They need app-native entitlement discovery, continuous access review, and reconciliation against IAM records. The key is to compare what the application actually allows with what the directory says should exist, then investigate every direct grant, token, and inherited role that does not map cleanly.
How untracked permissions show up in practice
Untracked permissions are the gap between what a cloud or SaaS app is actually allowing and what your identity records say should exist. The problem often appears as direct grants, inherited roles, delegated admin paths, app-specific entitlements, or tokens that bypass the directory entirely. A useful detection model starts with the application’s own entitlement view, not just the IAM console.
In cloud estates, this is why right-sizing work focuses on granted versus used permissions, not only assigned roles. NHIMG’s Cloud PAM and CIEM Guide is useful here because it frames effective permissions, escalation paths, and unused access as the core detection problem rather than a one-time review exercise.
In SaaS, the same issue appears when role hierarchies, workspace permissions, or app-local admin grants drift away from the source of truth. The practical question is not “does the user exist,” but “what can this account, token, or inherited role actually do right now?”
What organisations need to compare to detect drift
The best detection pattern is reconciliation: compare app-native entitlements, IAM records, and the active access paths that the app exposes. That means reviewing direct user grants, group membership, service principals, delegated approvals, API tokens, and inherited permissions together, because any one of those can create effective access that is invisible in a basic directory report.
Organisations also need a stable entitlement inventory. If you do not know which roles, scopes, and admin surfaces exist inside the app, continuous access review becomes a manual guessing exercise. NHIMG’s Authorisation Models Guide helps because untracked permissions usually sit at the boundary between role models, attribute rules, and externally managed policy decisions.
For cloud platforms, this comparison should include privilege escalation paths as well as ordinary access. NHIMG’s Privileged Access Management Guide is relevant because standing privilege, break-glass access, and session-level elevation often create permissions that never appear in a simple “current role” export.
How to turn detection into a repeatable control
Detection works best when entitlement discovery is continuous, not quarterly. New grants appear through integrations, automation, admin shortcuts, and shadow IT, so the control has to watch for changes in near real time and re-check whether the permission still maps to an approved owner, business need, and expected lifecycle.
Practical teams also validate entitlements against use. If an app shows permissions that are never exercised, or if a token has broader scope than the person or workload needs, that is a signal to investigate whether the access was intentionally granted, inherited by design, or simply left behind after a workflow change. NHIMG’s Just-in-Time Access and Zero Standing Privilege Guide is relevant because it explains how temporary access can reduce the number of standing entitlements that need constant cleanup.
For cloud environments, the most reliable teams reconcile entitlement data with policy and trust boundaries, then investigate anything that cannot be explained by an approved role, managed exception, or documented delegation path. That is the difference between simple reporting and real entitlement governance.
Risk and Threat Considerations
Untracked permissions create hidden blast radius. They can persist after a joiner-mover-leaver event, survive app migrations, or remain attached to tokens and delegated admin paths long after the business owner has forgotten they exist. The risk is not only overprivilege, but also false confidence, because directory reports can look clean while the application still grants broad access.
Failure mechanism: Access is created, inherited, or delegated inside the app without being mirrored in IAM records, so review processes miss the effective permission. That gap is especially dangerous when the hidden access can reach production data, administrative functions, or sensitive SaaS content.
Impact: Organisations lose visibility into who can do what, making privilege creep, unauthorized access, and lateral movement easier to sustain. In the worst case, a forgotten grant or token becomes an attack path that survives normal access reviews and only surfaces after an incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Detecting untracked permissions depends on account and entitlement inventory discipline. |
| Recommendation — Inventory accounts and entitlements continuously, then remove or flag access that no longer matches approved ownership. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Continuous reconciliation of app grants against IAM records is an account governance activity. |
| AC-6 — Least Privilege | Untracked permissions are often excessive permissions that violate least-privilege expectations. | |
| Recommendation — Maintain account records and review them against actual application access on a recurring basis. Restrict privileges to the minimum required and investigate any access that exceeds job need. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Cloud and SaaS entitlement drift is fundamentally about granting, reviewing, and removing access rights. |
| Recommendation — Review access rights regularly and revoke permissions that are no longer justified. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud entitlement discovery and reconciliation are core IAM controls in cloud environments. |
| Recommendation — Map effective cloud permissions to approved identities and investigate any unmapped access. | ||
Practitioner Guidance
What to prioritise: Start with the applications that hold the most sensitive data or expose the widest admin surface, then work outward to lower-risk SaaS tools. If you cannot reconcile entitlements in those systems, the rest of your inventory is usually too weak to trust.
What to verify: Confirm that each detected permission can be tied to an owner, an approval path, and a current business need. Any entitlement that is only explainable through a stale group, inherited role, or forgotten token should be treated as suspect until it is validated.
Common mistake: Treating directory sync as proof of control. Sync tells you what should have happened in IAM, not what the application still permits after local grants, delegated admin changes, or API token creation.
Practitioner takeaway: The real control is not discovering every permission once, but maintaining a live reconciliation loop between source identity data and the app’s effective authorization state.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org