Join our Newsletter — 33% off our NHI Course

JIT access and micro-reviews: what IAM teams should copy

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: C1.ai says Instacart eliminated standing AWS access, expanded just-in-time control to apps like Stripe, and completed nearly 70,000 automated IAM tasks while replacing quarterly reviews with per-request micro-reviews. The shift is not speed alone: governance is moving toward ephemeral, auditable entitlement windows instead of persistent grants.

Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “So Long, Standing Access: Inside Instacart’s Just-In-Time Access Playbook”.

Key questions

Q: What breaks when standing access is replaced with JIT access?

A: The main failure point is the old assumption that access should remain available long enough to be reviewed later.

Q: Why does JIT access reduce risk in sensitive business apps?

A: Because it narrows the time window in which a credential or entitlement can be misused.

Q: What are the signs that AI-assisted access governance is working?

A: Signs include fewer toxic access combinations, cleaner role definitions, faster remediation of conflicting access, and stronger audit evidence from continuous monitoring.

Practitioner guidance

  • Define expiry as the default for sensitive access Review privileged and sensitive entitlements so that standing access exists only where a documented exception is justified.
  • Translate recurring approvals into code Move repeat access decisions into source-controlled policy so reviewers can inspect rules, test changes, and trace entitlement history.
  • Use task-based micro-reviews instead of quarterly recertification alone Treat each access request as a governed event with its own context, approval logic, and expiry, especially for sensitive business applications and engineering workflows.

Bottom line: Standing access is increasingly the wrong default because it creates entitlement that outlives the work it was meant to support.

What's in the full article

C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:

  • Terraform-backed policy workflows and how Instacart used GitHub review history as audit evidence
  • The dual-path rollout approach for moving users from legacy requests to JIT access
  • How Gadjit scores JIT requests using peer adjacency, role similarity, and risk profile
  • The specific ways Instacart expanded JIT to sensitive business apps like Stripe

👉 Read C1.ai's account of Instacart's just-in-time access model →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 15 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Micro-review governance is replacing access review as the meaningful control boundary. Quarterly user access reviews assume entitlement lasts long enough to be meaningfully certified after the fact. In a JIT model, each request is the control point, so the governance object is the access event rather than the standing account state. That changes how teams think about evidence, ownership, and remediation across IAM and PAM.

A few things that frame the scale:

  • 91% of organisations say at least half of their privileged access is always-on, and only 1% have fully implemented just-in-time privileged access, according to a CyberArk study.

A question worth separating out:

Q: How should security teams govern just-in-time access for non-human identities?

A: Security teams should treat JIT as a timing control, not a trust control. Require contextual checks on the issuer, workload, and requested resource before granting access, and define deny rules for identities that behave outside baseline patterns. That approach limits abuse while preserving production continuity.

👉 Read our full editorial: Instacart’s JIT access model shows where identity governance is heading


This post was modified 15 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.