Removal comes first when the access no longer supports a business purpose, because reviewing dead access preserves unnecessary risk. Review matters for active permissions, but stale entitlements should be retired as soon as they are identified. The two controls work together, yet revocation is the faster way to shrink exposure.
Why the sequence matters: dead access vs active entitlement decisions
Removal should be the first move when the entitlement is no longer needed. access review is a judgment step for permissions that may still have a business purpose, but it does not by itself reduce exposure when the entitlement is already obsolete. In practice, review and removal are complementary, yet retirement is the faster way to shrink blast radius.
When access is stale, every extra day increases the chance that an unused permission becomes the path for misuse, lateral movement, or simple policy drift. That is why lifecycle cleanup and certification should be treated as related controls, not competing ones. A review can confirm whether an active entitlement should stay; removal eliminates the risk carried by dead access.
Where entitlement removal belongs in the lifecycle
Entitlement removal is strongest when the issue is obvious: a leaver, a role change, a decommissioned system, a duplicate account, or a permission that no longer maps to a current duty. In those cases, waiting for the next review cycle just preserves unnecessary access. The correct order is to remove the entitlement first, then let the next review process validate what remains.
This also applies when teams discover access during inventory, reconciliation, or audit preparation. If the permission is not justified now, it should not survive as a “to be reviewed later” item. Joiner-Mover-Leaver (JML) Guide and NHI Lifecycle Management Guide both reflect the same operational reality: lifecycle hygiene is what keeps access from becoming long-lived by accident.
How review should be used once removal has handled the obvious cases
Access review is still essential, but its best role is to arbitrate remaining entitlements that are active, ambiguous, or high impact. It helps separate justified permissions from excess permissions, especially where ownership, business purpose, or exception handling is unclear. Review is slower than removal, but it adds governance value when the access is still in use and the business consequence of a mistake is real.
That is why entitlement review should focus on decision quality, while removal focuses on exposure reduction. A good process uses both: remove what is clearly dead, then review what is still alive and potentially legitimate. The supporting control set is broader than one workflow, as shown in Access Reviews and Certification Guide and IAM and IGA Basics, which both connect review with entitlement governance rather than treating it as a standalone event.
Risk and Threat Considerations
Stale entitlements create avoidable exposure because they expand the set of identities, roles, and paths an attacker can abuse after an account or process should have been constrained. The longer dead access remains, the more likely it is to be forgotten, over-relied on, or inherited by another workflow.
Failure mechanism: organisations defer revocation until a review completes, so obsolete permissions remain active long enough to be exploited, reused, or inherited by downstream systems.
Impact: the environment retains unnecessary privilege, enlarges the attack surface, and increases the chance that a compromised identity or stale credential can reach data or systems it should no longer touch.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Entitlement removal is an account lifecycle control for unused or stale access. |
| AC-6 — Least Privilege | Removing unnecessary entitlements directly reduces excess privilege and exposure. | |
| Recommendation — Revoke obsolete access promptly under AC-2 and keep only current, approved entitlements. Apply AC-6 to remove permissions that no longer support a current business need. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights management covers granting, reviewing and revoking entitlements. |
| A.8.2 — Privileged access rights | Stale privileged entitlements are especially risky and should be removed first. | |
| Recommendation — Use A.5.18 to remove obsolete access before the next review cycle. Remove unused privileged access immediately under A.8.2 and review what remains. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account and entitlement hygiene requires prompt revocation of access no longer needed. |
| Recommendation — Use CIS-5 to disable or remove unneeded access before certification reviews. | ||
Practitioner Guidance
What to prioritise: remove entitlements immediately when the business need is gone, then queue the residual active permissions for review. If the access is already dead, do not wait for certification to do a job revocation can complete now.
What to verify: confirm there is a current owner, a current business purpose, and a current dependency before preserving any entitlement. If any one of those is missing, treat the permission as a removal candidate rather than a review candidate.
Practitioner takeaway: the fastest risk reduction comes from eliminating access that should not exist, while review is reserved for access that still might.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise secret rotation or access review first
- Should organisations prioritise access review or lifecycle automation first?
- Should organisations prioritise supplier access review or perimeter hardening first?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org