TL;DR: Access reviews, audit responses, and governance decisions fail when teams assume identity data is accurate without independently verifying connectors, mappings, entitlements, and vault records, according to Hydden. That makes attestation a control for proving data integrity, not just completing a review, and the underlying assumption collapse matters for IAM, PAM, and NHI governance alike.
NHIMG editorial — based on content published by Hydden: identity data attestation for access reviews, audits, and vault governance
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
- Only 5.7% of organisations have full visibility into their service accounts.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
Questions worth separating out
Q: How should security teams prove that access reviews are based on accurate identity data?
A: They should require evidence that the source data itself was verified before certification closes.
Q: What breaks when access reviews are not tied to identity lifecycle events?
A: Reviews become a backward-looking checklist instead of a control that removes real excess access.
Q: How do organisations know whether PAM is actually covering privileged access?
A: Organisations know PAM is covering privileged access when they can demonstrate governance over the full secret estate, not just the credentials stored in one vault.
Practitioner guidance
- Verify connector and mapping integrity before certification Require reviewers to confirm connector configuration, attribute mappings, and collection scope before any access review can close.
- Reconcile governed records against source systems Use side-by-side comparisons for accounts, roles, and memberships so governance teams can see field-level drift between the system of record and the system being certified.
- Treat vault contents as candidates for validation Before attesting privileged access, compare vaulted accounts with the directory or application sources they should trace back to.
What's in the full article
Hydden's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step walkthrough of how identity integrity attestation works across connector settings, mappings, accounts, entitlements, and role membership.
- Side-by-side reconciliation examples showing how mismatched source records and governance records appear in practice.
- Examples of how immutable attestation bundles preserve reviewer activity, configuration state, and exported evidence for audit.
- Workflow behaviour for recurring cycles, including scheduled attestation creation and status-triggered routing.
👉 Read Hydden's article on identity data attestation and review integrity →
Identity data attestation: is your governance data actually right?
Explore further
Identity governance built on unverified data is a control illusion. Access reviews, recertifications, and audit responses only have value when the underlying identity record is correct. If connector state, mappings, or role membership drift is unchecked, the governance outcome is procedurally complete but substantively false. The implication is that data integrity must be treated as a prerequisite control, not a downstream documentation step.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
A question worth separating out:
Q: Who is accountable when identity data used for certification is wrong?
A: Accountability sits with the governance owner who approved the data and the process that allowed unverified records to be certified. Good IAM and PAM practice requires a named reviewer, a defined attestation decision, and preserved evidence showing what was checked. Without those elements, nobody can defend the outcome to audit.
👉 Read our full editorial: Identity data attestation closes the gap in access reviews