Point-in-time governance leaves stale entitlements, orphaned accounts, and unused privileges in place long after business conditions change. That gap weakens compliance, increases audit findings, and creates hidden access paths for attackers. Effective programmes need ongoing certification, revocation, and policy enforcement across joiner, mover, and leaver events.
Why This Matters for Security Teams
Onboarding-only governance creates a false sense of control because access is approved once and then treated as stable, even though roles, vendors, systems, and risk change continuously. That leaves stale entitlements, orphaned accounts, and excessive privileges active long after they stop being justified. The problem is especially visible in NHI estates, where a recent NHIMG research summary found that 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks.
Security teams often miss the fact that joiner-only controls do not protect the access lifecycle. A user or workload can be cleanly provisioned on day one and still become over-entitled by day thirty, whether through role drift, project changes, vendor handoffs, or automation that never got deprovisioned. Frameworks such as the NIST Cybersecurity Framework 2.0 and the OWASP Non-Human Identity Top 10 both point toward continuous control, not point-in-time approval.
In practice, many security teams encounter the real exposure only after an audit finding, a failed access review, or a breach investigation shows that “approved” access had quietly outlived its business purpose.
How It Works in Practice
lifecycle governance works when identity decisions are tied to ongoing business context, not just the initial account request. That means every meaningful change in employment status, project assignment, vendor relationship, or machine workload should trigger review, reduction, or revocation. For human users, this usually spans joiner, mover, and leaver events. For NHIs, it also includes key rotation, secret expiry, token revocation, and ownership changes across CI/CD, cloud, and API ecosystems.
Practitioners should treat onboarding as the start of control, not the finish. A workable programme usually combines:
- Periodic access certification for privileged and sensitive access
- Automatic revocation when accounts are unused, expired, or unowned
- Short-lived credentials and secret rotation for non-human identities
- Policy checks aligned to business role, system sensitivity, and time bound need
- Logging that proves access was reviewed and removed, not merely approved
That approach is consistent with the control intent behind NIST CSF 2.0 and the control discipline described in NHI Lifecycle Management Guide. For teams managing secrets at scale, the Guide to the Secret Sprawl Challenge is a useful reference because stale credentials are often the technical symptom of weak lifecycle governance. These controls tend to break down in environments with unmanaged service accounts, shadow IT, or legacy applications that cannot support automated deprovisioning because ownership and revocation paths are unclear.
Common Variations and Edge Cases
Tighter lifecycle governance often increases operational overhead, requiring organisations to balance stronger assurance against the friction of reviews, exceptions, and service disruption. That tradeoff is real, especially where business teams depend on always-on access, but the alternative is allowing dormant privilege to accumulate unnoticed.
Best practice is evolving, and there is no universal standard for how often every entitlement should be recertified. High-risk access usually warrants shorter review cycles, while low-risk, low-impact access may be reviewed less often. The key is to avoid treating all identities the same. An inherited admin role, a third-party OAuth grant, and a dormant contractor account do not carry the same risk profile.
For NHIs, lifecycle failures often show up differently than for human users. Secrets may never “leave” unless rotation is enforced, so onboarding-only governance can be especially dangerous when systems issue long-lived tokens or certificates. The Guide to NHI Rotation Challenges helps illustrate why rotation and revocation are inseparable from governance. The practical lesson is simple: if access can be created in minutes but removed only manually, the organisation is carrying avoidable residual risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Addresses stale NHI credentials and weak rotation across the access lifecycle. |
| NIST CSF 2.0 | PR.AA-01 | Identity lifecycle control is central to governing who can access what over time. |
| NIST SP 800-63 | IAL2 | Lifecycle governance depends on maintaining assurance as identity context changes. |
| NIST Zero Trust (SP 800-207) | AC-2 | Zero Trust requires continuous access decisions, not one-time onboarding approval. |
| NIST AI RMF | Lifecycle governance supports ongoing accountability and risk monitoring for AI-driven access. |
Apply governance and monitoring processes that reassess identity risk as conditions change.
Related resources from NHI Mgmt Group
- What breaks when access certifications and lifecycle controls are missing from SAP identity governance?
- What breaks when organisations rely on always-on desktop access instead of just-in-time access for remote users?
- Why do dynamic, context-based access policies work better than static groups for modern identity governance?
- Why do organisations struggle to maintain effective identity governance across fragmented application environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org