Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when organisations manage disconnected apps with…
Governance, Ownership & Risk

What breaks when organisations manage disconnected apps with spreadsheets and ticket-based workflows?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

Manual handling breaks scale, consistency, and assurance. Spreadsheets and tickets cannot reliably keep pace with joiner, mover, and leaver events, so access stays outdated longer and governance data becomes incomplete. The result is higher operational burden, more audit friction, and greater exposure to errors that can leave accounts overprovisioned or unmanaged.

Why This Matters for Security Teams

Spreadsheet-driven access management looks manageable until the environment grows beyond a few applications. At that point, disconnected records, delayed approvals, and manual reconciliation stop being administrative annoyances and become security defects. The core problem is not just speed; it is that ticket queues and spreadsheets do not preserve a trustworthy, real-time view of who has access, why it was granted, and when it should be removed.

That gap matters most for non-human identities, where access often outlives the team that created it. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs, which explains why governance drifts so quickly when records live in separate files and ticket trails. The issue also shows up in broader identity programs, where the NIST Cybersecurity Framework 2.0 expects repeatable, measurable access control outcomes rather than ad hoc administration. In practice, many security teams discover stale access only after an audit request, a failed offboarding, or an incident review exposes the gap.

How It Works in Practice

Manual workflows break down because identity governance depends on synchronized lifecycle events. A joiner event should trigger access assignment, a mover event should adjust scope, and a leaver event should revoke access quickly and completely. Spreadsheets can record those events, but they cannot enforce them. Tickets can document intent, but they rarely provide the closed-loop assurance needed to confirm that the change actually happened across every application, directory, vault, and API endpoint.

For disconnected apps, the failure pattern is usually the same: each team maintains its own copy of access truth, then reconciles later. That creates lag, duplicate records, and blind spots. For NHIs, the risk is sharper because credentials may be embedded in code, automation, or CI/CD workflows. The Top 10 NHI Issues highlights how frequently organisations lose control of those identities, and the NHI Lifecycle Management Guide reinforces the need for discovery, ownership, rotation, and offboarding as linked controls, not separate tasks.

Operationally, stronger programs replace spreadsheet-only administration with authoritative sources, workflow automation, and periodic reconciliation. A practical model is to map each application to an owner, define a system of record for access decisions, and require evidence of completion for provisioning and revocation. Where service accounts are involved, teams should also track secret location, rotation status, and last-use date, because static records tend to miss dormant access that still remains valid. These controls tend to break down when apps lack APIs or when ownership is split across business units because there is no dependable way to verify completion at scale.

Common Variations and Edge Cases

Tighter access control often increases operational overhead, so organisations must balance governance strength against the friction of change management. That tradeoff becomes visible in merger activity, legacy platform estates, and application portfolios where some systems support automation while others require manual intervention.

Current guidance suggests the answer is not to eliminate tickets entirely, but to limit them to exception handling and attach them to a stronger control plane. For example, spreadsheets may still be useful as a temporary inventory during a cleanup effort, but they are too fragile to serve as the source of truth. In hybrid environments, teams often need compensating controls such as scheduled recertification, owner attestations, and reconciliation reports. For NHI-heavy environments, the Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a useful reminder that auditors look for evidence of repeatability, not informal assurances, especially when access revocation depends on humans noticing a change.

The practical edge case is local autonomy. Some organisations cannot centralise everything immediately because business units depend on niche tools or external integrations. In those cases, best practice is evolving toward minimum standards for inventory accuracy, owner assignment, and revocation timing, even if the execution path differs by application. That reduces audit friction without pretending every system can be automated on day one.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Manual workflows obscure NHI inventory and ownership across disconnected apps.
NIST CSF 2.0PR.AC-1Disconnected tickets weaken identity proofing and access assignment consistency.
NIST AI RMFGOVERNManual handling undermines accountability and repeatable governance outcomes.
CSA MAESTROIAM-02Agentic and workload identities need lifecycle controls that tickets cannot enforce reliably.

Use automated lifecycle workflows for provisioning, rotation, and offboarding of machine identities.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org