TL;DR: Just-in-time access reduces standing privilege but does not solve the governance gap created when access is still requested, approved, and revoked through human-paced IAM workflows, according to Ploy. The model is useful, but it only works when entitlement scope, auditability, and revocation are tightly controlled, not assumed.
NHIMG editorial — based on content published by Ploy: Understanding Just-In-Time Access: A New Era in Cybersecurity
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: What breaks when just-in-time access is used without lifecycle governance?
A: Temporary access becomes another form of standing privilege if no one owns revocation, recertification, and offboarding.
Q: Why does just-in-time access still need strong governance review?
A: Because JIT changes the timing of privilege, not the accountability for it.
Q: What are the biggest implementation mistakes with just-in-time access?
A: The most common mistakes are over-broad entitlement templates, weak expiration enforcement, and failure to validate cleanup across target systems.
Practitioner guidance
- Map the real privilege boundary behind each JIT request Document the exact resource, role, and downstream inheritance attached to each temporary grant, then remove any entitlement that exceeds the task scope.
- Test revocation against downstream systems Verify that temporary access disappears from identity providers, cloud roles, application sessions, and cached tokens when the task ends.
- Attach issuance logs to governance evidence Record who requested access, why it was approved, what scope was granted, and when it expired.
What's in the full article
Ploy's full insights article covers the operational detail this post intentionally leaves for the source:
- Step-by-step explanation of how JIT access is granted, evaluated, and revoked in practice.
- Examples of JIT use across healthcare, financial services, and software development environments.
- Discussion of operational trade-offs between speed, compliance evidence, and access reduction.
- The article's broader commentary on the future of access management in fast-changing environments.
👉 Read Ploy's analysis of just-in-time access and modern access management →
Just-in-time access: are your access controls keeping up?
Explore further
Just-in-time access is not a substitute for privilege design. It reduces standing exposure, but it does not answer the harder question of how much privilege should exist in the first place. If the underlying role or entitlement is over-scoped, JIT simply turns a permanent problem into a temporary one. Practitioners should treat it as a constraint on duration, not a cure for access excess.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: What is the difference between just-in-time access and zero standing privilege?
A: Just-in-time access is the delivery pattern, while zero standing privilege is the policy goal. JIT grants access when needed and removes it after use. ZSP goes further by eliminating persistent access as the default state. Teams need both, but ZSP is the governance model that makes JIT meaningful.
👉 Read our full editorial: Just-in-time access is weakening standing privilege assumptions