Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How do access reviews and segregation of duties…
Governance, Ownership & Risk

How do access reviews and segregation of duties fail when teams treat SSO as the access record?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Governance, Ownership & Risk

SSO group lists are not certification evidence and they do not capture toxic combinations at the permission level. Effective access reviews need timestamped proof of who held what, when they got it, and when it was revoked. Segregation of duties also requires visibility across application entitlements, not just identity-provider membership.

Why This Matters for Security Teams

Access reviews fail when SSO membership is mistaken for the record of truth. Identity-provider groups show a coarse snapshot of who can authenticate, but they do not prove which application entitlements were actually granted, which combinations were active, or whether access was revoked on time. That gap breaks both certification quality and segregation of duties, especially where service accounts, automation, and delegated admin paths exist.

Security teams often discover the problem only after an audit exception or an internal control failure. The OWASP Non-Human Identity Top 10 treats credential and entitlement sprawl as a core risk, while NIST SP 800-53 Rev. 5 expects access control evidence that can support accountability, review, and revocation. NHIMG’s NHI Lifecycle Management Guide frames the same issue operationally: lifecycle state has to be visible across the full chain of issuance, use, and removal, not only at login.

In practice, many security teams encounter toxic combinations and stale permissions only after an auditor asks for proof that nobody retained conflicting access for months.

How It Works in Practice

A defensible review process starts by separating authentication from authorisation. SSO proves that an identity entered the system; it does not prove the full set of downstream entitlements that were assigned in SaaS apps, cloud consoles, PAM vaults, or custom tools. For access certification, the evidence set should include timestamped assignment records, approval context, effective start and end times, and revocation confirmation. That is the only way to show who held what, when they got it, and when it disappeared.

For segregation of duties, the control is even stricter. A reviewer needs visibility across entitlements, not just across people. If one role grants payment approval and another grants invoice creation, SSO group membership may still look harmless while the combined permission set is toxic. Current guidance suggests building review logic around effective permissions and business functions, then mapping those to SoD rules at the application or privilege layer. NHIMG’s 52 NHI Breaches Analysis shows how often hidden privilege paths become visible only after compromise or misuse, not during routine directory review.

  • Use identity-provider groups as one input, not the certification record.
  • Pull entitlement data from each critical application and privileged platform.
  • Record approvals, timestamps, and revocations in an immutable workflow log.
  • Recompute SoD conflicts from effective access, not from HR job titles.

Where mature programs improve further, they reconcile SSO, app entitlements, and PAM sessions into one evidence chain. That approach also supports review of NHI and automation identities that may never appear in a human-focused access attestation. Ultimate Guide to NHIs is useful here because it reinforces that non-human access must be governed by lifecycle state and scope, not by a directory label. These controls tend to break down in federated SaaS estates where each app stores entitlements differently and revocation is asynchronous.

Common Variations and Edge Cases

Tighter access review rules often increase operational overhead, requiring organisations to balance stronger assurance against slower certification cycles and more manual evidence collection. That tradeoff becomes sharper in environments with frequent contractor changes, delegated admin roles, or NHI-driven automation, where a simple quarterly review cannot keep pace with entitlement drift.

There is no universal standard for this yet, but current guidance suggests treating SSO membership as a trigger for review rather than as the review artefact itself. In practice, teams may also need exception handling for break-glass accounts, shared operational accounts, and short-lived JIT access. Those cases still need timestamped proof, but the approval path may be different from standard user access.

One useful pattern is to define SoD rules at the business capability level, then translate them into app-level entitlements and privileged actions. That keeps the control meaningful when one application exposes multiple permissions under a single role or when an NHI uses API scopes instead of interactive login. The DeepSeek breach and the Microsoft SAS Key Breach both underscore how quickly access assumptions collapse when credentials and privileges are not tracked with precision.

The practical failure mode is simple: when review evidence stops at the SSO layer, the organisation can certify a clean group list while hidden app rights, revoked-but-still-active sessions, and toxic permission pairs remain untouched.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04Covers entitlement sprawl and missing lifecycle evidence for non-human access.
NIST CSF 2.0PR.AC-4Access permissions must be reviewed and managed at the entitlement level.
NIST SP 800-53 Rev 5AC-2Account management requires authoritative issuance, modification, and removal records.
NIST AI RMFAI governance emphasizes traceability and accountability for automated access decisions.
CSA MAESTROMAESTRO addresses governance for agentic and non-human workloads with dynamic permissions.

Reconcile SSO, app grants, and revocations so reviews certify effective access, not directory membership.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org