Security teams should automate provisioning around authoritative identity sources, enforce policy checks before access is granted, and validate role assignments against segregation of duty rules. The goal is to reduce manual inconsistency across onboarding, transfers, promotions, and offboarding while preserving auditability. A strong process correlates identity data from HR and other systems before accounts are created or changed.
Why This Matters for Security Teams
ERP provisioning looks simple until identity changes start touching finance, procurement, payroll, and reporting at the same time. If access is granted first and validated later, small mapping errors can create toxic combinations, delayed revocation, or roles that bypass segregation of duty controls. Current guidance from the NIST Cybersecurity Framework 2.0 and NHIMG’s Lifecycle Processes for Managing NHIs points to the same operational reality: provisioning must be policy-aware, not just automated.
The risk is not limited to incorrect human access. ERP platforms often trigger downstream service accounts, API integrations, approval bots, and scheduled jobs, so a single user change can widen the blast radius if policy checks are weak. That is why authoritative sources, pre-access validation, and auditable change trails matter as much as speed. NHIMG’s Top 10 NHI Issues highlights how quickly identity sprawl turns into control failure when lifecycle governance is inconsistent. In practice, many security teams discover toxic ERP entitlements only after an audit finding or post-incident review, rather than through intentional prevention.
How It Works in Practice
The safest pattern is to treat HR or workforce data as the trigger, not the source of truth for access. Identity governance tools should ingest authoritative attributes, evaluate them against policy, and only then create or modify ERP access. That means the provisioning workflow should verify job code, location, manager, legal entity, and SoD constraints before any account is issued. If the request fails policy, the change should stop and route for review rather than being fixed manually afterward.
In mature environments, the workflow also distinguishes between human accounts and dependent machine identities. ERP access often includes integration credentials, batch jobs, or file-transfer accounts, so the provisioning process should check both user entitlements and any connected NHIs. NHIMG’s NHI Lifecycle Management Guide is useful here because the same lifecycle discipline applies: create, approve, rotate, monitor, and revoke based on business need. For control design, NIST SP 800-53 Rev. 5 Security and Privacy Controls supports least privilege, separation of duties, and account lifecycle review.
- Use authoritative identity sources such as HR, IAM, and finance master data before provisioning.
- Map job attributes to pre-approved ERP roles, not to ad hoc named access.
- Run SoD checks and approval rules before account creation or role expansion.
- Log the source attribute, policy decision, approver, and effective time for every change.
- Revalidate access on transfers, promotions, and leaves, not only at onboarding.
NHIMG research shows only 5.7% of organisations have full visibility into their service accounts, which is why ERP provisioning should include any service identities that inherit or act on behalf of a user. These controls tend to break down when ERP role catalogs are outdated, because policy engines can only enforce what the business has actually maintained.
Common Variations and Edge Cases
Tighter provisioning often increases workflow overhead, requiring organisations to balance speed against assurance. That tradeoff becomes most visible in subsidiaries, shared services, and emergency-access scenarios where business owners want fast approvals but security teams need hard policy gates. Best practice is evolving, but there is no universal standard for how much manual override is acceptable in ERP environments; the practical answer depends on risk appetite and audit expectations.
One common edge case is temporary access for finance close, acquisition activities, or regional reporting cutovers. Those requests should use time-bound entitlements with explicit expiry rather than permanent role changes. Another edge case is delegated administration, where a local ERP admin can assign access inside the system after the central IAM workflow has approved only part of the change. That split control creates policy gaps unless the ERP-side action is also constrained and logged. NHIMG’s Regulatory and Audit Perspectives and the Coupang Signing Key Breach both reinforce the same lesson: lifecycle failures and overly broad trust assumptions create audit and security exposure fast. Current guidance suggests treating exceptions as exception-managed events with expiry, evidence, and post-use review. The model breaks down in highly customised ERP instances where role design is inconsistent across business units and policy rules cannot be standardised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Provisioning gaps often create over-privileged NHIs linked to ERP users. |
| OWASP Agentic AI Top 10 | Automated provisioning logic can act like an autonomous agent with tool access. | |
| CSA MAESTRO | MAE-03 | Covers governance for automated workflows that change identity and access state. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access control is central to safe ERP provisioning. |
| NIST AI RMF | Risk governance applies when automation makes access decisions at scale. |
Use AI RMF governance to document decision logic, oversight, and exception handling for automated provisioning.
Related resources from NHI Mgmt Group
- How should security teams modernize user access requests without creating new governance gaps?
- How should security teams streamline Separation of Duties reporting in complex ERP environments?
- How should security teams use JIT provisioning without creating offboarding gaps?
- How should teams migrate endpoint policies from Group Policy and SCCM to Intune without creating security gaps?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org