Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should teams prioritise hidden identity discovery or access…
Governance, Ownership & Risk

Should teams prioritise hidden identity discovery or access recertification first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

Discovery comes first. Recertification cannot reliably govern identities that the programme has not yet found, and hidden assets can continue to accumulate risk while teams certify only the visible estate. Once the blind spots are identified, access review becomes far more accurate and materially easier to sustain.

Why discovery has to precede recertification

Discovery is the prerequisite because access recertification can only govern identities, entitlements, and credentials that are already in scope. If hidden accounts, service identities, or unmanaged secrets remain undiscovered, review campaigns will naturally certify the visible estate while the riskiest blind spots stay untouched. That makes discovery the control that expands the governed population before any meaningful review can begin.

In practice, this is less about choosing one control and more about sequence. Discovery establishes what exists, who or what owns it, where it authenticates, and whether it still has business purpose. Once that inventory exists, recertification can be aimed at real access rather than a partial list that creates false confidence.

For teams building a governance baseline, the discovery step should include stale accounts, orphaned service identities, shadow integrations, dormant credentials, and other assets that do not show up in ordinary ownership lists. That is why identity lifecycle work and review work are tightly coupled, as reflected in the NHI Lifecycle Management Guide and the IAM and IGA Basics.

What hidden identity discovery changes in the review model

Hidden identity discovery changes the unit of analysis. Instead of asking only whether a known account still needs access, teams first determine whether the account, token, key, or workload identity should have been known and governed at all. That matters because an access review over an incomplete population is operationally tidy but security-poor.

Once discovery has found the hidden estate, recertification becomes more precise in three ways. First, ownership can be assigned to the correct business or technical custodian. Second, access can be reviewed against current function rather than legacy entitlement. Third, dormant or overprivileged identities can be removed instead of repeatedly re-approved because nobody recognized what they were reviewing.

That is why the most useful review programmes are built on visibility and closure, not just periodic attestations. Access Reviews and Certification Guide is relevant here because it frames review as a mechanism to remove access, cut volume, and close the loop rather than simply collect approvals.

Discovery also improves the quality of role, entitlement, and segregation decisions. If the underlying population is incomplete, then role mining, access certification, and SoD checks all inherit the same blind spot. Teams usually feel that defect only later, when exceptions recur or orphaned access reappears after review.

How to sequence the two without delaying governance

The right sequence is discovery first, then targeted recertification, then continuous upkeep. Discovery should not be treated as a one-time inventory exercise, because hidden identities tend to reappear through automation, integrations, and cloud drift. Recertification should start as soon as the first reliable slice of the estate is found, but only for the identities that can be validly owned and reviewed.

The practical rule is simple: if an identity can already be scoped, review it; if it cannot yet be trusted as complete, discover it. This lets teams avoid the common mistake of waiting for perfect visibility before doing any governance, while still preventing premature certification of an unknown population.

Programmes that combine lifecycle control with review discipline usually get the fastest payoff from joiner-mover-leaver flows, inventory reconciliation, and access cleanup. The Joiner-Mover-Leaver (JML) Guide is useful for that sequence because it links provisioning, deprovisioning, and the removal of access that leavers or movers leave behind. For a broader inventory-led view, the Identity Visibility and Intelligence Platforms (IVIP) Guide helps teams connect discovery to a continuously updated governed view.

Risk and Threat Considerations

Hidden identities are risky because they bypass the normal control loop. Unfound accounts, service credentials, and stale secrets can retain access long after the team believes they have been reviewed, creating a quiet path for privilege accumulation, lateral movement, or unauthorized persistence.

Failure mechanism: The governance process certifies the visible estate, while undiscovered identities remain outside ownership, review, and remediation workflows. Over time, those blind spots become the easiest place for excess privilege, unused access, or abandoned credentials to persist.

Impact: Organisations get a false sense of control, and the residual risk can be material because the very identities most likely to be forgotten are often the ones with weak lifecycle handling or broad access. That is also why hidden access often becomes an audit issue, not just an operational one, as shown in the Ultimate Guide to NHIs — Regulatory and Audit Perspectives.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-01 — Physical devices and systems within the organization are inventoriedHidden identity discovery is an inventory problem for governed access assets.
Recommendation — Inventory all identities and access-bearing assets before running recertification campaigns.
NIST SP 800-53 Rev 5CM-8 — System Component InventoryDiscovery requires a complete inventory of accounts, secrets, and service identities.
IA-5 — Authenticator ManagementDiscovery must surface credentials and secrets before they can be reviewed or revoked.
AC-2 — Account ManagementRecertification only works when all accounts, including hidden ones, are discovered and managed.
Recommendation — Maintain an authoritative inventory of identity-bearing components before certifying access. Track and govern credentials and secrets from discovery through rotation and revocation. Discover every account, then apply account review and removal actions consistently.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsDiscovery depends on a reliable inventory of identities and access-related assets.
Recommendation — Keep an up-to-date inventory of access-bearing assets before certification cycles.
CIS Controls v8CIS-1 — Inventory and Control of Enterprise AssetsHidden identities are a visibility gap that inventory controls are meant to close.
Recommendation — Find and inventory all access-bearing assets before reviewing their access.

Practitioner Guidance

What to prioritise: Build the discovery list first for identities that can create long-lived or high-impact access, especially service credentials, shared accounts, dormant principals, and integrations that fall outside the normal HR or joiner-mover-leaver flow. Those are usually the blind spots that make recertification look healthier than it is.

What to verify: Before trusting a recertification result, verify that the population is complete enough to represent the environment. If the review cannot explain ownership, purpose, and last-use context for a material slice of access, the programme is not ready to rely on certification outcomes alone.

Decision rule: If the environment still has unknown identities, recertification should be treated as a cleanup control, not the primary governance control. Once discovery is mature enough to expose the hidden estate, review cadence and scope become far more defensible.

Practitioner takeaway: Discovery is not a supporting task before review, it is the control that makes review real; without it, teams can only recertify what they already know how to see.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org