes. One cadence cannot govern all three actor types effectively.


Technical breakdown

Why per-application access reviews miss cross-app risk

Traditional certifications assume risk is contained within one application or entitlement catalogue. In modern environments, identities accumulate permissions across business apps, SaaS, cloud infrastructure, and workflow platforms, so the harmful pattern is often the combination rather than any single grant. A role may look harmless in isolation while creating SoD conflict, data exposure, or excessive privilege when correlated elsewhere. That is why per-application review produces false confidence: it sees records, not relationships. Continuous correlation is the technical shift required to expose how access actually behaves across the estate.

Practical implication: correlate entitlements across systems before recertification so reviewers see composite risk, not isolated permission lists.

Why standing privilege and dormant access survive periodic review

Periodic review tends to preserve what looks familiar, which is why standing elevated access often remains unchallenged. Without usage telemetry, a reviewer sees that access exists but cannot tell whether it is actively needed, stale, or merely inherited from an old operating model. This is especially problematic for service accounts and API keys, where “always on” access is common and ownership is frequently unclear. Dormant access becomes invisible risk because the review process checks presence, not operational necessity or last-use context.

Practical implication: pair entitlement review with usage data and ownership evidence so persistent access is tested against actual need.

Why NHIs and AI agents change the governance model

NHIs and AI agents do not wait for a quarterly review cycle. They are provisioned, used, modified, and retired on operational timelines that can be hours or days, which means risk can emerge and decay between certification events. That creates a governance mismatch: the review process is periodic, but the identity behaviour is continuous. The right technical model is event-aware and contextual, with controls that can evaluate identity type, privilege accumulation, and business criticality as states change. Without that, the review only documents exposure after the fact.

Practical implication: move NHI and AI agent oversight into continuous governance workflows with event-driven review triggers.


Threat narrative

Attacker objective: The objective is to exploit fragmented governance so over-privilege, dormant access, and cross-application combinations remain available for abuse.

  1. Entry begins when identities are granted access across multiple applications and cloud services without a unified view of ownership or business context.
  2. Escalation occurs as individually acceptable entitlements combine into toxic privilege sets, standing access, or SoD conflicts that no single review cycle can see.
  3. Impact is the persistence of hidden exposure, repeated audit findings, and unresolved business risk despite apparently completed certifications.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Periodic access review is now a lagging indicator, not a control boundary. The review model was built for stable, human-paced identity change inside single applications, but modern identity risk is distributed and continuous. Once entitlement combinations, usage patterns, and identity types evolve across systems, a completed certification can coexist with unchanged exposure. Practitioners should treat periodic review as one input to governance, not the mechanism that proves control.

Cross-application visibility is the real missing control, not more certification effort. The problem is not that teams are reviewing too little, but that they are reviewing without the context required to understand business risk. Cross-app SoD conflicts, toxic entitlement combinations, and dormant access are governance failures only when they are visible enough to act on. The practitioner conclusion is straightforward: if you cannot correlate access across environments, you cannot certify risk reduction.

Identity type is now a governance variable, not a metadata field. Human users, NHIs, and AI agents behave differently enough that one review cadence cannot govern them all well. Human JML workflows assume slower change, while NHIs and AI agents can be deployed and retired on much shorter timelines. The implication is that identity governance programmes must distinguish actor type before they can claim effective oversight.

Application-scoped governance creates a false sense of completeness. A review can be fully executed and still miss the largest risks if it never sees how identities combine across business processes, SaaS tools, and cloud platforms. That is why repeated audit findings often reflect visibility failure rather than review failure. Practitioners should measure governance by the reduction in composite exposure, not by certification completion rates alone.

Continuous contextual governance is the named concept this problem now demands. It is the operating model that connects entitlement data, usage telemetry, business criticality, and identity type into one decision surface. That concept matters because the modern identity estate changes faster than quarterly governance cycles can observe. The practitioner conclusion is to design for continuous decision support, not static attestation.

From our research:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which explains why entitlement reviews so often miss the highest-risk machine identities.
  • For a broader control baseline, see Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs for provisioning, rotation, and offboarding patterns.

What this signals

Identity review programmes are shifting from attestation to correlation. Teams that still treat certifications as the primary control will continue to miss cross-application exposure, because the control problem is now the relationship between entitlements, not the entitlement itself. That is why the operating model must be redesigned around continuous context and not just periodic approval.

With 79% of organisations having experienced secrets leaks, the wider lesson is that access governance and secrets governance are now inseparable. Once credentials, tokens, and service accounts are treated as part of the same control surface, review cycles have to include usage, ownership, and lifecycle state, not just permission snapshots. See Ultimate Guide to NHIs for the broader lifecycle framing.

Continuous contextual visibility is the practical answer for IAM, IGA, and PAM teams that need to govern humans, NHIs, and AI agents together. The organisations that adapt fastest will be the ones that stop asking whether access is approved and start asking whether the current combination of access still makes business sense.


For practitioners

  • Correlate entitlements across applications Build a review workflow that joins SaaS, cloud, and business-app permissions so reviewers can see toxic combinations and SoD conflicts before certification sign-off.
  • Add usage telemetry to recertification Require last-use and activity evidence for privileged roles, service accounts, and API keys so persistent access is challenged by operational need, not habit.
  • Separate human, NHI, and AI agent review paths Map different certification cadences and approval logic to the identity type being governed, because a single review pattern will not reflect different lifecycle speeds.
  • Shift from point-in-time review to event-driven governance Trigger access re-evaluation when entitlements change, identities are created, or business context shifts, rather than waiting for the next periodic cycle.

Key takeaways

  • Access reviews fail when they are scoped to one application and one moment in time, because modern identity risk is cross-application and continuous.
  • The persistent blind spot is context: reviewers can see entitlements, but they often cannot see what those entitlements enable across the environment.
  • Governance needs continuous correlation, usage telemetry, and identity-type awareness if it is going to reduce real risk rather than merely complete certifications.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03The article centers on visibility gaps, privilege accumulation, and lifecycle blind spots in NHI governance.
NIST CSF 2.0PR.AC-4The post argues for access governance based on least privilege and cross-system context.
NIST SP 800-53 Rev 5AC-2Account management is directly implicated by periodic review failures and stale access.
NIST Zero Trust (SP 800-207)The article's call for continuous contextual visibility aligns with Zero Trust verification principles.

Apply AC-2 to ensure access is reviewed with usage and lifecycle evidence, not entitlement lists alone.


Key terms

  • Cross-Application Risk: Risk that emerges only when access and workflow data from multiple systems are evaluated together. A user or service account may appear compliant in one application while still creating a toxic combination or fraud path when combined with privileges in another system.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Contextual Visibility: Contextual visibility is the ability to see not only that an identity exists, but who owns it, what uses it, and what it can access. For NHI governance, this context turns a static inventory into an operational control for auditing, anomaly detection, and offboarding.
  • Identity Type Awareness: The practice of distinguishing human users, non-human identities, and AI agents before applying governance controls. It is essential because each actor type changes on a different lifecycle cadence, so one review model cannot reliably govern all three without losing risk context.

What's in the full article

Saviynt's full blog covers the operational detail this post intentionally leaves for the source:

  • How the vendor maps cross-application access reviews to application access governance workflows in practice
  • The specific ways entitlement lists, usage data, and business context are combined in the underlying operating model
  • Why periodic and event-driven certifications are positioned differently in the full article
  • How the source frames NHI, AI agent, and human identity review within one governance model

👉 Saviynt's full post expands on cross-application visibility, standing privilege, and modern review gaps.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org