Teams can know which apps are installed and still miss who can use them. That creates a gap between ownership and access, so unused licences, abandoned accounts, and stale app entitlements remain active even after business need has ended.
Where the management chain breaks first
IT asset management can still tell you what exists, where it is installed, and when it was last seen. The break happens when that inventory is not linked to identity lifecycle events such as joiner, mover, leaver, role change, or ownership change. At that point, the asset record may be accurate while the access reality is stale, so governance decisions are made on incomplete state.
The practical failure is not discovery, it is control continuity. A licence may remain assigned after the user has left, a shared application account may survive a team handoff, or an entitlement may outlive the business purpose that justified it. That is why lifecycle linkage is part of access governance, not just a reporting convenience. The linkage also needs to cover non-human access paths, because the same drift appears in service accounts and application credentials when ownership and deprovisioning are not tied back to the asset record. IAM and IGA Basics and Ultimate Guide to NHIs, lifecycle processes both frame the same control problem from the identity side.
When the linkage is missing, asset teams and identity teams each hold part of the truth but neither holds the complete answer. That creates duplicate effort in one place and blind spots in another. Procurement may see renewal, operations may see installation, and security may see no obvious incident, yet the organisation can still carry dormant access that should have been removed when employment, ownership, or business need changed.
What becomes stale, and why it matters
The most visible symptom is entitlement drift. Software remains assigned to people who no longer need it, but the more consequential problem is that the asset and its access path are no longer retired together. Unused licences waste spend, abandoned accounts widen the attack surface, and stale entitlements make access reviews less trustworthy because reviewers are looking at an asset list rather than a live access map.
This is also where remediation becomes harder. If a leaver event only closes a ticket in HR or ITSM, but does not trigger revocation in the asset or entitlement system, the organisation may believe the asset has been cleaned up when it has only been administratively closed. Joiner-Mover-Leaver (JML) Guide and NHI Ownership and Accountability Guide reinforce that ownership and offboarding need to be explicit, not inferred from the asset catalogue.
At scale, the problem compounds across SaaS, endpoints, cloud apps, and internal tools. One missed link may look like housekeeping; hundreds of missed links become a structural control gap. That is how license creep, account creep, and entitlement creep become persistent rather than exceptional.
How to treat identity lifecycle as part of asset governance
Identity lifecycle linkage should be treated as a control design requirement, not an integration nice-to-have. The asset register needs a dependable relationship to the source of truth for who owns the asset, who is allowed to use it, and what event should remove that access. Without that relationship, periodic reviews can confirm existence but cannot confirm legitimacy.
The cleanest operating model is to make lifecycle events authoritative for access changes. A new owner, department move, or departure should update licence assignment, privileged access, and application entitlements through the same governed process that updates the asset record. Joiner-Mover-Leaver (JML) Guide and IAM and IGA Basics are useful navigation points for that operating model, while NHI lifecycle management shows the same requirement for machine-facing access.
For practitioners, the key question is whether the control can answer three things at once: who owns the asset, who can use it now, and what event should remove or reduce that access. If those answers come from different systems with no reconciliation rule, the organisation has inventory, but not lifecycle control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | Inventory must connect assets to responsible owners and current use. |
| AC-2 — Account Management | Stale app access is an account lifecycle failure tied to asset governance. | |
| IA-5 — Authenticator Management | Lifecycle linkage must cover credentials and tokens tied to the asset. | |
| Recommendation — Link asset inventory to ownership and deprovisioning triggers. Revoke or disable accounts when asset use or ownership ends. Track and rotate authenticators with the asset's ownership lifecycle. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | Asset inventories need ownership and use state to stay trustworthy. |
| A.5.18 — Access rights | Access rights must follow asset ownership and business need changes. | |
| Recommendation — Maintain inventory records that include ownership and current business use. Review and remove access rights when asset need ends. | ||
Practitioner Guidance
What to prioritise: Start with the assets that grant access, not the full catalogue. Applications, licences, shared accounts, service credentials, and entitlements tied to business-critical systems create the highest-risk mismatch when lifecycle linkage is missing.
What to verify: Confirm that leaver, mover, and ownership-change events actually trigger downstream deprovisioning, licence recovery, and entitlement review. If the process ends at record update, the control is incomplete.
Common mistake: Treating asset inventory accuracy as proof of access hygiene. A current list of installed software does not prove that the right people still need it, or that stale access has been removed.
Practitioner takeaway: The control objective is not merely to know what is installed, it is to ensure every asset has a live ownership and revocation path so access ends when business need ends.
Related resources from NHI Mgmt Group
- What breaks when identity lifecycle management depends on custom connectors?
- What breaks when device lifecycle management is not tied to identity governance?
- What breaks when identity lifecycle management only automates onboarding?
- What breaks when third-party access is not governed as part of identity lifecycle management?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org