TL;DR: Periodic access reviews were built for human-centric, single-application identity models, but Saviynt argues they miss cross-application risk, standing privilege, dormant access, NHIs, and AI agents because modern entitlements now change continuously across SaaS, cloud, and hybrid environments. The core issue is not review cadence but fragmented visibility that leaves systemic exposure unmeasured between certification cycles.
NHIMG editorial — based on content published by Saviynt: Why Access Reviews Miss Application Risk
By the numbers:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
Questions worth separating out
Q: What breaks when reviews only cover one application at a time?
A: Cross-application risk stays hidden.
Q: Why do periodic access reviews miss the real NHI risk?
A: Periodic reviews miss the real risk because they measure entitlement state at a point in time, while NHI exposure can change between cycles.
Q: How can organisations tell whether access review is actually reducing risk?
A: Organisations should look beyond campaign completion and measure downstream removal, reopened exceptions, and the number of high-risk roles still present after review.
Practitioner guidance
- Correlate entitlements across applications Build a review workflow that joins SaaS, cloud, and business-app permissions so reviewers can see toxic combinations and SoD conflicts before certification sign-off.
- Add usage telemetry to recertification Require last-use and activity evidence for privileged roles, service accounts, and API keys so persistent access is challenged by operational need, not habit.
- Separate human, NHI, and AI agent review paths Map different certification cadences and approval logic to the identity type being governed, because a single review pattern will not reflect different lifecycle speeds.
What's in the full article
Saviynt's full blog covers the operational detail this post intentionally leaves for the source:
- How the vendor maps cross-application access reviews to application access governance workflows in practice
- The specific ways entitlement lists, usage data, and business context are combined in the underlying operating model
- Why periodic and event-driven certifications are positioned differently in the full article
- How the source frames NHI, AI agent, and human identity review within one governance model
👉 Read Saviynt's analysis of why access reviews miss application risk →
Access reviews and cross-app risk: why are teams missing it?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Periodic access review is now a lagging indicator, not a control boundary. The review model was built for stable, human-paced identity change inside single applications, but modern identity risk is distributed and continuous. Once entitlement combinations, usage patterns, and identity types evolve across systems, a completed certification can coexist with unchanged exposure. Practitioners should treat periodic review as one input to governance, not the mechanism that proves control.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which explains why entitlement reviews so often miss the highest-risk machine identities.
A question worth separating out:
Q: Should teams keep using access reviews for human users while treating NHIs differently?
A: Yes, but only if the governance model separates identity types. Human reviews still fit slower JML patterns, while NHIs and AI agents need continuous, event-driven oversight tied to ownership, usage, and lifecycle changes. One cadence cannot govern all three actor types effectively.
👉 Read our full editorial: Why access reviews miss modern identity risk across apps