The process breaks down when identity requests depend on informal communication and scattered records. IT spends time reconciling changes, scripts drift as APIs change, and access decisions become inconsistent across teams. That creates slower onboarding, more helpdesk work, and higher odds that users keep access they no longer need.
Where the process breaks, and why it stays fragile
identity provisioning is built on a simple idea: the request, approval, creation, change, and removal of access should follow a predictable path. When that path runs through email threads, phone calls, and spreadsheets, the process loses a durable system of record. Each handoff becomes a place where approvals can be missed, duplicated, or interpreted differently, and where nobody can reliably tell which access state is current.
The biggest failure is not just slower administration, it is loss of control. Manual coordination makes it hard to prove who approved what, when a change was actually applied, or whether deprovisioning happened at all. That is why identity lifecycle problems so often turn into access creep, inconsistent entitlements, and avoidable helpdesk work. For a lifecycle-focused view of the problem, see NHI Lifecycle Management Guide.
In practice, the process also breaks when the environment changes faster than the paperwork. Teams update apps, roles, and APIs, but spreadsheet logic does not inherit those changes automatically. The result is drift: one team believes access is temporary, another treats it as permanent, and scripts or manual steps no longer match the live application state. This is why identity provisioning needs an authoritative workflow, not just an inbox and a tracker.
What operational failure looks like at scale
At small scale, informal provisioning may seem workable because people can correct errors by memory. At larger scale, the weak points multiply. Onboarding slows because every request needs human interpretation. Offboarding becomes especially unreliable because departed users, contractors, or service relationships can be missed if the revocation depends on someone remembering to update a sheet or forward an email.
When access changes are scattered across messages and files, IT and security teams spend more time reconciling than governing. They lose the ability to answer basic operational questions quickly: who still has access, which approvals were valid, and whether a change was completed everywhere it needed to be. That is exactly the kind of fragmentation a lifecycle reference such as Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is intended to eliminate in non-human environments.
Once the process depends on people stitching together records, any integration change can create silent failure. A form, script, or spreadsheet column can be altered without the surrounding process being updated, so the organisation thinks it has a control when it really has a convention. That is why provisioning quality is judged less by the existence of a request path and more by whether the path produces consistent, auditable outcomes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 5 — Account Management | Manual provisioning failures create stale and inconsistent account state. |
| 6 — Access Control Management | Spreadsheets and email weaken consistent access decisions and enforcement. | |
| 8 — Audit Log Management | Informal provisioning leaves weak evidence for approvals and revocation. | |
| Recommendation — Standardise account lifecycle handling so requests, changes, and removals are tracked and enforced consistently. Enforce access decisions through centrally managed controls rather than ad hoc manual coordination. Retain authoritative logs for provisioning and deprovisioning actions so access changes are auditable. | ||
| NIST CSF 2.0 | PR.AC — Access Control | Identity provisioning determines who gets access and under what conditions. |
| GV.RM — Risk Management Strategy | Manual identity workflows create governance and exposure risk through inconsistency. | |
| PR.PS — Platform Security | Provisioning drift often appears when scripts and processes no longer match system state. | |
| Recommendation — Define and enforce access provisioning rules through a governed control plane. Treat manual provisioning drift as a governance risk requiring formal ownership and review. Align provisioning automation with current platform interfaces and change control. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Provisioning quality depends on trustworthy identity proofing and enrollment. |
| AAL — Authenticator Assurance Level | Weak provisioning often coexists with poorly governed access establishment. | |
| Recommendation — Bind enrolment and identity proofing to a controlled process before granting access. Require appropriate authenticator strength for the access being provisioned. | ||
Practitioner Guidance
What to verify: Treat the current process as broken if you cannot reconstruct, from one authoritative source, the full chain from request to approval to provisioning to revocation. If those states live in separate inboxes or spreadsheets, the control is already too weak for dependable identity governance.
What good looks like: Requests should land in a system that records ownership, approval, fulfillment, and expiry in one place, with changes applied from that record rather than copied manually. The practical test is simple: if an auditor or responder asks for current access state, the answer should not require reconciling multiple human-maintained artifacts.
Common mistake: Teams often automate only the creation step and leave approvals, offboarding, or exception handling in email. That reduces visible effort but preserves the same failure modes, including stale access and inconsistent entitlement review.
Practitioner takeaway: The real break is not “manual versus automated”, it is whether the identity process has a single source of truth that keeps access decisions, implementation, and removal aligned as systems change.
Related resources from NHI Mgmt Group
- What breaks when identity governance relies on spreadsheets and email approvals?
- What breaks when authorization is still handled through static RBAC for AI systems?
- What breaks when access requests are handled through email and chat?
- What breaks when identity governance still relies on spreadsheets?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org