Governance breaks at the point where approved access diverges from actual behaviour. Provisioning records can show that an identity was allowed to act, but they cannot prove that every runtime action stayed within the intended scope. That is why runtime telemetry matters for NHI, service accounts, and AI agents that can cross system boundaries quickly.
Where provisioning-only governance stops being reliable
Provisioning tells you what access was approved, requested, or assigned. It does not tell you whether the identity stayed within that intended scope during actual execution. The gap matters most when the actor can keep operating long after the original change record, so governance based only on lifecycle events becomes a historical record instead of a control over live behaviour.
That is why runtime observability has to complement provisioning, especially for systems where access can shift quickly across hosts, APIs, tenants, or workflows. IAM and IGA Basics is useful here because it frames provisioning, entitlements, and governance as related but distinct control layers.
Provisioning evidence is still valuable, but it answers a narrower question: was access granted according to policy? Live-use visibility answers the harder one: did the identity behave consistently with that policy once it started acting? In practice, both are needed because an approved entitlement can be misused, expanded by delegation, or carried into a context the original approval never contemplated.
Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs and the Joiner-Mover-Leaver (JML) Guide both reinforce that governance is not complete when access is issued; it must also be withdrawn, rotated, or re-scoped when the operational reality changes.
Why runtime use changes the governance question
Runtime use introduces context that provisioning systems usually do not model well: which resource was touched, which boundary was crossed, which command or API call was executed, and whether the action matched the approved purpose. For human users, that can show up as privilege misuse. For service accounts and machine identities, it often appears as broad automation that quietly expands into adjacent systems. For AI agents, the problem is even sharper because the same identity may chain tools and actions faster than manual review can follow.
Identity Visibility and Intelligence Platforms (IVIP) Guide fits this gap well because it focuses on identity telemetry, effective access, and the difference between assigned access and observed activity. Ultimate Guide to NHIs — Key Challenges and Risks adds the practical problem of visibility gaps, sprawl, and unmanaged credentials that make live-use review harder than entitlement review alone.
The governance implication is simple: a clean provisioning record is not proof of safe use. If runtime access is not measured, then least privilege becomes an assumption, not an observed state. That is especially true where the identity can be reused, delegated, or embedded in automation that outlives the original workflow owner.
Ultimate Guide to NHIs — Regulatory and Audit Perspectives is relevant because auditability increasingly depends on evidence of what identities actually did, not just what they were allowed to do on paper.
What good governance looks like when live use is visible
Good governance combines entitlement evidence with runtime evidence. That means the reviewer should be able to answer three questions: what was granted, what was actually exercised, and whether the exercised scope stayed inside the approved boundary. When those answers do not line up, the issue is not merely a reporting gap, it is a control failure that should trigger follow-up.
Access Reviews and Certification Guide is a strong companion because it shows how to make reviews context-aware instead of treating every entitlement as equally trustworthy. Segregation of Duties (SoD) Guide also matters when live behaviour can cross into conflicting actions that provisioning alone would never reveal.
For practitioners, the useful shift is from static certification to evidence-backed certification. Review access that was granted, then verify whether the runtime trail shows narrow, expected behaviour or broad, repeated, cross-boundary use. If the second half is missing, the certification result is incomplete even if the entitlement list looks clean.
Identity Security Programme Guide helps here because it treats identity governance as a programme with operational feedback loops, not a one-time provisioning workflow.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Runtime activity must be reviewed to validate actual access use. |
| AC-6 — Least Privilege | Behavioral drift shows when granted access exceeds what runtime use should require. | |
| IA-5 — Authenticator Management | Provisioning-only views miss the lifecycle of credentials that enable live use. | |
| Recommendation — Review identity activity records to confirm live actions match approved access. Limit standing privileges to the minimum needed for observed business tasks. Rotate and revoke authenticators when live use no longer matches approved scope. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Governance needs live-use visibility to manage identity risk effectively. |
| Recommendation — Incorporate runtime identity telemetry into your risk management strategy. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account control must extend beyond issuance to actual account use and removal. |
| Recommendation — Continuously validate account activity against approved access and remove unused access. | ||
Practitioner Guidance
What to verify: Do not trust access review outcomes unless you can show runtime evidence for the same identity and period. The key check is whether observed actions stayed within the intended system, data, and privilege boundaries.
Decision rule: If the identity can act across systems, APIs, or tools, treat runtime telemetry as part of governance, not an optional detective control. If you cannot observe live use, lower your confidence in the certification result and escalate the review scope.
What practitioners underestimate: Provisioning accuracy and governance accuracy are not the same thing. A platform can be excellent at assigning access and still miss the real question of how that access was used after issuance.
Practitioner takeaway: The control objective is not just “who got access,” but “what that access did in production,” because only the second view reveals whether governance is actually constraining behaviour.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org