Security teams should move from periodic reviews to continuous, data-driven governance. The practical shift is to maintain live entitlement data, continuously discover identities, and enforce policy based on current context rather than stale certification snapshots. That approach reduces overprovisioning, shortens exposure windows, and lets governance keep pace with decentralized SaaS, distributed work, and fast-changing machine identity populations.
Why access governance has to become continuous
When SaaS sprawl and non-human identity growth outpace periodic reviews, the core problem is not just review speed, it is that the entitlement picture is already stale by the time certification starts. Modern access governance has to behave like an always-current control plane: discover identities continuously, normalise entitlement data across services, and make policy decisions against the present state rather than a quarterly snapshot.
That shift matters because decentralized SaaS and machine-heavy automation create fast-changing access relationships. A control that depends on manual sampling will miss short-lived privileges, unused but still active accounts, and cross-tool entitlements that never appear in a single source of truth. The practical objective is to reduce standing exposure, not merely to document it after the fact.
One useful indicator of why this matters is the scale of the population itself. The NHI and Secrets Risk Report notes that NHIs now outnumber human identities by 144:1 in enterprise environments, which helps explain why periodic certification models break down under modern operating conditions.
What changes in the operating model
The governance model changes from reviewing entitlements at rest to managing them in motion. That means three capabilities become central: continuous identity discovery, entitlement context enrichment, and policy automation that can interpret current risk signals such as owner, workload, app, environment, and usage pattern. Without those inputs, a reviewer is forced to approve or revoke access based on incomplete context.
For SaaS estates, this usually requires consolidating data from IdP, SaaS admin APIs, SCIM, cloud control planes, and ticketing or approval workflows so the governance function can see actual access rather than inferred access. For non-human identities, the same principle applies, but with extra attention to lifecycle events, credential age, and whether an account is still tied to an active workload or integration.
Manual certification can still have a role, but it should be reserved for exceptions, high-impact approvals, and ambiguous entitlements that automation cannot classify confidently. When teams try to force every decision through human review, they typically create backlogs, defer revocations, and leave orphaned or overprivileged access in place longer than intended.
Several internal guides map directly to this operating model: NHI Lifecycle Management Guide is the best fit for provisioning, rotation, offboarding and visibility, while Ultimate Guide to NHIs provides the broader governance and access-governance foundation that continuous certification depends on.
How to make governance fast enough to be useful
The practical target is not to eliminate review, but to make review risk-based. Teams should prioritise the identities and entitlements with the largest blast radius, the least reliable ownership, or the weakest lifecycle discipline, and let low-risk, well-understood access follow an automated or semi-automated path. That creates room for deeper human scrutiny where it matters instead of spending equal effort on every account.
- Anchor certification to current source data, not spreadsheet extracts or annual export files.
- Use entitlement ageing, inactivity, privilege level, and environment sensitivity to triage review queues.
- Require explicit ownership for SaaS apps and machine identities so revocation and recertification decisions are actionable.
- Escalate exceptions when access cannot be tied to a live business or workload need.
Practitioner takeaway: The winning model is not “more reviews”, it is “better facts with narrower human judgment”, so the control can keep pace with SaaS drift and NHI growth without turning governance into a bottleneck.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 5 — Account Management | Directly governs review and removal of stale or excessive access across SaaS and NHI estates. |
| CIS Control 6 — Access Control Management | Fits continuous enforcement of current entitlement context instead of periodic snapshot approvals. | |
| CIS Control 8 — Audit Log Management | Supports governance by proving who had access, when it changed, and whether revocation happened in time. | |
| Recommendation — Automate account review and revoke unused or excessive access before it accumulates. Apply access policy continuously using live identity and entitlement context. Centralise access evidence so certification decisions and revocations are traceable. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Addresses managing identity lifecycle and access decisions with current assurance and least privilege. |
| GV.OV — Oversight | Fits governance models that replace manual review cadence with continuous oversight of access posture. | |
| Recommendation — Implement identity and access controls that stay aligned with current risk and business need. Use continuous oversight to monitor access posture and governance exceptions. | ||
| NIST Zero Trust (SP 800-207) | POL — Policy Engine and Continuous Evaluation | Directly supports policy decisions based on live context rather than stale certification snapshots. |
| Recommendation — Evaluate access continuously against current context before allowing or renewing it. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Relevant because NHI governance depends on controlling the credentials that enable machine access. |
| NHI-03 — Identity Lifecycle Management | Directly matches continuous discovery, review, and revocation of machine and SaaS identities. | |
| NHI-04 — Least Privilege and Permission Management | Supports reducing overprovisioning by aligning access with present need. | |
| Recommendation — Track and govern the credentials that underpin non-human access. Continuously discover, review, and deprovision non-human identities and their entitlements. Minimise standing privilege and remove excess entitlements as soon as they are identified. | ||
Related resources from NHI Mgmt Group
- How should security teams make NHI best practices usable across the business?
- What is the difference between role-based access and API key governance for NHI security?
- How should security teams use IAST and RASP in NHI governance?
- How should IT teams automate identity lifecycle when app sprawl and frequent role changes make manual provisioning too slow?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org