Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when organisations rely only on access…
Governance, Ownership & Risk

What breaks when organisations rely only on access reviews and ignore telemetry data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Governance, Ownership & Risk

Access reviews show what a user is allowed to do, but not what they actually do. Without telemetry and change tracking, teams miss unused access, sudden spikes in activity, unusual timing, and unexpected configuration changes. Those signals are often early indicators of misuse, excess privilege, or process breakdown, and they are essential for a complete governance picture.

Why This Matters for Security Teams

Access reviews are a snapshot of entitlement, not a record of behaviour. That distinction matters because NHIs and service accounts often act continuously, at machine speed, and across systems that no reviewer can reliably reconstruct from a spreadsheet. NHI Mgmt Group’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which makes review-only governance especially fragile.

Security teams usually assume access review evidence is enough to prove control effectiveness. It is not. The real risk is hidden in the gap between approved access and actual execution: dormant accounts that suddenly activate, tokens used from new locations, privileges exercised outside normal windows, and configuration drift that never appears in a review attestation. That is why guidance in the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls emphasizes visibility, logging, and continuous monitoring alongside access governance.

In practice, many security teams discover excessive NHI activity only after an outage, a misuse investigation, or a third-party incident has already exposed the gap.

How It Works in Practice

A practical control model combines periodic access reviews with telemetry from identity providers, cloud logs, secret managers, endpoint tools, and change-control systems. Reviews still matter because they validate ownership, business purpose, and least privilege. But telemetry shows whether that entitlement is being used in a way that matches the approved design. For NHIs, the useful questions are operational: Was the token used? From where? At what time? Did the service account attempt actions outside its normal scope? Did a configuration or policy change follow the access event?

That is where continuous signals close the governance gap. For example, a service account may pass every quarterly review and still be generating failed authentication bursts, unusual read activity, or privilege escalation attempts. Those patterns are often the earliest signs of compromise or process failure. The Ultimate Guide to NHIs — Key Challenges and Risks and 52 NHI Breaches Analysis both reinforce that visibility gaps are a common precursor to major identity incidents.

  • Use access reviews to confirm ownership, purpose, and approved scope.
  • Use telemetry to verify actual use, timing, source, and volume of activity.
  • Correlate identity events with change records, CI/CD activity, and secret rotation.
  • Alert on deviations such as unused standing access, sudden spikes, or unexpected admin actions.
  • Revoke or reduce entitlements when telemetry shows persistent non-use or anomalous use.

This approach aligns governance to evidence, not assumption, and it is much harder to evade than periodic certification alone. These controls tend to break down in highly distributed environments with weak logging discipline because the telemetry is fragmented, delayed, or missing at the point of decision.

Common Variations and Edge Cases

Tighter monitoring often increases operational overhead, requiring organisations to balance better detection against privacy, log volume, and integration cost. That tradeoff becomes sharper in environments with many ephemeral workloads, third-party integrations, or shared platform accounts where simple review logic no longer maps cleanly to real activity.

There is no universal standard for which telemetry signals are sufficient, but current guidance suggests prioritising identity events, privilege changes, secret access, and configuration deltas. A stale review can still be useful if paired with activity evidence, yet a clean review without telemetry is not strong assurance. This is especially true when NHIs are rotated frequently, when pipelines generate short-lived credentials, or when one account is used by multiple automation paths. In those cases, the review may say the account is approved while the telemetry shows it is being used in ways the approver never understood.

One common edge case is service account sprawl: teams can approve the same entitlement in multiple systems and still miss cross-platform abuse. Another is delegated administration, where human approvers certify access they do not directly observe. For that reason, the Ultimate Guide to NHIs — Key Research and Survey Results is useful for framing why full visibility remains uncommon and why review-only governance routinely underestimates exposure.

In short, access reviews answer who should have access, while telemetry answers what the identity actually did, and both are needed for a credible control picture.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05Telemetry gaps hide NHI misuse and anomalous activity.
NIST CSF 2.0DE.CM-8Continuous monitoring is required to detect identity misuse beyond access approvals.
NIST AI RMFAI governance depends on monitoring behaviour, not just policy approval.
CSA MAESTROAgentic and workload governance requires runtime observability and control validation.

Use AI RMF monitoring practices to detect drift between approved access and actual system behaviour.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org