Organisations should move from periodic manager sign-off to authorization decisions made at the moment of each request. That approach evaluates current attributes, context, and policy every time access is requested, so the decision reflects present risk rather than a stale review. For sensitive environments, continuous authorization is a stronger control than a monthly or quarterly recertification report.
From periodic recertification to request-time authorization
Manual recertification is a backward-looking control: it asks whether access still looked appropriate at some review date. Continuous policy-driven authorization changes the control point to the moment of use, so the decision is based on current identity attributes, device state, environment, role, data sensitivity, and policy conditions. That shift is most valuable where access conditions change quickly or where stale approval creates avoidable exposure.
A practical implementation usually separates entitlement administration from runtime decisioning. Recertification can still clean up dormant or obviously excess access, but it should no longer be the main control for approving active use. The operational goal is to make access eligible only when policy allows it, rather than trusting a prior human review to remain valid until the next cycle.
When organisations make this transition well, they reduce approval lag without weakening control. It also gives security teams a clearer decision record, because each request can be evaluated against the current policy context instead of a spreadsheet or ticket that may already be out of date.
What continuous authorization must evaluate
Policy-driven authorization is only strong if it looks at the signals that actually change risk. Typical inputs include the requesting user or workload, privilege scope, requested resource, time, location, device posture, network zone, business justification, and whether the access is interactive or automated. If the policy engine ignores context, the organisation has only replaced one manual step with another brittle rule set.
This is where authorization differs from periodic review. A reviewer can approve a general access relationship, but a request-time policy can deny a sensitive action in a low-trust context, shorten access duration, or require step-up checks for a high-risk operation. That makes the control dynamic rather than ceremonial. For broader identity governance foundations, the relationship between access review and runtime authorization is explained in IAM and IGA Basics, while lifecycle pressure points such as stale access and excessive permissions are covered in NHI Lifecycle Management Guide.
For organisations with machine-to-machine access, the same principle applies to service accounts, API clients, and automation. The policy should assess whether the request is coming from the expected workload, whether the secret or token is still valid, and whether the scope matches the requested action. Where access governance breaks down, the usual failure is not the absence of a review date, but the absence of a reliable decision context.
Operating model and control design for continuous authorization
To replace manual recertification cleanly, organisations need clear ownership, a policy source of truth, and measurable enforcement. The policy decision point should be authoritative for the protected resource, while entitlement systems, identity stores, and ticketing should feed it with current facts. If approvals are still needed for every routine request, the process has not really become continuous.
The most useful design pattern is to reserve human approval for exceptions, high-impact exceptions, or policy creation, not for every low-risk access event. That lets teams keep governance where judgment matters while letting policy handle repetitive decisions at scale. In practice, the success criterion is simple: can the organisation explain why a request was allowed or denied based on present conditions, not just who signed off last month?
For sensitive environments, the strongest model is to combine policy-driven authorization with short-lived access and tight scope. That reduces the blast radius of both mistakes and compromise, because access exists only while the policy says the current request is justified. Continuous authorization is therefore not just an IAM improvement, it is a stronger operational security posture when the access path itself is a meaningful risk surface.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Continuous authorization reduces reliance on periodic account review. |
| AC-3 — Access Enforcement | Request-time policy decisions enforce access at the moment of use. | |
| IA-5 — Authenticator Management | Continuous authorization depends on current credential validity and rotation. | |
| Recommendation — Use AC-2 to keep account review and removal tied to current access need. Apply AC-3 to enforce policy decisions before granting each request. Use IA-5 to manage authenticators so stale credentials do not outlive policy. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Continuous authorization is an access-control operating model for current decisions. |
| A.5.18 — Access rights | Replaces periodic access-rights attestation with ongoing entitlement decisions. | |
| Recommendation — Define access control rules that evaluate current conditions before granting use. Review access rights continuously and revoke access when policy conditions change. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | This topic centers on managing and enforcing access decisions over time. |
| Recommendation — Tighten access control management so approvals reflect current risk and need. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Access Management | Continuous authorization is an identity-access decision process at request time. |
| GV.RM-01 — Risk Management Strategy | The shift changes how organisations govern recurring access risk. | |
| Recommendation — Implement request-time access decisions that evaluate current identity and context. Set a risk strategy that favors live authorization over stale review cycles. | ||
Practitioner Guidance
What to prioritise: Start with the highest-risk access paths first, especially privileged, production, third-party, and automation-driven access. Those are the cases where stale recertification creates the most obvious gap between approval history and current risk.
What to verify: Before you retire recertification as the primary control, confirm that the policy engine has reliable inputs for identity, device, resource sensitivity, and time-bound context. If those signals are incomplete or inconsistent, continuous authorization will simply automate uncertainty.
Decision rule: If the access can materially change system state, expose sensitive data, or trigger downstream automation, require request-time policy evaluation and keep human review for exceptions rather than routine approvals.
Practitioner takeaway: The real transition is from trusting a prior approval to trusting a live decision process, so the control must be observable, policy-led, and narrow enough to deny access when present conditions no longer justify it.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on coarse access lists instead of policy-driven authorization?
- When should organisations replace access reviews with continuous validation for NHIs?
- How do policy-driven authorization controls improve access governance?
- How do policy-driven authorization and application code differ in access control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org