Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when every tenant request becomes a…
Governance, Ownership & Risk

What breaks when every tenant request becomes a new global role?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

The model breaks because the global catalogue becomes a dumping ground for exceptions. Reviewers lose a clear baseline, administrators cannot predict the blast radius of each role, and customers inherit permissions that were designed for someone else. Scoped roles keep variation where it belongs, inside the tenant boundary.

Why global role catalogs fail under tenant-specific exceptions

A global role model only works when the same permission bundle means the same thing everywhere. Once tenant-by-tenant exceptions start accumulating, the catalog stops being a clean access model and becomes a patchwork of one-off entitlements. At that point, role names no longer communicate intent, and the policy surface becomes harder to reason about than the underlying permissions.

The practical failure is not just volume, it is semantic drift. A role that was safe and understandable for one tenant starts carrying hidden assumptions from another, so the catalog can no longer serve as a reliable source of truth for access design or review.

What reviewers and administrators lose when roles stop being scoped

Reviewers need a stable baseline to judge whether access is appropriate. When every new tenant request creates a global role, the baseline fragments, and each review becomes a bespoke interpretation exercise instead of a repeatable control. That raises the chance that excessive access survives simply because the reviewer cannot compare it cleanly with the rest of the catalogue.

Administrators lose predictability. If a role can vary in meaning across tenants, then its blast radius is no longer obvious from the name or description. That makes lifecycle tasks, approval workflows, and change impact assessment more fragile, especially when teams assume a role is reusable because it looks standardized.

Scoped design keeps variation inside the tenant boundary, where it can be isolated, tested, and retired without changing the meaning of everyone else’s access. The access model stays interpretable because the global layer expresses common capability, not tenant-specific exception handling.

How cross-tenant permission drift creates customer and governance risk

When a global role absorbs tenant-specific exceptions, one customer can inherit permissions created for another customer’s workflow, contract, or integration pattern. That is a governance problem as much as an access problem, because the role catalogue stops reflecting a clean authorization decision and starts reflecting historical exception handling.

This is also why many access-control programs pair least privilege with explicit scoping and strong review discipline, as reflected in NIST Cybersecurity Framework 2.0 and NIST SP 800-207 Zero Trust Architecture. The point is not simply to reduce privilege, but to preserve bounded trust decisions that do not silently expand across tenants.

Risk and Threat Considerations

Global roles that accumulate tenant exceptions create a classic privilege-exposure pattern: over time, the role becomes broader than any single reviewer expects, and that hidden breadth increases the impact of misuse or compromise. The more tenants share a mutated role definition, the more likely an error or abuse case in one tenant becomes relevant to others.

Failure mechanism: permission exceptions are normalized into the shared catalog, so access that should have been isolated becomes reusable across tenants and harder to detect during review or change control.

Impact: cross-tenant overreach, unpredictable blast radius, and weaker accountability for who actually needs each entitlement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Least PrivilegeScoped roles and tenant boundaries directly support least-privilege access decisions.
GV.RM-01 — Risk Management StrategyRole sprawl and blast-radius uncertainty are governance risks that need an explicit strategy.
Recommendation — Enforce least-privilege role design so tenant-specific exceptions do not expand shared access. Set a role governance strategy that limits exception growth and defines review thresholds.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe question is fundamentally about preventing excessive permissions in shared roles.
Recommendation — Apply least-privilege role assignments and separate tenant-scoped exceptions from global access.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control policy must keep shared roles understandable and bounded across tenants.
Recommendation — Define access rules that prevent tenant-specific exceptions from polluting shared role definitions.

Practitioner Guidance

What to prioritise: Keep the global role catalogue small and capability-based, then push tenant-specific variance into scoped overlays, tenant policies, or local mappings. If a role description requires tenant context to make sense, it is already too broad for a shared global baseline.

What to verify: For every shared role, confirm that the permission set is stable, explainable, and reusable without hidden tenant assumptions. If administrators cannot predict what changes when a role is assigned, reviewed, or revoked, the design is already too exception-driven to govern well.

Practitioner takeaway: The test is not whether a global role can be made to work for many tenants, it is whether the role still means one thing after the third exception.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org