Treat incomplete activity data as a governance constraint, not just a reporting problem. If current use cannot be observed, certification and vaulting decisions should be flagged as low-confidence. Teams need to correlate entitlement state with runtime evidence before deciding whether an account is dormant, active, or risky.
Why incomplete activity data changes the identity decision
When activity telemetry is partial, the decision is no longer simply whether an account exists, but whether there is enough evidence to treat it as active, dormant, or risky. That shifts governance from a reporting exercise to an evidence-quality problem. The right posture is to avoid overconfident certification when runtime use cannot be verified.
Incomplete data usually means one of three things: the identity has weak observability, the logs do not cover all relevant systems, or the account is used in ways the current telemetry cannot see. In each case, the governance issue is the same, the team is making a privilege or vaulting decision without a trustworthy activity signal.
For that reason, identity data quality and identity fabric practices matter here because they improve correlation across sources, reduce ambiguity in entitlement review, and make it easier to separate truly dormant access from simply unobserved activity. The same logic is reflected in identity security programme governance, where ownership, evidence standards, and review thresholds need to be explicit.
How to classify uncertainty in dormant, active, and risky accounts
The practical mistake is to force a binary answer when the evidence is insufficient. If an account has entitlements but no observable usage, the question is not only "Is it active?" but "Can we prove it is safe to keep?" Low-confidence states should be treated as a distinct governance outcome, especially where the account can reach sensitive systems or vaults.
Teams should correlate entitlement state with runtime evidence before making a decision. Entitlements tell you what the account could do; runtime evidence tells you what it actually did. When those signals disagree, the account may still be legitimate, but the decision to keep it certified should be conservative until the missing evidence gap is explained.
Identity correlation becomes the deciding mechanism in this step, because it links records across authoritative sources, access systems, and logs. Where correlation is weak, the team should not pretend certainty exists; it should classify the account as unresolved and route it for further validation.
What governance should require before certification or vaulting decisions
Governance should define what evidence is sufficient, which systems are in scope, and what happens when evidence is missing. A sound review process does not assume that "no activity seen" equals "safe to certify." It requires a documented fallback for incomplete data, including additional validation, exception handling, or a shorter review interval.
For high-value accounts, vaulting or retention decisions should also consider whether the account has been observed under the relevant workload conditions, not just whether it appears unused in one system. If the account sits behind a vault or rotation process, the decision should reflect the quality of the evidence supporting continued access, not the convenience of leaving credentials in place.
NHI lifecycle management is useful here because it ties provisioning, rotation, offboarding, and visibility into one governance model. Regulatory and audit perspectives also matter when decisions must be defensible, because auditors will usually care about whether teams had evidence, not whether the access review felt reasonable.
Risk and Threat Considerations
Incomplete activity data creates a blind spot that can hide stale access, excessive privilege, or compromised accounts. The risk is not just missed reporting, but the possibility that an apparently quiet identity is still able to reach critical systems or secrets.
Failure mechanism: A team treats missing telemetry as proof of inactivity, or it approves access on partial evidence, so dormant, abused, or hidden use remains unchallenged.
Impact: Unnecessary access persists, compromised credentials remain viable longer, and governance decisions lose credibility because they are based on incomplete observation rather than verified behaviour.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Incomplete activity data makes audit review and correlation central to identity decisions. |
| IA-5 — Authenticator Management | Low-confidence identity decisions often hinge on lifecycle and trust in credentials or authenticators. | |
| Recommendation — Correlate entitlement changes with audit evidence before certifying access. Track credential lifecycle evidence before treating an account as safely dormant. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Governance of incomplete activity data directly affects access decisions and review thresholds. |
| A.8.15 — Logging | The question centers on incomplete activity data and the need to judge confidence in observed use. | |
| Recommendation — Define access review rules that require evidence before continued approval. Ensure logs cover the systems needed to support identity recertification decisions. | ||
| CIS Controls v8 | CIS-5 — Account Management | Dormancy, recertification, and retention decisions are account-management issues when activity evidence is weak. |
| Recommendation — Review accounts using evidence-based dormant-access criteria and exception handling. | ||
Practitioner Guidance
What to verify: Before certifying an account, verify whether the telemetry gap is a logging problem, a correlation problem, or a genuine absence of use. If the team cannot explain the gap, it should not treat the account as low risk.
Decision rule: If runtime evidence is missing for a privileged or vault-connected account, classify the decision as low-confidence and require additional corroboration before retention, recertification, or exemption.
What practitioners underestimate: The hardest cases are not obviously active or obviously dormant, they are the identities that are partially observed. Those are the ones most likely to produce false reassurance if governance relies on a single source of truth.
Practitioner takeaway: The objective is not to force a certainty label, but to make uncertainty visible enough that access decisions stay conservative until entitlement state and observed use line up.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org