Join our Newsletter — 33% off our NHI Course

On-demand access reviews: are calendar cycles leaving gaps?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Calendar-based recertification leaves a security gap because access can drift for weeks or months before the next review, while on-demand reviews can be triggered by JML events, privilege changes, or security incidents, according to Veza. That shift matters because access governance only works when reviews happen close to the risk event, not after it has already widened the blast radius.

Editorial analysis by NHI Mgmt Group, based on content published by Veza: “On-demand Access Reviews”.

Key questions

Q: What breaks when access reviews are only run on a fixed schedule?

A: Fixed-cycle reviews encourage repetition, not judgment.

Q: Why do on-demand access reviews reduce identity risk better than quarterly recertification?

A: They tie certification to the event that changed the risk, which means access is judged while the change is still current.

Q: How do security teams know when recertification is too late?

A: It is too late when the entitlement has already changed several times before the review starts, or when the account has already accumulated stale access that the reviewer cannot reasonably judge from the current state.

Practitioner guidance

  • Define review triggers around risk events Launch access reviews when role changes, offboarding, privilege escalation, MFA status changes, or anomalous account activity are detected, rather than waiting for the next campaign.
  • Separate trigger logic from review scope Use a narrow detection condition to start the review, then scope the certification to the broader entitlement set that should be revalidated.
  • Prioritise movers and leavers first Give immediate review handling to accounts with recent role changes, terminations, or accumulated access that may no longer match current duties.

Bottom line: Calendar-based access recertification can leave excess permissions in place long after the underlying risk has changed.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 10 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20760
 

Calendar-bound recertification is a timing control, not a risk control. Once access changes faster than the review cadence, the programme can no longer prove least privilege at the moment it matters. The governance failure is not lack of review activity, but review latency relative to access drift. Practitioners should treat cadence as a constraint, not a security outcome.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations review NHIs and human accounts with the same governance model?

A: The lifecycle logic can be similar, but the triggers and evidence differ. Human movers and leavers are driven by HR or identity events, while NHIs need ownership, purpose, and end-of-life handling to prevent stale service accounts and keys from outliving their use.

👉 Read our full editorial: On-demand access reviews close the recertification security gap


This post was modified 10 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.