Automation should come first for recurring machine connections and vendor access because OT teams cannot sustain manual review of every session without creating friction. Manual reviews still matter for exceptions, critical changes and high-risk links, but the baseline needs continuous control. Otherwise, review cycles will always lag behind the pace of operations.
Why OT access reviews should be automated first
OT access review is not just an administrative task, it is part of keeping plant access current in an environment where connections, vendors and support accounts change faster than review cycles. Automation gives you a continuous baseline, while manual review remains the exception path for atypical access, critical changes and high-risk relationships.
The practical reason is scale and timing. OT teams usually face recurring machine connections, scheduled maintenance windows and third-party support that cannot wait for periodic spreadsheet-style certification. A continuous review approach also fits better with OT and ICS Identity and Access Guide because OT access governance depends on knowing who, or what, is connected, when, and for how long.
Automation is strongest when the access pattern is repeatable and the decision rule is clear: a known vendor connection, a standard service account, or a machine-to-machine path can be checked against policy every time it appears. Manual review still has value, but only when human judgement is needed to interpret the business justification, confirm a compensating control, or approve a deviation from normal operating conditions.
Where manual review still earns its place
Manual access review should focus on the cases where the risk is not fully machine-readable. That includes emergency access, unusual remote support, shared accounts, temporary plant changes, and links that bridge IT and OT zones. Those are the situations where the reviewer needs context, not just a checklist.
Good OT review design also needs lifecycle discipline. A useful control stack combines recurring automated checks with periodic human validation of ownership, rotation, and removal, which is why NHI Lifecycle Management Guide is relevant even in OT, because stale access is usually a lifecycle failure before it is a review failure. The same logic appears in IAM and IGA Basics, where access review is treated as part of continuous governance rather than a once-a-quarter ceremony.
For vendor access, the key judgement is whether the connection is both expected and bounded. If the access is recurring, approved and technically constrained, automation should carry the baseline. If the access is one-off, privileged, or tied to a production fault, manual review should verify the scope and end condition before it is trusted.
What the right OT access model looks like in practice
The best OT model does not choose automation or manual review as an either-or. It uses automation to keep the normal case clean, then reserves manual attention for edge cases where risk, safety or operational impact is materially higher. That is especially important where access is mediated by third parties or where an account can be reused across multiple sessions.
This is why Privileged Access Management Guide matters to the question: privileged OT access should be time-bounded, session-aware and reviewable, not merely recorded after the fact. When the organisation can pair automation with strong session controls, review effort moves away from rote approvals and toward actual exception handling.
It is also worth separating access review from access cleanup. Review tells you whether access should continue; lifecycle controls tell you whether old access has already become stale. In OT, the gap between those two steps is where unnecessary exposure tends to accumulate.
Risk and Threat Considerations
Manual-only access review creates lag, and in OT that lag can leave vendor accounts, shared support credentials or machine connections active long after they should have been removed. Automation reduces that exposure, but if it is too permissive it can also normalize excess access and hide unusual relationships that deserve human scrutiny.
Failure mechanism: Periodic review misses fast-changing OT connections, while weak automation rubber-stamps recurring access without confirming whether the path is still needed, bounded, and owned.
Impact: Stale or overbroad access can expand blast radius, weaken segmentation, and give an attacker or careless vendor a standing route into critical systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | OT access reviews depend on controlling account and credential lifecycle, including rotation and revocation. |
| AC-2 — Account Management | The question is about reviewing whether OT access remains appropriate across recurring connections and vendors. | |
| AC-6 — Least Privilege | OT automation should limit standing access so recurring sessions do not become excessive privilege. | |
| Recommendation — Enforce IA-5 to review, rotate, and revoke OT credentials on a defined lifecycle. Use AC-2 to automate account review, disable stale access, and keep owners accountable. Apply AC-6 to bound OT access and keep vendor and machine permissions minimal. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | OT access review is fundamentally about managing who can connect and when. |
| Recommendation — Use CIS-6 to automate access review and remove unnecessary OT access promptly. | ||
| NIST Zero Trust (SP 800-207) | 1 — All Data Sources and Computing Services Are Accessed Securely | OT access should be continuously verified rather than trusted because connections are recurring and high impact. |
| Recommendation — Apply zero trust to require continuous verification for OT connections and exceptions. | ||
Practitioner Guidance
What to prioritise: Automate the repeatable baseline first, including recurring vendor access, standard machine connections, and known service paths. Reserve manual review for exceptions, emergency access, and any link that crosses a trust boundary or supports production control.
What to verify: Each automated rule should have a clear owner, an expiry or review trigger, and an obvious remediation path when access is no longer justified. If the review process cannot show removal as well as approval, it is not closing the loop.
Common mistake: Treating manual certification as the primary control in an OT environment usually turns review into a lagging record-keeping exercise. The better question is whether the control can keep pace with operational change without creating unsafe friction.
Practitioner takeaway: In OT, automation should carry the steady-state access burden, while manual review should be reserved for the decisions where context, exception handling, and operational judgement actually change the outcome.
Related resources from NHI Mgmt Group
- How should security teams run access reviews for non-human identities?
- How do organisations decide whether to prioritise access reviews, lifecycle automation, or shadow IT detection first?
- Should organisations prioritise lifecycle automation or manual reviews for non-human identities?
- How should security teams prioritise NHI remediation in cloud environments?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org