Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations prioritise live access visibility over periodic…
Governance, Ownership & Risk

Should organisations prioritise live access visibility over periodic spreadsheet reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Yes. Live visibility should come first when SaaS estates are large or permissions change frequently, because periodic review alone cannot keep pace with identity churn. Once authoritative current-state visibility exists, periodic certification becomes an oversight activity rather than the primary control.

Why live access visibility should come before spreadsheet reviews

Periodic spreadsheets are a lagging control: they can only tell you what access looked like when the review ran. Live visibility gives you the current state of accounts, entitlements, and ownership, so you can spot drift, orphaned access, and fast-changing privilege before the next certification cycle. In large SaaS estates, that difference is operational, not cosmetic.

When access changes frequently, the review process itself becomes part of the problem if it relies on stale exports and manual reconciliation. The control objective is not to make spreadsheets more polished, but to reduce the time between a permission change and the point at which someone can actually see it.

That is why authoritative current-state visibility is the better foundation for recertification. It turns certification into a verification layer over an already-known inventory, rather than a substitute for discovery.

What live visibility changes in the access governance model

Live access visibility changes the governance question from “who was approved last quarter?” to “who has access right now, why do they have it, and is it still justified?” That matters when permissions are additive, temporary, inherited from groups, or created by automation, because a static review can miss the path that produced the effective access.

It also improves the quality of access reviews themselves. Reviewers can make decisions faster when the system shows current entitlements, active usage, owner, and privilege context in one place, instead of forcing them to reconstruct the state from multiple spreadsheets and ticket trails. See Access Reviews and Certification Guide for a deeper treatment of how to make reviews remove access rather than merely reapprove it.

For programmes that manage both human and non-human access, visibility also needs to cover service accounts, integrations, and automation paths, because they can hold standing privilege long after the original business use case has changed. A current inventory is what lets governance teams separate harmless access from access that has quietly become excessive. IAM and IGA Basics explains how provisioning, entitlements, and review fit together across people and machines.

Why the right sequence is visibility first, certification second

The practical sequence is simple: discover and normalise the live access picture first, then run periodic certification against that source of truth. If you do the reverse, reviewers end up certifying snapshots, not authority, and the organisation learns too late that the spreadsheet never matched production.

This sequence becomes even more important when access churn is high, because new apps, role changes, contractor turnover, and emergency access all create short-lived states that periodic review can miss. Once visibility is in place, the review cadence can be chosen for oversight and accountability, not for basic discovery.

That is also why lifecycle discipline matters. NHI Lifecycle Management Guide is useful here because lifecycle controls only work when discovery, ownership, and offboarding are visible enough to act on, not merely documented after the fact.

Risk and Threat Considerations

Spreadsheet-only review creates blind spots between review cycles, especially in environments where access is granted by automation, inheritance, or delegated administration. The result is stale approval evidence, delayed revocation, and a higher chance that excessive privilege persists long enough to be abused.

Failure mechanism: Manual review sees an outdated export, misses a recent entitlement change, and leaves orphaned, overprivileged, or dormant access in place until the next cycle. Attackers and careless insiders benefit from the gap between change and detection.

Impact: Excess access can survive multiple business changes, increasing the blast radius of account compromise, privilege misuse, and audit failure. In practice, that means the organisation may be certifying yesterday’s access while production already moved on.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementLive access visibility and certification are core IAM governance concerns.
Recommendation — Implement IAM controls to maintain current entitlement visibility before periodic access certification.
NIST SP 800-53 Rev 5AC-2 — Account ManagementCurrent account and entitlement visibility supports ongoing account governance and review.
AC-6 — Least PrivilegeLive visibility helps identify overprivilege and reduce standing excess access.
Recommendation — Maintain authoritative account inventories and review them continuously. Use least-privilege checks to remove excess access revealed by current-state visibility.
ISO/IEC 27001:2022A.5.18 — Access rightsPeriodic review versus current access state maps directly to access rights governance.
Recommendation — Review access rights from a current authoritative source before recertification.
CIS Controls v8CIS-6 — Access Control ManagementThe question concerns how to govern and review access at scale.
Recommendation — Centralise access control management and keep inventories current for timely review.

Practitioner Guidance

What to prioritise: Build a reliable live inventory of effective access first, including inherited permissions, privileged roles, and service or automation accounts. If you cannot answer “who has what right now” with confidence, the review process is already behind.

What to verify: Check that the live source is authoritative for the systems being reviewed, that ownership is assigned, and that the feed captures changes fast enough to matter. A good certification campaign starts with evidence that the inventory and entitlement model match production state.

Practitioner takeaway: Use periodic reviews as an accountability layer, but treat live visibility as the control that makes those reviews trustworthy in the first place.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org