Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SaaS access reviews and the governance gap teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: Quarterly access reviews only validate who had access on a single day, while Salesforce tokens, role creep, and AI agent permissions can change continuously between cycles, according to PlainID. The control problem is not diligence but timing: snapshot-based certification cannot govern a constantly changing SaaS estate.

NHIMG editorial — based on content published by PlainID: SaaS Authorization: When Access Reviews Fall Behind

By the numbers:

  • The average company now runs on 106 SaaS applications, according to BetterCloud’s State of SaaS report.

Questions worth separating out

Q: What breaks when SaaS access is not tied to lifecycle controls?

A: Access persists after the business need has ended, which means former employees, stale integrations, and unused permissions can still reach data.

Q: Why do SaaS environments make access certification harder to trust?

A: Because the environment changes faster than the review cadence.

Q: How can security teams reduce stale access in SaaS?

A: Use runtime authorization for the most sensitive applications, pair it with explicit lifecycle ownership for non-human identities, and shorten the time between entitlement change and policy enforcement.

Practitioner guidance

  • Shift high-risk SaaS access to runtime policy enforcement Apply policy at request time for systems where standing access creates the biggest exposure, especially finance, CRM, HR, and support platforms.
  • Separate human reviews from non-human lifecycle controls Give service accounts, integrations, and AI agents explicit ownership, expiry, and purpose tracking so they are not governed only through the employee review process.
  • Measure the delay between entitlement change and review Track how long contractor exits, role changes, and integration updates remain active before policy or review catches up, then use that lag as a control metric.

What's in the full article

PlainID's full article covers the operational detail this post intentionally leaves for the source:

  • How the runtime authorization model is applied inside existing SaaS, IAM, and IGA environments.
  • What Zero Standing Privilege means for contractor access, service accounts, and agent-driven workflows.
  • How policy-based access control changes the review workflow without replacing the identity stack.
  • Why the Authorization Graph matters when auditors ask for evidence of who accessed what and when.

👉 Read PlainID's analysis of why SaaS access reviews fall behind →

SaaS access reviews and the governance gap teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Snapshot-based review is a governance artefact, not a runtime control. Access certification proves that someone looked at permissions at one point in time, but it does not constrain what happens before or after that moment. In SaaS estates where entitlements can change daily, the control cannot close exposure windows created by delayed offboarding, integration sprawl, or scope creep. The implication is that access governance has to move from attestation to enforcement.

A few things that frame the scale:

  • 28% of secrets incidents now originate outside code repositories, in Slack, Jira, and Confluence, and are 13% more likely to be categorised as critical than code-based leaks, according to the State of Secrets Sprawl 2026.
  • 64% of valid secrets leaked in 2022 are still valid and exploitable today, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: Who is accountable when an AI agent performs an unauthorized action in a SaaS product?

A: Accountability stays with the organisation that granted the agent authority, but investigators need evidence to prove what the actor was allowed to do and what it actually did. That is why audit logs, scope controls, and session-level attribution matter across human, service, and agent activity.

👉 Read our full editorial: SaaS access reviews are failing between review cycles



   
ReplyQuote
Share: