When teams rely only on assigned access, they miss shadow over-provisioning, stale entitlements, and license mismatches that create audit and cost exposure. They also lose visibility into whether SoD rules are being violated in practice. The result is weaker governance, poorer remediation prioritisation, and less defensible compliance evidence.
Why This Matters for Security Teams
Assigned access is a planning assumption. Real usage data is evidence. When organisations govern service accounts, API keys, and agent identities from what was provisioned instead of what was actually used, they lose the ability to spot over-provisioning, dormant entitlements, and privilege creep before those issues become incidents. NHI Mgmt Group notes that 97% of NHIs carry excessive privileges, which makes this gap especially dangerous in practice, not just in theory.
This matters because audit teams care about actual privilege exposure, not the spreadsheet version of access. If a token exists but is never used, it still creates attack surface, license cost, and remediation debt. If an entitlement is used far beyond its intended scope, assigned access reviews may falsely show compliance while operational reality diverges. Current guidance from OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls both points toward evidence-driven access governance rather than static assignment alone. In practice, many security teams encounter the misuse only after audit findings, cost overruns, or an incident expose how little the assigned model reflected reality.
How It Works in Practice
Usage-based governance starts by collecting telemetry from identity providers, cloud audit logs, vaults, SaaS platforms, CI/CD systems, and workload runtimes. The goal is to answer three questions: what was assigned, what was actually used, and what was used in a way that matches policy. That distinction is critical for NHIs because service accounts and API keys often persist long after their original purpose has changed, and assigned access reviews alone do not reveal whether a secret is still active.
Teams typically compare assigned permissions to observed activity, then classify each entitlement as active, dormant, excessive, or mis-scoped. This is where the Ultimate Guide to NHIs is useful as a baseline reference for lifecycle, visibility, and offboarding controls. The Ultimate Guide to NHIs — Key Research and Survey Results also shows how weak visibility remains across environments, which is why usage evidence is often missing when it is needed most.
- Use access logs to confirm whether each NHI actually exercised the assigned permission.
- Flag entitlements with no observed use over a defined review window as candidates for removal or step-up validation.
- Prioritise high-risk permissions first, especially write, delete, admin, and lateral movement capabilities.
- Cross-check usage with business purpose so valid but rare activity is not mistaken for excess.
- Feed results into recertification, secret rotation, and offboarding workflows.
For implementation detail, OWASP Non-Human Identity Top 10 helps frame common identity failure modes, while NIST SP 800-53 Rev 5 Security and Privacy Controls supports the control expectation that access must be reviewed, monitored, and adjusted based on evidence. These controls tend to break down when logs are incomplete across SaaS, cloud, and local tooling because the organisation cannot reconstruct actual entitlement use end to end.
Common Variations and Edge Cases
Tighter usage-based control often increases operational overhead, requiring organisations to balance governance accuracy against telemetry quality and review effort. That tradeoff is especially visible in environments with shared service accounts, ephemeral workloads, or infrequent batch jobs, where low usage does not necessarily mean unnecessary access.
There is no universal standard for this yet, but current guidance suggests treating usage data as a decision input, not an absolute verdict. A dormant entitlement may be acceptable for break-glass access, disaster recovery, or monthly reconciliation jobs. Conversely, a frequently used entitlement may still be inappropriate if the usage spans systems outside its intended scope. The practical question is not only whether access exists, but whether the pattern of use matches the approved purpose.
Teams also need to distinguish between human-style recertification and machine-style governance. Assigned access models can work for stable roles, but they are weaker for NHI estates where permissions change faster than review cycles. That is why usage data should inform not just removals, but also license cleanup, secret rotation, and privilege redesign. When organisations ignore this distinction, they end up preserving access that looks justified on paper while real operational behaviour continues to drift. For deeper breach context, the 52 NHI Breaches Analysis shows how identity misuse often persists unnoticed until after damage is visible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 | Assigned access without usage evidence hides excessive or stale NHI permissions. |
| NIST CSF 2.0 | PR.AA-04 | Access rights should be monitored and adjusted using real identity evidence. |
| NIST AI RMF | Usage-based governance supports accountability for autonomous workloads and their changing behaviour. | |
| CSA MAESTRO | ID.1 | Agentic and workload identities need lifecycle visibility beyond assigned permissions. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management must be based on current use, not only provisioning records. |
Use observed activity to recertify NHI permissions and remove entitlements that are never exercised.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on coarse access lists instead of policy-driven authorization?
- What breaks when organisations rely on monitoring alone instead of real-time enforcement for Salesforce data security?
- What breaks when organisations rely on documentation instead of real identity activity data?
- What breaks when organisations rely on indefinite access for privileged systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org