By NHI Mgmt Group Editorial TeamBased on Zluri: “Why is Zluri the Best IGA Platform In 2026?” (December 24, 2025)

TL;DR: Manual access reviews, provisioning, deprovisioning, and certification create visibility and compliance gaps across SaaS estates, according to Zluri, and its 2026 IGA positioning centres on automation, discovery, and ticketless requests for governance workflows. The deeper issue is that access governance only works when entitlement state is current, complete, and reviewable, which manual processes rarely guarantee.


At a glance

What this is: This is an IGA-focused article arguing that manual access governance breaks down across SaaS estates when visibility, provisioning, deprovisioning and certification depend on human effort.

Why it matters: It matters because IAM, IGA and PAM teams cannot certify or revoke access reliably if the underlying entitlement picture is stale, partial or spread across disconnected systems.


Context

Identity governance only works when the entitlement record is current, complete and reviewable. In SaaS-heavy environments, that becomes difficult because access changes happen continuously across onboarding, role changes, app requests and offboarding.

Zluri's article argues that manual workflows create visibility gaps, review delays and deprovisioning risk. The governance problem is not just operational inefficiency. It is the loss of trustworthy access state, which undermines certification decisions, audit evidence and timely revocation.


Key questions

Q: What breaks when access reviews rely on stale entitlement data?

A: Access reviews become a documentation exercise instead of a control test when entitlement data is stale. Reviewers approve or reject a snapshot that no longer reflects who can actually reach systems, so orphaned accounts, inactive privileges, and unowned access escape detection. A live source of truth is the difference between governance and guesswork.

Q: When should organisations automate data access instead of using tickets?

A: Organisations should automate access when the request is recurring, low-risk, and policy-driven, such as standard analyst access or repeat AI consumption patterns. Tickets should be reserved for exceptions, sensitive escalations, and unusual combinations of data. If routine access still needs manual handling, the governance model is too slow for the business.

Q: What are the signs that SaaS app permission governance is failing?

A: Common warning signs include users approving apps outside policy, security teams lacking visibility into permission changes, and integrations with broad access that no one can explain. If administrators cannot see app security settings or changes are not reviewed promptly, the organisation is operating with blind spots that attackers can exploit through consent phishing or existing integrations.

Q: How do identity teams reduce access drift across onboarding, changes and offboarding?

A: They should connect identity lifecycle events to provisioning, modification and deprovisioning workflows so access changes follow the business event rather than a later manual ticket. That keeps role changes, departures and new joiners aligned with policy and reduces the chance that stale access survives past its justified window.


Technical breakdown

Why manual certification fails in SaaS estates

Access certification depends on reviewers seeing the right user, the right app and the right permission at the right time. In a decentralised SaaS estate, that evidence is fragmented across SSO, HR, finance systems and direct app admin consoles, so manual review becomes a reconstruction exercise rather than a control. When the review input is incomplete, the certifier can only validate a partial picture. That weakens the governance value of the review and turns certification into a paperwork activity instead of an authoritative control.

Practical implication: treat incomplete entitlement visibility as a control failure, not a process nuisance.

How automated discovery changes the access data model

Discovery engines change IGA by aggregating entitlement signals from multiple sources and normalising them into a single access view. In practice, that means identity teams can see who has access, which accounts look active or inactive, and which apps are managed, unmanaged or shadow IT. This matters because governance decisions depend on correlating user status, app ownership and permission scope. Without that correlation, the team is certifying access against stale assumptions, not operational reality.

Practical implication: build governance decisions on a unified entitlement view before you trust review outcomes.

Why ticketless requests and automated deprovisioning matter

Manual access request and offboarding workflows slow down entitlement change, which creates a mismatch between business reality and access state. Ticketless requests reduce friction for approved access changes, while automated deprovisioning shortens the window between leaver status and revocation. In lifecycle terms, the issue is not convenience. It is preventing persistent access from surviving the business event that justified it. The governance gain comes from making access change and access removal part of the same controlled lifecycle.

Practical implication: align request, modification and offboarding flows so revoked access is not left to manual follow-through.


Threat narrative

Attacker objective: The likely objective is to exploit stale or excessive SaaS access for unauthorized data access while the organisation's governance process fails to catch it in time.

