TL;DR: Permission drift, standing access, and weak review cycles can turn ordinary role changes into security incidents and compliance failures, according to Soffid, which argues that access governance must be continuous rather than periodic. The core issue is that access reviews alone cannot contain privilege accumulation between review windows.
NHIMG editorial — based on content published by Soffid: Access Governance: when permissions stop being a management problem and become a security risk
By the numbers:
- The average cost of an incident originating internally, whether malicious or not, reaches $13.1 million.
- 97% of non-human identities have excessive privileges.
Questions worth separating out
Q: How should security teams turn access reviews into real risk reduction?
A: Security teams should use access reviews to remove dormant access, orphaned accounts, and privileges that no longer match the work being performed.
Q: Why do temporary access and exceptions create so much identity risk?
A: Temporary access becomes dangerous when it outlives the event it was created for.
Q: What breaks when governance relies only on quarterly access reviews?
A: Quarterly reviews miss the day-to-day drift that accumulates between certification cycles.
Practitioner guidance
- Map every permission to an owner and expiry Require each access grant, exception, and temporary entitlement to carry a named owner, business reason, and review date.
- Convert access reviews into continuous entitlement monitoring Use periodic certifications only as one checkpoint in a broader control loop that watches role changes, dormant accounts, and new exceptions between review cycles.
- Enforce least privilege through revocation, not just assignment Build revocation into role change, transfer, and offboarding workflows so access is removed as part of the identity lifecycle.
What's in the full article
Soffid's full article covers the operational detail this post intentionally leaves for the source:
- How its IGA approach centralises visibility into identities, access types, and review cycles.
- How access review automation is positioned alongside PAM, AM, and IRC inside a converged IAM platform.
- How traceability is maintained for approvals, exceptions, and revocations across the identity lifecycle.
- How the article links continuous governance to regulated-environment evidence and audit readiness.
👉 Read Soffid's article on access governance and continuous permission control →
Access governance and permission sprawl: are your controls keeping up?
Explore further
Permission persistence is the real control failure, not the initial grant. The article is strongest when it moves beyond onboarding and focuses on what happens after access is approved. In IAM and IGA programmes, risk usually emerges from role change, exception handling, and delayed revocation, not from the original permission request. Practitioners should treat lingering access as the governance failure mode to eliminate.
A few things that frame the scale:
- 97% of non-human identities have excessive privileges, according to The 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected, according to the same report.
A question worth separating out:
Q: Who is accountable when stale group access causes a security incident?
A: Accountability usually sits with identity owners, application owners, and compliance leaders together, because stale group access is a governance failure rather than a single technical mistake. The practical test is whether the organisation can explain why the group existed, who approved it, and why it was still active.
👉 Read our full editorial: Access governance turns permission sprawl into a security risk