Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when access is approved from org…
Governance, Ownership & Risk

What breaks when access is approved from org charts instead of actual usage?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Org charts are too static to reflect project work, contractor status, inactive accounts, or app-specific sensitivity. That causes unnecessary permissions to survive long after the business need has changed, which weakens least privilege and creates persistent over-provisioning.

Why org charts fail as an access model

An org chart answers reporting relationships, not operational need. Access decisions built from hierarchy tend to miss the real signals that drive entitlement: which project someone is on, whether a contractor is still active, what application they touch, and whether a role carries sensitive data. The result is stale access that outlives the business reason for granting it.

That mismatch is especially visible in shared teams and fast-moving delivery work. A person can remain “in scope” on paper while their actual duties have changed, or they can move between systems with very different sensitivity levels. When the approval model follows structure instead of usage, entitlement reviews become a formality rather than a control.

What fails when approval follows reporting lines instead of usage

The first thing that breaks is least privilege. If approvers rely on title, department, or manager chain, they often grant broader access than the job actually requires. That creates persistent over-provisioning, especially where access was approved once and never revisited after a project ended or an account went dormant.

The second failure is lifecycle drift. Org-based approvals do not naturally capture short-term work, temporary access, or application-specific sensitivity, so revocation happens late or not at all. In practice, the access graph becomes detached from the work graph, which makes both recertification and cleanup less reliable.

The third failure is accountability. When approval logic is vague, reviewers cannot tell whether they are validating business need, manager preference, or inherited entitlement. That weakens the control’s value as an audit trail and makes exceptions harder to challenge.

How to think about a better access decision model

A usable access model starts with actual usage and business context, not just organisational position. That means asking whether the user is still active in the relevant project, whether the account type is appropriate for the task, whether the requested system carries higher sensitivity, and whether the access should expire when the work ends.

For sensitive systems, the decision should be explicit and time-bound. If the access is temporary, the approval should include a review point or expiry. If the entitlement is broad, the reviewer should require a clearer justification than “this person reports to the right manager.”

This is where external control guidance helps anchor the practice. Least-privilege and account governance expectations in CIS Controls v8, the access-control and identification controls in NIST SP 800-53 Rev 5 Security and Privacy Controls, and the access-control requirements in ISO/IEC 27001:2022 Information Security Management all support the same practical direction: approval should reflect current need, not static structure.

Risk and Threat Considerations

When approvals are based on org charts, access tends to accumulate quietly. That creates exposure when inactive users, ex-contractors, or moved staff retain permissions that still reach sensitive applications or data. The threat is not only misuse, it is also the enlarged blast radius if an account is compromised after its business need has already passed.

Failure mechanism: Static approval criteria fail to track actual work, so excess entitlement survives role changes, project transitions, and account inactivity.

Impact: The environment drifts toward persistent over-provisioning, weaker least privilege, and a larger set of accounts that can be abused, inherited, or overlooked during review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementAccess approvals based on current need depend on disciplined account lifecycle control.
Recommendation — Review accounts and entitlements regularly, and remove access that no longer matches business need.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeOrg-chart approvals commonly grant more access than the task requires, which AC-6 is meant to limit.
Recommendation — Enforce the minimum permissions needed for the current task or role.
ISO/IEC 27001:2022A.5.15 — Access controlAccess should be granted and reviewed against business need, not static hierarchy.
Recommendation — Define and apply access rules that reflect current business and security requirements.

Practitioner Guidance

What to prioritise: Review the approval rule itself before tuning the review cadence. If the rule is “manager approved,” “same department,” or “in the org,” it is too coarse for systems where sensitivity changes by application or project.

What to verify: Check whether each approved entitlement can be tied to a current business task, an owner who can defend it, and an expiry or recertification trigger. If you cannot explain why the access still exists today, treat it as a cleanup candidate, not a standing entitlement.

Practitioner takeaway: Good access governance follows actual work and current risk, while org charts only describe structure; when those two diverge, over-provisioning is usually the first control failure you will see.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org