Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

On-demand access reviews: are calendar cycles leaving gaps?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Calendar-based recertification leaves a security gap because access can drift for weeks or months before the next review, while on-demand reviews can be triggered by JML events, privilege changes, or security incidents, according to Veza. That shift matters because access governance only works when reviews happen close to the risk event, not after it has already widened the blast radius.

NHIMG editorial — based on content published by Veza: on-demand access reviews and event-driven recertification

By the numbers:

Questions worth separating out

Q: How should security teams replace calendar-based access recertification?

A: Security teams should keep periodic certification for baseline governance, but add event-driven reviews for role changes, termination, privilege escalation, MFA changes, and dormant accounts.

Q: Why do periodic access reviews leave organisations exposed?

A: Periodic reviews are snapshots, not continuous control.

Q: What breaks when on-demand reviews use the wrong review scope?

A: If the trigger is high-risk but the review scope is too narrow, the control can certify the wrong entitlements and miss the real exposure.

Practitioner guidance

  • Tie reviews to identity events Launch access certification when role changes, privilege escalation, MFA changes, or termination events occur instead of waiting for quarterly cadence.
  • Separate trigger logic from review scope Use one saved query or alert to detect risk and a different scoping query to define which entitlements or accounts must be reviewed.
  • Prioritise leaver and mover workflows Make offboarding and role-change events automatic review triggers so residual access is challenged before the next campaign window.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • How Access Intelligence rules translate identity drift into on-demand review launches across specific alert conditions.
  • How Lifecycle Management workflows chain HRIS or IdP events into immediate mover and leaver certifications.
  • How consolidated mode and individual mode change review handling for broad versus entity-specific access changes.
  • How Review Intelligence and Veza Actions can be layered into downstream remediation workflows after review decisions.

👉 Read Veza's analysis of on-demand access reviews and lifecycle-triggered certification →

On-demand access reviews: are calendar cycles leaving gaps?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Calendar-based recertification is a control timing problem, not a control absence problem. The article is right to focus on the security gap between review cycles, because the risk is not that organizations never review access. The risk is that review timing is too slow for modern identity churn across users and NHIs. Least privilege degrades in the interval between events and the next campaign, so practitioners need to treat timing as part of the control design.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.

A question worth separating out:

Q: Who should be accountable when event-driven access reviews fail to close residual access?

A: Accountability should sit with identity governance owners, application owners, and the business managers who approve access decisions, because the failure is usually a process design gap rather than a single bad review. Frameworks such as access certification, lifecycle management, and least privilege all require clear ownership and auditable action.

👉 Read our full editorial: On-demand access reviews close the recertification security gap



   
ReplyQuote
Share: