TL;DR: Governance fails when IGA tools miss trusts, temporary privilege, and cross-boundary access paths, according to Clarity Security. The Enterprise Access Model helps answer who should hold Tier 0 and Tier 1 access, but it does not reveal all the nested, federated, and unmanaged permissions already in play.
NHIMG editorial — based on content published by Clarity Security: the Enterprise Access Model, tiered access governance, and hidden privilege paths
Questions worth separating out
Q: What breaks when Tier 0 access is hidden behind nested or federated trusts?
A: Governance breaks because review tools see the parent identity, not the effective control path.
Q: Why do nested and federated access paths create more risk than direct assignments?
A: They create risk because they can bypass the normal access model that teams think they are governing.
Q: How should security teams govern emergency Tier 0 access?
A: Treat it as a privileged workflow with explicit approval, expiry, and post-event validation.
Practitioner guidance
- Catalogue every trust path into Tier 0 Inventory cross-forest trusts, federated access, nested group membership, cloud account linkages, and legacy authentication dependencies that can produce Tier 0 control.
- Review effective privilege at the destination system Do not rely on the source directory or IDP to describe who really has access.
- Time-box every privileged exception Use just-in-time elevation for Tier 0 and Tier 1 tasks, require a stated business purpose, and force expiry plus post-use review.
What's in the full article
Clarity Security's full article covers the operational detail this post intentionally leaves for the source:
- The article walks through Tier 0 and Tier 1 examples across IAM, cloud control planes, and business systems.
- It expands the recommended review focus to cross-forest trusts, federated permissions, and legacy access paths.
- It describes how teams can structure recurring access reviews for privileged accounts and vendor exceptions.
- It explains where most organisations miss hidden access because the IDP does not know everything.
👉 Read Clarity Security's analysis of the Enterprise Access Model and privileged access governance →
Enterprise access model tiers: where identity governance breaks down?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Tier-based governance only works when the effective identity graph is visible. The Enterprise Access Model is a useful policy frame, but policy is not discovery. If nested trusts, federated permissions, and linked cloud accounts are outside the review surface, then the organisation is governing a diagram rather than actual access. The implication is simple: access tiering must be validated against effective privilege, not only assigned privilege.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Only 20% of organisations have formal processes for offboarding and revoking API keys, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should be allowed to use Tier 0 or Tier 1 access in practice?
A: Only identities that have a documented operational need, a defined scope, and an independently reviewable access path should be allowed to use those tiers. That includes dedicated administrators, tightly governed response teams, and rare vendor exceptions. If the path cannot be reviewed, it should not be trusted.
👉 Read our full editorial: Enterprise access model governance gaps in tier 0 and tier 1