Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when service accounts and integrations are…
Governance, Ownership & Risk

What breaks when service accounts and integrations are not continuously monitored in ERP systems?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Governance, Ownership & Risk

Without continuous monitoring, orphaned or inactive identities can stay live long after their business purpose ends. That creates hidden attack paths, weakens audit readiness, and allows excessive permissions to persist. In practice, teams lose visibility into who or what can change workflows, move data, or touch regulated financial records, which raises both security and compliance exposure.

Why This Matters for Security Teams

ERP service account and third-party integrations often have broader reach than their owners realise, because they can post journal entries, trigger approvals, sync payroll data, or update master records. When continuous monitoring is missing, dormant accounts and stale connectors remain active, even after a vendor change, project closure, or staff turnover. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts, which makes this a common blind spot rather than an edge case. The issue is not simply excess access, but loss of control over business-critical workflows.

That matters because ERP environments are both operational and regulated. A forgotten integration can become a backdoor into financial records, and an over-permissioned service account can bypass the normal approval chain entirely. Current guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls supports ongoing account oversight, not one-time provisioning. In practice, many security teams discover these issues only after an audit exception, a failed access review, or an incident tied to an account no one remembered existed.

How It Works in Practice

Continuous monitoring means treating ERP service accounts and integrations as living identities with their own lifecycle, owners, and risk signals. The operational goal is to know what each account can do, when it was last used, whether its scope still matches the business process, and whether its secrets, certificates, or tokens are still valid. That is why lifecycle visibility is central to the NHI Lifecycle Management Guide and the broader lessons in the Ultimate Guide to NHIs — Key Challenges and Risks.

In practice, teams should monitor several conditions continuously:

  • Account activity, including last authentication, last transaction, and unusual access timing.
  • Permission drift, such as role expansion after patching, testing, or support escalation.
  • Integration health, including token age, secret rotation status, and certificate expiry.
  • Ownership changes, especially when business process owners, vendors, or administrators change.
  • Offboarding events, where accounts should be disabled or re-scoped immediately.

Security teams should also correlate ERP logs with identity governance, SIEM alerts, and change management records. That makes it easier to distinguish a legitimate month-end posting job from a stale connector that suddenly starts touching sensitive tables. For high-risk environments, current practice is to pair continuous discovery with periodic attestations and automated revocation where there is no verified business need. The Top 10 NHI Issues highlights why this is especially important when secrets are embedded in code, CI/CD tools, or vendor-managed middleware. These controls tend to break down when ERP integrations are tightly coupled to legacy processes and no team has clear ownership of the account after deployment.

Common Variations and Edge Cases

Tighter monitoring often increases operational overhead, requiring organisations to balance faster detection against change fatigue, noisy alerts, and ownership ambiguity. That tradeoff is especially visible in ERP estates where one service account may support multiple jobs, regional instances, or partner integrations.

There is no universal standard for this yet, but current guidance suggests treating shared or cross-functional accounts as higher risk and reviewing them more often than single-purpose workloads. Temporary project integrations are another edge case: they are usually created for convenience, then left in place because the business process was never formally retired. A similar problem appears with outsourced support connectors, where access is technically legitimate but poorly scoped. The most serious failures often involve secrets that never rotate, because even a disabled dashboard account may remain usable through an API key or certificate. NHIMG’s breach research, including the 52 NHI Breaches Analysis, shows how often compromise starts with identities that were assumed to be low-risk or temporary. Where ERP platforms rely on custom middleware or vendor-managed scripts, continuous monitoring can miss the true control point unless the integration path is mapped end to end.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Service accounts need continuous discovery and ownership to avoid hidden identity sprawl.
NIST CSF 2.0PR.AC-1Continuous monitoring supports timely account control and access validation.
NIST AI RMFGOVERNOngoing oversight aligns with governance for changing automated system behaviour and risk.
CSA MAESTROID-02Agent and workload identity lifecycle controls map well to ERP integration monitoring.
NIST Zero Trust (SP 800-207)SC-7Zero trust requires continuous verification of identities and connections, including service accounts.

Inventory every ERP service account and integration, then assign an accountable owner and review cadence.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org