  1. Entry occurs through ordinary SaaS access sprawl, where accounts and permissions accumulate across onboarding, role changes and app requests without a single authoritative view.
  2. Credential or entitlement misuse follows when reviewers and administrators rely on incomplete data, allowing excessive or stale access to remain in place after business changes.
  3. Escalation happens when unmanaged apps, shadow IT or delayed offboarding create permissions that outlive the user role or employment status.
  4. Impact is unauthorized access to SaaS data and weakened auditability because the organisation cannot prove that access was current when decisions were made.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Manual IGA breaks because reviewable truth is usually missing. Certification, provisioning and deprovisioning only work when entitlement state is current enough to be trusted. In SaaS estates, that state is often distributed across multiple systems and updated unevenly, so the governance process validates fragments instead of facts. The practitioner conclusion is that access review quality depends on data integrity before reviewer diligence.

Discovery is the control that makes certification defensible. Identity governance is not improved merely by asking reviewers to work harder. It improves when the programme can assemble a usable entitlement record from SSO, HR, finance and direct application signals, then classify managed, unmanaged and shadow IT access consistently. That shifts IGA from retrospective reconciliation to evidence-led control, which is the only basis for reliable certification.

Ticketless access changes the governance economics of access change. When approved requests are bottlenecked by manual tickets, the organisation creates delay that often outlasts the business need. Automated request flows do not eliminate governance, but they do move it to pre-approved policy and faster execution. The practitioner implication is that access latency and governance quality are no longer separate goals; weak latency becomes a governance defect.

Lifecycle governance is the real control plane for SaaS access. Onboarding, role change and offboarding are the moments when access either stays aligned or drifts out of policy. Manual handoffs create persistent privilege windows that reviewers later struggle to correct. The conclusion for practitioners is that IGA maturity should be measured by how quickly the programme closes those windows, not by how many forms it can process.

From our research library:

What this signals

Access governance fails fastest where the entitlement picture is least complete. Teams should assume that every manual handoff creates a gap between actual access and documented access unless discovery, request and deprovisioning are tied into the same lifecycle flow. That gap is where certification loses value and audit confidence starts to erode.

The practical test is whether a reviewer can act on live context. If the programme cannot show current app ownership, user status and permission scope in one place, the certification outcome is descriptive rather than authoritative. For most IAM teams, that means IGA maturity is now a data-integration problem as much as a process problem.


For practitioners

  • Map every SaaS app to a single entitlement source of truth Consolidate SSO, HRMS, finance and direct app data into one governance view before running certification or access reviews.
  • Automate deprovisioning at offboarding Trigger revocation and account suspension from leaver events so access does not survive employment changes or role exits.
  • Classify managed, unmanaged and shadow IT apps Use discovery signals to separate controlled applications from unknown or unsanctioned ones before assigning reviewers or owners.
  • Move access requests to policy-based self-service Pre-approve common entitlements for specific roles and route exceptions for manual review only when the request falls outside policy.
  • Measure certification quality by data completeness Track how often reviewers are deciding with stale or missing context, then treat that as a governance metric rather than an admin issue.

Key takeaways

  • Manual access governance breaks down when entitlement state is fragmented, stale or hard to verify across SaaS estates.
  • Automated discovery, ticketless requests and offboarding workflows reduce the time between business change and access change.
  • The strongest IGA programmes treat access visibility and lifecycle execution as one control plane, not separate administrative tasks.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingManual offboarding gaps are central to the article's access revocation problem.
NHI-05 — Overprivileged NHIThe article centres on excess access persisting because governance cannot keep state current.
NHI-08 — Environment IsolationThe article's shadow IT and SaaS sprawl problem reflects weak separation of controlled and uncontrolled access contexts.
Recommendation — Automate offboarding triggers so entitlement removal follows the leaver event without manual delay. Review SaaS entitlements for overprivilege and remove access that exceeds role need or current purpose. Separate governed SaaS access from unmanaged app access so reviewers are certifying a bounded estate.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing permissions and authorizations across user lifecycle events.
Recommendation — Maintain current entitlements and authorization records before running access reviews or certification.
CIS Controls v8CIS-5 — Account ManagementThe article focuses on account lifecycle management across onboarding, change and offboarding.
Recommendation — Centralise account provisioning, modification and removal so access changes are consistent and auditable.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential and access lifecycle control is implied by the article's automation of provisioning and deprovisioning.
Recommendation — Apply authenticator management controls to keep access changes timely, tracked and revocable.

Key terms

  • Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
  • Entitlement: An entitlement is the permission set that defines what a non-human identity can do after it authenticates. It is usually expressed through roles, policies or access assignments, and unmanaged entitlements are a common reason machine identities become over-privileged over time.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Ticketless Access: A self-service access request model that removes manual ticket handling and routes requests through predefined policy and approval logic. It can improve speed, but it only remains safe when catalog scope, exception paths, and ownership are tightly controlled.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org