Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should teams review agency access in marketing…
Governance, Ownership & Risk

How should teams review agency access in marketing platforms?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

They should review access against current contracts, current campaigns, and current business ownership, not against historical convenience. If the person or agency cannot be tied to active work, the default should be removal until the entitlement is re-approved.

How to review agency access without relying on history

Agency access should be treated as time-bound business access, not a permanent relationship. Reviewers need to ask whether the agency is still performing active work, whether that work matches the current contract, and whether the access is still justified by a live campaign or service line. If the business owner cannot defend the entitlement with current need, it should be removed and re-approved only when the need is re-established.

That approach matters because marketing platforms often accumulate access for analytics, publishing, ad operations, creative approvals, and vendor support. Those roles can stay open long after the original engagement changes, especially when campaign ownership moves between teams or agencies. A review that starts from the current operating model is more likely to catch access that has become idle, excessive, or misassigned.

For teams building the review criteria, NHIMG’s Access Reviews and Certification Guide is a useful model for making reviews evidence-based rather than ceremonial. It aligns well with a campaign-led review because the question is not whether access once made sense, but whether it still maps to a present-day business purpose.

What counts as a valid justification in marketing platforms

A valid justification should connect the person or agency to something operationally current and observable. In practice, that means one of three things: an active contract or statement of work, an active campaign or workstream, or a current business owner who can explain why the access remains needed. Vague references to “we have always used them” or “they may need it later” are weak signals and should not survive review on their own.

The platform also matters. Some marketing tools mix content publishing, audience data, ad spend, analytics, and permissions to external agencies. That means the reviewer should test not only whether the account is still needed, but whether the level of access still matches the actual duty. A content agency may need publishing rights, but not billing, audience export, or admin functions. That is why access review and entitlement review need to be paired with a role-level check, not handled as a simple name-by-name list.

NHIMG’s IAM and IGA Basics helps anchor that distinction between access request, entitlement, and ongoing governance. For teams with mixed human and vendor access, the same review logic should be applied consistently to all entitlements, not only staff accounts.

How to make removal the default when ownership is unclear

The safest operating rule is to treat unclear ownership as a reason to remove access, then restore it only after re-approval. That is especially important in agencies because the original requester, day-to-day user, and business sponsor are often different people, and one of them may have changed without the platform record being updated. When no current owner can attest to the need, the entitlement is effectively unactionable, even if it is still technically functioning.

This is where lifecycle discipline matters. Access should be reviewed on a schedule that matches campaign turnover and vendor change, not just annual audit timing. If a platform supports multiple brands or regions, the review should also confirm whether access is tied to one workstream that has ended while another remains active. The review outcome should be explicit: keep, reduce, or remove, with removal being the default for anything that lacks current justification.

NHIMG’s NHI Lifecycle Management Guide is relevant here because lifecycle control is what prevents stale access from becoming accepted normality. For agency access, the practical lesson is the same: if no active purpose can be demonstrated, the entitlement should not persist by inertia.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAgency access needs periodic review, reapproval, and removal when no longer justified.
AC-6 — Least PrivilegeMarketing platform entitlements should match current campaign duties, not historical convenience.
IA-5 — Authenticator ManagementAgency access depends on managing credentials and revocation when access is removed.
Recommendation — Review and disable agency accounts that no longer have a current business need. Limit agency permissions to the minimum needed for active campaign tasks. Revoke or rotate credentials tied to agencies when entitlement is withdrawn.
ISO/IEC 27001:2022A.5.15 — Access controlCurrent-business-based review is an access control decision for third-party users.
A.5.18 — Access rightsPeriodic review and removal of stale agency rights is directly about access rights governance.
Recommendation — Apply access control rules that require current justification for agency access. Recertify and remove agency rights that no longer map to active work.

Practitioner Guidance

What to prioritise: Start with the highest-risk agency entitlements first, especially accounts that can publish, spend, export data, or change configuration. Those permissions create the biggest blast radius if they outlive the business need.

What to verify: Ask for current contract coverage, named business owner, and the specific campaign or service currently supported. If any of those are missing, treat the access as unsubstantiated until proven otherwise.

Common mistake: Teams often review access against the original onboarding record instead of current business reality. That turns recertification into a historical check and leaves dormant agency access in place long after the work has ended.

Practitioner takeaway: The best review decision is usually the simplest one, keep only what can be tied to live work today, and remove everything else until someone explicitly re-justifies it.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org