TL;DR: Access creep accumulates during employment, not just at onboarding or termination, because role changes and temporary access often never get cleaned up; Zluri’s analysis models 500 employees, 100 SaaS apps, and 4,500 excess grants a year. The control gap is visibility and lifecycle automation, not a lack of provisioning effort.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “The Math Behind Access Creep: What Happens Between Onboarding and Offboarding”.
Key questions
Q: What breaks when access cleanup only happens at onboarding and offboarding?
A: Access accumulates during the middle of employment when role changes and temporary grants are not re-evaluated.
Q: Why do role changes create so much access creep?
A: Role changes create access creep because organisations are faster at adding new access than removing old access.
Q: How can security teams tell if agentic access is getting out of hand?
A: Look for tokens that can reach multiple environments, secrets that appear in config files or shared workspaces, and actions that do not trigger external approval before production writes.
Practitioner guidance
- Implement role-change-triggered access reviews Link promotions, team moves, and department changes to an automatic entitlement review that recalculates the role baseline and removes superseded access.
- Add default expiry to temporary access Require every project, emergency, or backup grant to carry an end date unless a system event explicitly renews it.
- Build a complete application inventory Unify federated SaaS, direct-to-app provisioning, departmental tools, and shadow IT into one discovery view before attempting cleanup.
Bottom line: Access creep builds during active employment, especially when role changes and temporary access are not tied to removal workflows.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Access creep is a lifecycle control failure, not a provisioning failure. The article’s core insight is that onboarding can be clean while access still accumulates through the middle of employment. That shifts the governance problem from grant accuracy to entitlement decay, which is where many IAM and IGA programmes still underinvest. The practitioner conclusion is that lifecycle control has to extend across the full employment journey, not just the joiner and leaver endpoints.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations prioritise automation or role cleanup first in user access management?
A: Role cleanup should usually come first when access is badly structured, because automation will only accelerate messy decisions. Once roles and responsibilities are clearer, automation can reduce delay in provisioning, deprovisioning, and review cycles. The right order is to simplify the model, then automate the repetitive work around it.
👉 Read our full editorial: Access creep between onboarding and offboarding is a math problem