When directory groups are requested, certified, and cleaned up in separate workflows, access drift builds faster than governance can correct it. The result is stale membership, unclear ownership, and more manual exception handling. IGA teams should treat that as a lifecycle design problem, not a helpdesk issue.
Where the lifecycle breaks down
Directory groups stop being a clean permission primitive as soon as their lifecycle is split across request, certification, and cleanup. You get one workflow asking who should be added, another asking whether the membership is still valid, and a third trying to remove what nobody owns anymore. That separation turns group membership into a moving target rather than a governed asset.
The practical failure is not just slower administration. When IAM and IGA Basics are applied as a single operating model, access requests, recertification, and entitlement cleanup reinforce each other; when they are split, the control loop weakens and stale membership survives long enough to become normal.
Why split workflows create access drift
Access drift grows because each workflow has a different incentive and a different time horizon. Requests optimise for speed, reviews optimise for acknowledgement, and cleanup optimises for backlog reduction. If those steps are not tied to the same authoritative lifecycle, groups accumulate members that were once justified but are no longer current, and reviewers end up certifying inherited noise instead of real access need.
Access Reviews and Certification Guide is useful here because it treats certification as a removal mechanism, not a paperwork exercise. That matters when the same group is repeatedly approved without effective removal, since certification loses force if the cleanup step sits outside the review outcome.
In mature programs, group governance also has to line up with ownership. If nobody can answer who owns the group, why it exists, and what event should trigger its removal, the directory becomes a storage layer for old decisions rather than a current access model.
What practitioners should design instead
The fix is to manage groups as lifecycle objects with one owner, one source of truth for membership justification, and one removal path when access is no longer needed. That design usually means joining request, approval, review, and deprovisioning to the same entitlement record so the control can close the loop instead of merely documenting it.
Joiner-Mover-Leaver (JML) Guide supports that model because lifecycle events, not calendar time, should drive entitlement change. When movers keep old group access and leavers are not reconciled promptly, the directory absorbs exceptions that later show up as hard-to-explain standing access.
Where groups also carry elevated or operationally sensitive access, pair lifecycle handling with privilege design. Privileged Access Management Guide reinforces the point that access should expire, be reviewable, and be reversible, which is exactly what split group workflows tend to obscure.
How to recognise when the model is already failing
The warning signs are predictable: recurring exceptions for the same group, long-lived memberships that nobody can justify quickly, delayed recertification decisions, and cleanup tasks that keep getting deferred because ownership is ambiguous. At that point, the issue is no longer a messy directory, it is an entitlement governance defect.
That is why teams should watch for groups that are certified more often than they are emptied, or emptied only after manual escalation. The more exception handling becomes normal, the more the process depends on human memory instead of enforced lifecycle state.
Risk and Threat Considerations
Separated workflows increase the chance that stale group memberships remain active long after business need has ended, which widens the window for unauthorized access and makes audit evidence harder to trust. The same pattern also creates privilege creep, because old memberships tend to survive reviews when no system reliably removes them.
Failure mechanism: Request, review, and cleanup are executed as disconnected steps, so approval signals do not automatically drive revocation or ownership correction. That leaves orphaned or outdated members in place until someone notices them manually.
Impact: Attackers and insiders gain a larger pool of overlooked access, governance teams spend more time on exceptions, and the directory no longer reflects current business intent.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Directory group lifecycle and cleanup map to managed access changes and revocation. |
| AC-6 — Least Privilege | Split workflows often leave excessive memberships in place beyond need. | |
| AU-6 — Audit Review, Analysis, and Reporting | Recertification and cleanup need reviewable evidence to prove drift is being reduced. | |
| Recommendation — Tie group membership changes to authorized account management and revoke stale access promptly. Review group membership against least-privilege need and remove standing access when it is no longer justified. Correlate access-review outcomes with removals and investigate unresolved exceptions. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about governing access consistently across request, review, and cleanup. |
| Recommendation — Enforce a single access-control process that removes memberships when the justification ends. | ||
Practitioner Guidance
What to verify: Confirm that every directory group has a named owner, a defined business purpose, and a linked removal trigger. If a group cannot be removed through the same governance path that created it, treat that as a design defect rather than an operational delay.
Decision rule: If recertification does not reduce membership or trigger revocation automatically, the process is only evidencing access, not controlling it. Tighten the lifecycle first, then tune review frequency or reviewer scope.
What good looks like: A reviewer can see why the group exists, who still needs it, and what will happen when it is no longer justified. Cleanups should be routine and predictable, not a separate exception workflow that depends on memory or escalation.
Practitioner takeaway: Directory groups are safest when membership, review, and cleanup behave as one governed lifecycle. Once those steps diverge, drift is not an edge case, it is the default outcome.
Related resources from NHI Mgmt Group
- What breaks when access reviews are managed separately for ITGC and SOX?
- How should security teams run access reviews for non-human identities?
- When do NHI access reviews create more value than a one-time cleanup?
- What breaks when Active Directory controls are managed only through quarterly reviews?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org