Security teams should use activity data as evidence of whether an entitlement is actually exercised before they renew it. Usage frequency, recency and peer comparison help reviewers distinguish necessary access from access that persists only because nobody can see it being used. That makes certification decisions more defensible and less dependent on guesswork.
How activity data should shape an access certification review
Activity data should be treated as one of the strongest signals in certification because it shows whether access is actually being used, not just whether it exists on paper. The point is to test entitlement necessity with observable behaviour. That makes the review more defensible, helps reviewers spot stale or duplicate access, and reduces the tendency to renew rights by default.
Which activity signals matter most
Not all activity data is equally useful. Usage frequency, recency, and peer comparison are the most practical starting points because they answer different questions: is the access used at all, was it used recently, and is the pattern normal for a similar role or team. A single log line is rarely enough on its own, but a consistent pattern of low or absent use is strong evidence for challenge or removal.
Teams should also distinguish between direct business use and incidental technical noise. Service integration chatter, background syncs, or inherited platform activity can make an entitlement look active when the underlying human or workflow need has changed. Good reviewers look for evidence that the entitlement supports the expected job function, not merely that some system touched it.
When activity is available, use it to separate three outcomes: retain, challenge, or remove. A clearly exercised entitlement can be renewed with higher confidence; an entitlement with weak or ambiguous activity should be challenged for business justification; an entitlement with no meaningful activity should be removed unless there is a documented future need. Access Reviews and Certification Guide is useful here because it emphasises context and closed-loop review rather than rubber-stamping.
How to avoid misleading conclusions from activity data
Activity data is evidence, not a verdict. A role can be legitimately unused for a period because the owner is on leave, because access is only exercised during exceptions, or because a control is designed for rare events. The reverse is also true: recent use does not automatically justify broad entitlements if the activity is narrow and the entitlement is much larger than the task actually required.
Security teams should compare activity with scope. If the user only ever accesses one application object, one environment, or one function, that may support a narrower entitlement than the one currently certified. This is where peer comparison helps: it shows whether the access pattern aligns with similarly situated users or whether the entitlement is an outlier that deserves review.
Use activity data as a prompt to improve entitlement design as well as certification decisions. If reviewers repeatedly see broad access for narrow use, the real issue may be role design, inherited permissions, or poor entitlement packaging. In that case, recertification should feed role cleanup, not just another yes-or-no renewal.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Activity data in certification depends on reviewing audit evidence of entitlement use. |
| AC-2 — Account Management | Access certification is part of account and entitlement lifecycle governance. | |
| Recommendation — Use audit evidence to support entitlement renewal decisions and investigate unused access. Review and recertify accounts and entitlements on a defined cadence and remove unneeded access. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Certification decisions directly govern who should retain access rights over time. |
| Recommendation — Periodically review access rights and revoke entitlements that are no longer justified. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access reviews use observed activity to validate and reduce unnecessary access. |
| Recommendation — Review access use regularly and remove privileges that are not needed or exercised. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Access Management | Certification uses activity evidence to govern access entitlement validity. |
| Recommendation — Validate access entitlement necessity before renewing or expanding it. | ||
Practitioner Guidance
What to verify: Confirm that the activity source is tied to the entitlement being certified, not just to the account in general. A useful review should be able to explain why the entitlement was used, when it was used, and whether that usage matches the business purpose of the access.
What to measure: Track the share of renewals supported by recent, entitlement-specific activity versus renewals approved without evidence. If the latter remains high, the process is still too dependent on memory, manager guesswork, or reviewer fatigue.
Common mistake: Do not treat any activity as sufficient justification. Reviewers often renew access because they see some login or system interaction, even when the entitlement is much broader than the observed use. The better question is whether the entitlement itself is still needed in its current form.
Decision rule: If activity is absent or weak and there is no documented exception use case, treat the entitlement as a removal candidate rather than asking the reviewer to prove a negative. If activity is present but narrowly scoped, consider whether the entitlement should be reduced instead of renewed unchanged.
Practitioner takeaway: Activity data is most valuable when it changes the decision from “does this person have access?” to “does this specific entitlement still earn its place?”
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org