Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should SaaS access reviews be driven by usage…
Governance, Ownership & Risk

Should SaaS access reviews be driven by usage data or manager attestation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Usage data should lead, with attestation used as a backstop. Manager review alone often reflects organisational memory rather than current access reality, while telemetry can show inactive accounts, low-value licences, and stale entitlements. The strongest model combines both, but the evidence should come from observed use.

Usage Data vs Manager Attestation in SaaS Access Reviews

The better question is not which signal is “truer” in isolation, but which signal is operationally current enough to drive action. Usage data shows whether access is being exercised, while attestation can capture business context that telemetry cannot see. In practice, usage should lead the review, and manager attestation should confirm exceptions, edge cases, and ownership gaps.

Why Usage Data Is the Better Primary Signal

Usage data is closer to the actual control objective: remove access that is no longer needed. It can expose dormant accounts, low-value licences, stale entitlements, and accounts that exist only because no one has challenged them. That makes it more useful than memory-based review, especially where employees change teams, contractors leave, or applications accumulate old permissions over time.

A usage-led review also scales better because it starts with evidence, not recollection. For SaaS, this usually means login history, last activity, feature use, file access, API calls, or app-specific actions. The exact telemetry should match the access risk, because a simple login is not always enough to prove that an entitlement is still justified.

Access Reviews and Certification Guide and IAM and IGA Basics both reinforce the same operational pattern: reviews work best when they are evidence-led and tied to entitlement decisions, not treated as a paperwork exercise.

Where Manager Attestation Still Matters

Attestation still has value when usage is ambiguous or incomplete. A manager can confirm that an account is needed for a planned project, that a shared licence is intentionally quiet, or that a person has moved into a role where access is justified even before usage appears. It is also the fallback when telemetry is missing, when a SaaS product offers weak audit data, or when business ownership is unclear.

The danger is to use attestation as the starting point and then let it become a rubber stamp. Managers often approve access because they recognise the person, not because they can verify entitlement necessity. That is why attestation should be a backstop, not the primary proof of current need.

Identity Visibility and Intelligence Platforms (IVIP) Guide is useful here because it frames how activity, ownership, and access intelligence can reduce reliance on subjective review alone.

How to Run a Review Model That Actually Removes Access

Use usage data to pre-sort the review queue, then ask managers to confirm only the cases that need judgement. That means prioritising inactive accounts, high-risk entitlements, and access that has not been used for a defined period. It also means separating “no observed use” from “no business need”, because those are not always the same thing.

  • Review observed use first, then ask for attestation only where the telemetry is unclear.
  • Escalate stale or privileged access faster than ordinary low-risk access.
  • Require a named owner for shared SaaS accounts and service-style access.
  • Remove access when neither usage nor a timely business justification exists.

Joiner-Mover-Leaver (JML) Guide supports the lifecycle view here, while Privileged Access Management Guide is a useful companion whenever the SaaS access under review includes admin roles, break-glass paths, or other high-impact permissions.

Risk and Threat Considerations

When access reviews rely mainly on manager memory, organisations tend to keep stale entitlements alive longer than they realise. That creates exposure through dormant accounts, excess privilege, and accounts that outlive the business reason for their creation. In SaaS environments, that same weakness can also hide unmanaged third-party access or shadow use of licences and admin functions.

Failure mechanism: The review process confirms organisational familiarity instead of current access evidence, so inactive, mis-scoped, or overprivileged accounts survive multiple review cycles.

Impact: Unused access remains available for takeover, misuse, or lateral abuse, and the organisation pays for licences and entitlement risk it no longer needs.

MITRE ATT&CK Enterprise Matrix is relevant to the threat side because abandoned SaaS access and stale credentials are common enablers for credential abuse, privilege escalation, and persistence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingSaaS access reviews depend on observed activity and reviewable logs.
AC-2 — Account ManagementAccess reviews exist to confirm ongoing need and remove stale accounts.
IA-5 — Authenticator ManagementStale SaaS access often persists through unmanaged credentials and tokens.
Recommendation — Use AU-6 to base recertification decisions on auditable usage evidence. Use AC-2 to recertify accounts and disable access that lacks current justification. Use IA-5 to control credential lifecycle and retire unused authenticators.
CIS Controls v8CIS-5 — Account ManagementThe question is fundamentally about how to review and remove unnecessary access.
Recommendation — Use CIS-5 to inventory accounts and remediate dormant or excessive SaaS access.

Practitioner Guidance

What to prioritise: Start with accounts and entitlements that are both unused and high impact. If the access can reach sensitive records, admin functions, or external integrations, review it before low-risk convenience access.

What to verify: Do not trust a manager sign-off unless it is backed by a concrete signal, such as recent activity, an approved exception, or an explicit ownership statement for a shared account. If none exists, treat the entitlement as a removal candidate.

Practitioner takeaway: The strongest review model uses usage evidence to make the first decision and manager attestation only to resolve uncertainty, not to replace proof that access is still needed.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org