TL;DR: Continuous access comparison is now generally available, letting identity teams compare any two users side by side, surface standing, unused, overprivileged, and irregular access, and trigger remediation such as UARs, expiration dates, or permission removal, according to Opal Security. The governance shift is from periodic review to continuous access optimisation, where the real question is why access differs at all.
NHIMG editorial — what this means for NHI practitioners
Questions worth separating out
Q: How should teams handle users who have access that does not match their peers?
A: Treat peer variance as a governance signal, not just a review note.
Q: Why is unused access still a security problem if no one is using it?
A: Unused access still expands the attack surface, creates audit noise, and preserves privilege that should have expired.
Q: What do teams get wrong about quarterly access reviews?
A: The most common mistake is treating every quarter as identical.
Practitioner guidance
- Build peer-based access review paths Compare users in the same role, function, or application group before recertification begins so reviewers can focus on meaningful deltas instead of full entitlement inventories.
- Separate standing, unused, and irregular access queues Route each access pattern into its own remediation path so expiration, owner validation, and permission removal are handled according to the specific failure mode.
- Connect detection to enforcement Trigger UARs, expiration dates, and permission removal directly from comparison findings so remediation happens while the access variance is still current.
What's in the full announcement
Opal Security's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step workflow for comparing any two users across groups, roles, and application permissions
- Operational examples of when to notify application owners, trigger UARs, or convert access to time-bound grants
- Product-specific guidance on how Risk Center and Access Comparison are used together in the interface
- Documentation-level detail on deployment and day-to-day use for teams already running the platform
👉 Read Opal Security's article on Access Comparison for outlier access →
Access comparison for outlier access: is continuous review enough?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Continuous access comparison is a control for access drift, not just a convenience feature. The reason it matters is that identity teams often know an account is excessive before they can explain why it is excessive. A comparison-first model reduces the distance between detection and remediation, which is where many governance programmes lose momentum. Practitioners should treat this as a shift from static review evidence to live entitlement reasoning.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate versus 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How do organisations reduce excess access without slowing down operations?
A: Use exception-based workflows. Let comparison tooling surface the outliers, then trigger owner notification, access review, expiration, or removal only where the delta is unexplained. That keeps routine access intact while forcing remediation on the small subset of permissions that actually create risk.
👉 Read our full editorial: Continuous access comparison reframes least privilege for IAM teams