Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI review for access requests: can IAM keep up with volume?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Access decisions are drowning teams in volume, with median approval times of 15 minutes, some latencies over 24 hours, 43.5% unused access after 90 days, 2,300% growth in agents and NHIs, and 90% unreviewed access, according to Opal Security. The governance problem is not just speed: review-based IAM assumes access can be assessed slowly and still remain meaningful.

NHIMG editorial — what this means for NHI practitioners

By the numbers:

Questions worth separating out

Q: How should security teams handle access approvals when requests arrive faster than humans can review them?

A: Use context-aware automation for routine, policy-conforming requests and reserve humans for exceptions.

Q: Why do non-human identities require more than traditional IAM reviews?

A: Because traditional IAM reviews were built around people, stable employment relationships, and visible login activity.

Q: What do organisations get wrong about access that has not been used for months?

A: They often treat it as harmless because it is dormant, when it is still active privilege.

Practitioner guidance

  • Map request context to every access workflow Collect requester identity, peer access, resource sensitivity, and prior usage evidence before any approval is made.
  • Set escalation thresholds for ambiguous requests Define which combinations of policy conflict, unusual entitlement scope, or missing ownership metadata must be escalated to a human reviewer.
  • Track unused access as governance debt Review grants that remain unused after 90 days and treat them as stale entitlements that still enlarge blast radius.

What's in the full announcement

Opal Security's full article covers the operational detail this post intentionally leaves for the source:

  • How Paladin gathers request context from connected systems before making a recommendation
  • The approval and escalation flow for routine, risky, and ambiguous access requests
  • Examples of how role mining and policy suggestions are applied in live access governance
  • The specific integrations the platform reads from and how the review lane is configured

👉 Read Opal Security's analysis of AI review for access requests and NHI growth →

AI review for access requests: can IAM keep up with volume?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Access review is no longer the primary control for fast-moving non-human identities. Review cadences were designed for access that persists long enough to be examined. That assumption breaks when agents and NHIs are created, expanded, and used faster than the review queue can catch up. The implication is that identity governance has to stop treating review as the main safety net for high-velocity machine access.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: How should security teams automate access governance without losing control?

A: Security teams should automate repetitive review and provisioning tasks, but keep policy ownership human-led. The model works when risk tiers, SoD rules, and approval thresholds are defined centrally, then enforced consistently in workflow. Automation should speed execution and evidence collection, not replace governance judgement or exception handling.

👉 Read our full editorial: AI review for access requests exposes the limits of manual IAM



   
ReplyQuote
Share: