Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that access requests are…
Governance, Ownership & Risk

What are the signs that access requests are drifting out of IGA control?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Look for fragmented request records, unclear approver ownership, repeated policy exceptions, and access grants that cannot be tied back to a clear business justification. Those are strong signals that workflow automation has outpaced governance design.

When IGA request traffic stops telling a clear governance story

Drift usually shows up when the request channel still works, but the governance signals behind it no longer do. The process may look busy and automated, yet the organisation can no longer answer basic questions such as who owns the approval, why the access was granted, whether the request was exceptional, or whether the entitlement still fits the business need.

That is the point where IGA becomes a transport layer for approvals rather than a control point for access decisions. IAM and IGA Basics is useful background when the line between access administration and governance starts to blur.

What drifting requests look like in practice

The clearest sign is fragmentation. Requests are split across tickets, email threads, chat messages, and side approvals, so the system of record no longer contains a complete decision trail. A second sign is ownership ambiguity: approvers are copied in, delegated informally, or chosen because they are available rather than because they are accountable.

Another common pattern is exception normalisation. If policy exceptions keep reappearing for the same teams, apps, or roles, the process is signalling that the role model, request catalogue, or approval workflow no longer matches how access is actually being consumed. That is where the difference between workflow efficiency and governance integrity becomes operationally important.

When access grants can no longer be tied back to a business justification, a role definition, or a documented entitlement request, the request process has lost evidentiary value. Access Reviews and Certification Guide is a useful companion because the same weak evidence patterns usually reappear in review campaigns and certification sign-off.

Signals that the control plane is no longer keeping up

Drift becomes more obvious when the workflow is technically efficient but governance is stale. For example, request approvals may still close quickly while role owners, application owners, or reviewers do not understand what they are approving. That produces rubber-stamped access, not meaningful review.

Another indicator is a growing gap between request outcomes and lifecycle reality. If movers keep requesting old access back, if leavers retain privileges through manual exceptions, or if the same access keeps being regranted after every cleanup, the underlying identity model is no longer aligned to the operating model. Joiner-Mover-Leaver (JML) Guide helps show why request drift often starts as a lifecycle problem before it becomes an approval problem.

Role design failures can also masquerade as request drift. When requesters constantly ask for access that does not map cleanly to existing roles, or when roles proliferate into narrow one-off bundles, the approval workflow is compensating for poor entitlement architecture. Role Mining and Role Design Guide is relevant because request drift often reflects role drift underneath it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess requests and approvals govern account provisioning and changes.
AC-6 — Least PrivilegeDrifting requests often produce excessive or unjustified access.
AU-6 — Audit Record Review, Analysis, and ReportingFragmented request records weaken the evidence trail needed to spot drift.
Recommendation — Enforce approval, justification, and periodic review for every access grant. Limit grants to the minimum access needed for the stated business purpose. Review access-request logs and correlate approvals, exceptions, and entitlement changes.
ISO/IEC 27001:2022A.5.15 — Access controlAccess request drift is an access-control governance problem.
A.5.18 — Access rightsThe issue centers on granting, reviewing, and removing access rights cleanly.
Recommendation — Define and enforce access request rules, ownership, and approval criteria. Periodically recertify access rights and remove stale or unjustified entitlements.

Practitioner Guidance

What to prioritise: Start with traceability, not volume. If a request cannot be matched to a named owner, a documented business purpose, and a durable entitlement model, treat it as a governance defect rather than a low-priority process exception.

What to verify: Check whether approvers are genuinely accountable for the access they approve, whether exception paths are time bound, and whether repeated requests are signaling a missing role or a missing approval boundary. If the same exception recurs, the fix is usually structural, not procedural.

Practitioner takeaway: IGA drift is rarely about one bad request, it is about the organisation losing the ability to explain and defend access decisions at scale. Once that explanation breaks, automation is amplifying weak governance instead of enforcing it.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org