TL;DR: Access decisions are drowning teams in volume, with median approval times of 15 minutes, some latencies over 24 hours, 43.5% unused access after 90 days, 2,300% growth in agents and NHIs, and 90% unreviewed access, according to Opal Security. The governance problem is not just speed: review-based IAM assumes access can be assessed slowly and still remain meaningful.
NHIMG editorial — what this means for NHI practitioners
By the numbers:
- Median approval time stretched to 15 minutes, and latencies at some enterprises ran over 24 hours.
- 43.5 percent of granted access went unused for more than 90 days.
- Agent and non-human identities grew 2,300 percent, and 90 percent of that access went unreviewed.
Questions worth separating out
A: Use context-aware automation for routine, policy-conforming requests and reserve humans for exceptions.
Q: Why do non-human identities require more than traditional IAM reviews?
A: Because traditional IAM reviews were built around people, stable employment relationships, and visible login activity.
Q: What do organisations get wrong about access that has not been used for months?
A: They often treat it as harmless because it is dormant, when it is still active privilege.
Practitioner guidance
- Map request context to every access workflow Collect requester identity, peer access, resource sensitivity, and prior usage evidence before any approval is made.
- Set escalation thresholds for ambiguous requests Define which combinations of policy conflict, unusual entitlement scope, or missing ownership metadata must be escalated to a human reviewer.
- Track unused access as governance debt Review grants that remain unused after 90 days and treat them as stale entitlements that still enlarge blast radius.
What's in the full announcement
Opal Security's full article covers the operational detail this post intentionally leaves for the source:
- How Paladin gathers request context from connected systems before making a recommendation
- The approval and escalation flow for routine, risky, and ambiguous access requests
- Examples of how role mining and policy suggestions are applied in live access governance
- The specific integrations the platform reads from and how the review lane is configured
👉 Read Opal Security's analysis of AI review for access requests and NHI growth →
AI review for access requests: can IAM keep up with volume?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Access review is no longer the primary control for fast-moving non-human identities. Review cadences were designed for access that persists long enough to be examined. That assumption breaks when agents and NHIs are created, expanded, and used faster than the review queue can catch up. The implication is that identity governance has to stop treating review as the main safety net for high-velocity machine access.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: How should security teams automate access governance without losing control?
A: Security teams should automate repetitive review and provisioning tasks, but keep policy ownership human-led. The model works when risk tiers, SoD rules, and approval thresholds are defined centrally, then enforced consistently in workflow. Automation should speed execution and evidence collection, not replace governance judgement or exception handling.
👉 Read our full editorial: AI review for access requests exposes the limits of manual IAM