TL;DR: Broken access control remains the most exploited flaw in modern software, while stolen credentials appear in nearly one-third of breaches and AI-related incidents often lack proper access controls, according to Cerbos and referenced industry research. Authorization is shifting from an application detail to a board-level identity control because runtime decisions now govern humans, workloads, and AI agents alike.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “Benefits of on-premise authorization: Why enterprises are moving toward self-hosted”.
By the numbers:
- Broken access control has held the #1 spot on the OWASP Top 10 since 2021 and maintained it in 2025.
- Stolen credentials have appeared in nearly one-third of breaches, or 31%, over the past decade.
- Forty percent of enterprise applications are expected to integrate task-specific AI agents by the end of 2026.
Key questions
A: When authorization is spread across multiple applications, revocation becomes unreliable, team changes can leave stale access behind, and audits become fragmented.
Q: Why do stolen credentials become more dangerous when authorization is weak?
A: Stolen credentials provide entry, but weak authorization determines how far the attacker can go.
Q: What are the signs that an authorization model is failing in practice?
A: Common signs include inconsistent decisions across services, repeated permission errors, unexpected access to restricted resources, and policy changes that are hard to trace.
Practitioner guidance
- Map authorization ownership to a single control plane Identify where policy is currently implemented across services, scripts, and platform layers, then consolidate decision authority so teams can answer who can access what without code spelunking.
- Separate policy decision from policy enforcement Use a central policy decision point with distributed enforcement points so API services, workloads, and agents all evaluate the same rules at runtime.
- Define runtime controls for non-human identities Require every service account, workload, and AI agent to pass through the same authorization logic for sensitive actions, including delegation and tool use.
Bottom line: Authorization is now a governance control because runtime decisions determine whether humans, workloads, and AI agents can act under a defensible policy.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authorization has become the board-level control because it is the only layer that can explain live access decisions. Identity governance can inventory entitlements, but it cannot on its own answer why a specific request was allowed at a specific moment. That gap matters when regulators, auditors, and boards expect a defensible trail from request to policy to outcome. The practitioner conclusion is that authorization is now a governance instrument, not just an application utility.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: When should organisations choose on-premise authorization over cloud-hosted control?
A: Choose on-premise when policy data, decision logs, or runtime availability must stay inside a regulated boundary. That is most defensible in sovereign, air-gapped, defense, healthcare, and financial environments where external dependency would turn access control into an availability risk.
👉 Read our full editorial: On-prem authorization is becoming board-level identity control