Manual handling creates stale access, inconsistent permissions, and avoidable exposure when employees join, move roles, or leave. It also increases admin workload and makes it harder to keep shared credentials aligned to business needs. In practice, manual sharing and removal processes weaken governance long before they create a visible incident.
Why This Matters for Security Teams
Manual password sharing and offboarding turn identity governance into a queue of human follow-ups, which is fragile at any meaningful scale. When access is granted through spreadsheets, chat messages, or memory, the organisation loses a reliable record of who can use what, when it was revoked, and whether a shared credential still matches business need. NHI Management Group’s NHI Lifecycle Management Guide frames lifecycle control as a core security function, not an administrative convenience.
The real risk is not just inconvenience. Shared passwords and delayed removals create standing access that outlives the job role, the project, or the employee. That weakens least privilege, complicates audit evidence, and makes incident response slower because no one can quickly prove who had access at the time of exposure. The NIST Cybersecurity Framework 2.0 treats identity governance as an operational control, and that becomes harder when the control relies on manual follow-through. In practice, many security teams discover the gap only after a former employee, contractor, or shared account is still active long after offboarding should have closed it.
How It Works in Practice
Manual handling usually fails in three places: request, transfer, and revocation. During onboarding, teams often share a password directly with a new hire or place it in an email or ticket. During role change, the old access is rarely removed before the new access is added. During offboarding, revocation depends on someone remembering every system, vault, API key, and shared account tied to that person. NHI Management Group’s Ultimate Guide to NHIs notes that only 20% of organisations have formal processes for offboarding and revoking API keys, which shows how often lifecycle discipline is missing even before the environment becomes complex.
For growing organisations, the better pattern is to remove direct password sharing wherever possible and replace it with governed access flows. That means using a password manager or secrets platform with role-based access, time-bound approvals, and audit logs. It also means tying access to joiner-mover-leaver workflows so revocation happens automatically when an employee changes teams or exits. For high-risk systems, the control should be stronger: unique accounts, just-in-time access, MFA, and no shared administrative passwords. This aligns with the NIST CSF idea of maintaining identity proofing, access enforcement, and periodic review as part of normal operations rather than after-the-fact cleanup.
- Inventory every shared credential, service account, and emergency access path.
- Assign an owner for each credential so revocation is not ambiguous.
- Automate deprovisioning when HR status changes or access approvals expire.
- Replace informal password transfer with approved access workflows and logging.
- Review privileged access on a fixed cadence and after every role change.
The Top 10 NHI Issues page is useful here because shared credentials and poor lifecycle handling are rarely isolated problems. They usually sit alongside over-privilege, secret sprawl, and weak visibility. These controls tend to break down when access is distributed across legacy systems, local admin accounts, and contractor-managed environments because no single process owns the full lifecycle.
Common Variations and Edge Cases
Tighter offboarding often increases administrative overhead, requiring organisations to balance speed of business with control coverage. That tradeoff is real, especially where operations teams need emergency access or where legacy applications cannot support modern identity workflows. Current guidance suggests using compensating controls rather than accepting manual sharing as normal practice.
In smaller teams, the most common exception is a temporary shared credential for a break-glass scenario. That can be acceptable only if it is tightly monitored, rotated after use, and stored in a controlled system. In larger environments, the harder edge case is third-party access. Contractors and partners frequently keep access longer than internal employees because ownership is split across procurement, IT, and business teams. The lifecycle problem becomes even more visible when a single credential is reused across multiple systems, because revoking it can cause unexpected outages.
Research from the 2025 State of NHIs and Secrets in Cybersecurity found that 91% of former employee tokens remain active after offboarding, which is a strong signal that manual removal does not scale. The practical answer is to minimise shared credentials, shorten credential lifetime, and make every exception explicit, logged, and reviewable. There is no universal standard for every legacy case yet, but the direction is clear: if a password can be shared casually, it can also outlive its owner.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Addresses NHI inventory and ownership gaps that manual sharing obscures. |
| OWASP Agentic AI Top 10 | A-04 | Shows how unmanaged access paths create unsafe privilege in autonomous workflows. |
| CSA MAESTRO | AIC-02 | Covers lifecycle control and accountability for identities used by automated systems. |
| NIST CSF 2.0 | PR.AC-4 | Maps directly to least privilege and access review requirements. |
| NIST Zero Trust (SP 800-207) | Supports continuous verification instead of relying on shared static trust. |
Inventory all shared credentials, assign owners, and revoke any secret without a clear business owner.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org