Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when just-in-time provisioning is treated as…
Governance, Ownership & Risk

What breaks when just-in-time provisioning is treated as Zero Standing Privilege?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

The model still creates an entitlement that can be used during its validity window, so privilege exists before revocation. That means the organisation has reduced duration, not eliminated standing access. For IAM and PAM teams, the failure is conceptual and operational: the access is still present long enough to be abused, audited only after the fact, and counted as temporary when it is not truly session-only.

Why JIT Becomes a False Substitute for Zero Standing Privilege

Just-in-time provisioning reduces how long access exists, but it does not erase the fact that an entitlement is created and usable within a window. If the access can be exercised before revocation, the system still has standing privilege for that period. The practical difference is between time-bounded access and truly session-only access with no persistent privilege left behind.

That distinction matters because zero standing privilege is a state, not a scheduling preference. A JIT flow may still leave role membership, token scope, credential validity, or a recoverable entitlement in place until the window closes. For teams trying to remove blast radius, the question is whether the model ever allows dormant access to exist at all, even briefly.

In PAM and IAM terms, the control objective is not only shorter duration, but tighter authority boundaries. A system can be "temporary" and still fail the Zero Standing Privilege test if it grants an access path that can be reused, expanded, or abused during its active period. Just-in-Time Access and Zero Standing Privilege Guide is useful here because it separates time-bound elevation from a true move to zero standing privilege.

Where the Operational Failure Shows Up

The operational break is usually in governance language, not only in tooling. Teams mark access as ephemeral, but the entitlement still exists long enough to be audited, escalated, or misused. That means access reviews can look clean while the underlying permission model still depends on delayed revocation rather than immediate non-persistence.

This also changes how you interpret evidence. If the access model depends on lease expiry, timer cleanup, or post-use revocation, then the risk window is the period between activation and removal, not merely the intended short duration. Privileged Access Management Guide and PAM Buyer's Guide both reflect the core operational point: strong PAM has to control the whole privilege lifecycle, not just the approval event.

When this gets implemented badly, the organisation measures the wrong thing. It counts approvals or issuance events instead of verifying whether the entitlement disappears quickly enough to prevent reuse, privilege chaining, or persistence beyond the required session.

How to Tell Whether the Control Is Actually Zero Standing Privilege

A good test is simple: after activation, does the subject receive an access state that can still be used independently of the current session? If yes, the design is JIT with delayed revocation, not true ZSP. If no, and the permission only exists for the duration of an observable, bounded session, the model is much closer to the intended control.

For practitioners, the most revealing checks are whether the access is reusable, whether the entitlement remains discoverable after activation, and whether revocation is immediate rather than deferred to a cleanup cycle. The same logic applies across people, service accounts, and automated actors, because IAM and IGA Basics frames entitlement governance as a lifecycle problem, not just an access request problem.

That is why lifecycle tooling matters. NHI Lifecycle Management Guide and Joiner-Mover-Leaver (JML) Guide are relevant because provisioning, revocation, and offboarding controls determine whether privilege is genuinely absent or merely short-lived.

Risk and Threat Considerations

When JIT is treated as ZSP, the main risk is a false sense of elimination. The organisation may assume there is no standing access to abuse, yet the temporary entitlement can still be used during its validity window, so compromise, misuse, or lateral movement can occur before revocation.

Failure mechanism: The access path remains active long enough for an attacker, insider, or misconfigured automation path to exploit it, especially if approvals are broad, session controls are weak, or cleanup is delayed.

Impact: Privilege exposure is reduced in duration but not removed, which can preserve the attack window, complicate audit interpretation, and hide overprivilege behind a "temporary" label.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementJIT and ZSP depend on how credentials and expirations are issued and revoked.
AC-6 — Least PrivilegeThe question is about whether temporary access still leaves excessive effective privilege.
IA-2 — Identification and Authentication (Organizational Users)Temporary access still requires sound identity proofing and authenticated activation.
Recommendation — Set short-lived authenticator lifetimes and revoke them immediately after use. Limit each grant to the minimum privileges needed for the current session. Require strong authentication before issuing any elevated access.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control policy must distinguish temporary access from true standing privilege removal.
A.8.2 — Privileged access rightsPrivilege grants are central because JIT can still leave privileged rights active briefly.
Recommendation — Define when access is time-bound and when it must be removed entirely. Review privileged rights for reuse, persistence and delayed revocation.
NIST CSF 2.0PR.AA-05 — Access PermissionsThe control is about whether permissions are bounded tightly enough to avoid standing access.
Recommendation — Validate that permissions expire as soon as the task or session ends.
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsThe distinction turns on whether the access is truly ephemeral or only shortened.
NHI-05 — Overprivileged NHITemporary grants can still be overprivileged during their active window.
Recommendation — Replace durable credentials with short-lived access material where possible. Right-size each non-human grant so its active window cannot exceed its task need.

Practitioner Guidance

What to verify: Confirm whether the entitlement is actually non-persistent after activation, not merely time-limited. If the access can be reused, extended, or inherited during the window, treat it as residual standing privilege and not ZSP.

Decision rule: If the control objective is to eliminate dormant privilege, require immediate expiry of the usable access state, not just a short approval period. If the business only needs temporary elevation, document it as JIT and measure it against revocation speed, session containment, and post-activation blast radius.

Practitioner takeaway: ZSP is proven by the absence of usable standing access, so the right question is not how short the grant lasts, but whether any exploitable privilege exists between creation and revocation.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org