The control breaks when access exists in more than one system. A central directory can be updated while third-party portals, support tools, and managed service accounts still retain active access. That leaves former users or moved employees with permissions that no longer match their role, which defeats least privilege and creates audit gaps.
How single-directory onboarding breaks in the real world
When onboarding and termination live in only one directory, the directory stops being the source of truth and becomes only one control point. The failure is not usually the central directory itself, but the assumption that every downstream system reads it immediately and consistently. In practice, access drifts wherever provisioning is delayed, disconnected, or manually maintained.
That matters because access decisions are made across multiple control planes. HR or the directory may show a moved employee as revoked, while a support portal, SaaS tenant, admin console, or managed service account still carries the old entitlement. The result is not just inconvenience, it is residual access that no longer matches job function or employment status.
One of the clearest lifecycle patterns is joiner-mover-leaver governance. A directory update must be mirrored into the rest of the access estate, or the organisation gets a partial revocation that looks complete on paper. NHIMG’s Joiner-Mover-Leaver (JML) Guide and IAM and IGA Basics both reinforce that access governance only works when provisioning, recertification, and deprovisioning are tied together rather than treated as separate tasks.
What access drift looks like across directories and portals
The practical breakdown shows up as stale entitlements, orphaned accounts, and over-retained privileges. A user can move teams and keep old access because the directory fed the HR change, but the target application was never re-evaluated. A leaver can be disabled in the main directory yet still retain API access, support permissions, or a third-party login that was issued outside the primary identity flow.
This is especially common where organisations combine native directory controls with manual exceptions or vendor-managed access. Each exception creates a second lifecycle path, which means the organisation now has multiple places to provision, revoke, review, and prove removal. NHIMG’s NHI Lifecycle Management Guide and Workforce Identity Security Guide are useful here because they show how identity lifecycle failures become access creep, not just administrative clutter.
A related failure mode is credential persistence. Offboarding a person without revoking linked tokens, keys, or delegated service access leaves a live path even if the directory account is gone. That is why lifecycle management has to include the access-bearing material itself, not just the human record associated with it. For a concrete example of offboarding-driven exposure, NHIMG’s Coupang Signing Key Breach shows how unreleased credentials can outlive the personnel change that should have closed them.
Why the control gap becomes an audit and security problem
Once access exists in more than one system, the organisation loses simple proof that termination actually worked. Audit evidence becomes fragmented, because one record says access was removed while another system still grants it. That breaks least privilege, weakens joiner-mover-leaver controls, and creates a blind spot for investigations and reviews.
The security impact is not limited to former employees. A moved employee can retain prior-role access and accidentally or intentionally use it outside current duties. A service account or third-party portal can keep working after the owner changes, which means the blast radius of a missed deprovisioning step can extend well beyond the original directory. NHIMG’s Top 10 NHI Issues captures the broader pattern of visibility gaps, over-privilege, and unmanaged credentials that appear when access governance is partial rather than end-to-end.
For practitioners, the key issue is that a directory-centric process can give false confidence. If you cannot reconcile every downstream app, portal, token, and delegated account to the same lifecycle event, the control is incomplete even if the main directory looks clean. That is the point where a simple onboarding or termination workflow turns into an access governance deficiency.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Termination and lifecycle of credentials, tokens, and keys directly affect residual access. |
| IA-9 — Service Identification and Authentication | Downstream portals and managed service accounts need their own authentication lifecycle. | |
| Recommendation — Revoke and rotate authenticators when users leave or roles change. Bind non-human and service access to explicit lifecycle controls and revoke it on change. | ||
| CIS Controls v8 | CIS-5 — Account Management | This subject is about provisioning and deprovisioning accounts across systems. |
| Recommendation — Maintain authoritative account inventory and remove stale access in every connected system. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access must be governed consistently across all systems that grant it. |
| A.8.2 — Privileged access rights | Residual admin or support access after termination is a privileged access failure. | |
| Recommendation — Apply consistent access control rules across the full application estate. Review and revoke elevated rights whenever employment or role changes occur. | ||
Practitioner Guidance
What to prioritise: Treat the directory as the starting point for lifecycle control, not the finish line. The first thing to verify is whether every system that grants access has a revocation path tied to the same joiner-mover-leaver event, including third-party portals and any delegated or managed accounts.
What to verify: Before trusting offboarding, reconcile the directory record against a real access inventory. Look for active sessions, API tokens, service accounts, support tools, and vendor consoles that can still authenticate independently of the central directory.
Common mistake: Teams often measure success by whether the user was disabled centrally, not by whether all effective access disappeared. That metric is too narrow when access is distributed across multiple control planes.
Practitioner takeaway: The control is only as strong as its weakest downstream entitlement path, so termination must be validated by loss of actual access, not by the status of one directory record.
Related resources from NHI Mgmt Group
- What breaks when privileged access for contractors is managed with manual onboarding and one-off approvals?
- When do NHI access reviews create more value than a one-time cleanup?
- What breaks when access is managed one permission at a time?
- What breaks when access onboarding and termination are handled manually for SOC 2?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org