Join our Newsletter — 33% off our NHI Course
Home FAQ NHI Lifecycle Management What breaks when onboarding and offboarding are handled…
NHI Lifecycle Management

What breaks when onboarding and offboarding are handled manually across unmanaged applications?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: NHI Lifecycle Management

Manual lifecycle handling creates orphaned accounts, lingering sessions, and inconsistent credential revocation. That risk grows when one directory governs only a small part of the estate while employees use many unsanctioned tools. The failure is not just administrative overhead. It is persistent access that survives role changes, departures, and audits.

Why This Matters for Security Teams

Manual onboarding and offboarding fail fastest in application sprawl, where directories only cover a fraction of the estate and business users create access paths outside IT control. The result is not just delayed cleanup. It is persistent access that outlives role changes, contract endings, and incident response timelines, especially when credentials are reused across systems. NHI Management Group documents how lifecycle gaps remain a major issue in practice, including its Ultimate Guide to NHIs — Key Challenges and Risks.

That matters because unmanaged applications often hold the least visible access and the weakest revocation discipline. A manual process can remove a user from the HR system while leaving API keys, session tokens, app-local accounts, and delegated access untouched. NIST guidance on access control and account lifecycle management reinforces that security depends on timely revocation, not just initial provisioning, as reflected in the NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls. In practice, many security teams discover the problem only after a departed user, contractor, or former service owner still has live access during an audit, an incident, or a breach investigation.

How It Works in Practice

When lifecycle handling is manual, each unmanaged application becomes its own authority for identity and access. Security teams may close the directory account, but the application can still retain local credentials, cached sessions, personal API tokens, shared inbox delegation, or role mappings that no one revalidates. If the application is not integrated with the central joiner-mover-leaver workflow, offboarding becomes a chain of tickets, emails, and tribal knowledge rather than an enforced control.

That breaks the security model in three ways. First, revocation becomes inconsistent, so access survives beyond employment or vendor terms. Second, audit evidence becomes weak, because there is no reliable record of who removed what, when, and in which app. Third, privilege drift accumulates, especially where users are granted exceptions to keep operations moving. NHI Management Group notes in its Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs that formal offboarding and API key revocation remain immature in many organisations.

  • Replace ad hoc deprovisioning with event-driven workflows tied to authoritative HR, vendor, and IAM sources.
  • Inventory unmanaged applications separately from sanctioned apps so manual exceptions are visible and reviewed.
  • Track sessions, tokens, keys, and app-local accounts as distinct assets, not as a single user record.
  • Require explicit revocation evidence for every offboarding action, including API keys and delegated access.

Current guidance suggests that the control gap is largest where business units can create or subscribe to applications without security review, because identity state is then fragmented across shadow IT, shared credentials, and local admin rights. These controls tend to break down when offboarding depends on manual tickets across dozens of disconnected SaaS and legacy systems because no single team can verify completion end to end.

Common Variations and Edge Cases

Tighter offboarding often increases operational friction, requiring organisations to balance rapid user exit with continuity for shared services, contractors, and break-glass accounts. Not every application can support central federation or automated deprovisioning, and best practice is evolving for how to govern those exceptions without slowing the business.

One common edge case is the application that has no API, no SSO, and no admin export. In that environment, manual removal may be the only immediate option, but it should still be treated as a compensating control, not a finished control. Another edge case is service accounts embedded in scripts, CI/CD pipelines, or integrations, where “offboarding” a person does not remove the credentials they created or shared. NHIMG’s Top 10 NHI Issues and the vendor-reported figure that 91% of former employee tokens remain active after offboarding both underscore how quickly stale access persists when revocation is not automated.

For organisations with heavy app sprawl, the practical answer is tiered governance: automate what is connected, compensate what is not, and review exceptions on a fixed cadence. The objective is not perfect coverage on day one. It is reducing the number of identities, tokens, and sessions that can survive after a role change or departure without detection.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Manual offboarding leaves stale NHIs active after departure or role change.
OWASP Agentic AI Top 10A-04Unmanaged apps can expose agent-like access paths that persist beyond intent.
CSA MAESTROIAM-02MAESTRO addresses identity lifecycle gaps across distributed workloads and tools.
NIST CSF 2.0PR.AC-1Access control must be managed and revoked consistently across all systems.
NIST AI RMFGOVERNGovernance is needed to ensure lifecycle responsibilities are assigned and enforced.

Automate NHI revocation and verify every token, key, and service account is removed at offboarding.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org