Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do teams get wrong about discovery when…
Governance, Ownership & Risk

What do teams get wrong about discovery when they try to reduce privileged access risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Governance, Ownership & Risk

Many teams focus on features before they solve discovery. If you do not know where privilege exists, who uses it, and which privileges should be revoked, you cannot build an effective zero standing privilege model. The common mistake is treating PAM as a vault problem instead of an onboarding, inventory, and governance problem.

Discovery is a governance problem before it is a tooling problem

The biggest discovery failure is starting with feature selection instead of answering three basic questions: where privileged access exists, who can use it, and what should be removed or reduced. That is why discovery has to cover human and non-human privileged access path, standing permissions, and the accounts or keys that quietly accumulate authority over time. The lifecycle view of non-human identities is useful here because discovery is the intake mechanism for everything that follows.

Teams also underestimate how often the inventory is fragmented across directories, cloud consoles, CI/CD, vaults, application code, and third-party integrations. If discovery is scoped only to a single vault or PAM queue, you miss the broader set of credentials and entitlements that define actual privileged reach. The operational objective is not just to find accounts, it is to establish ownership, purpose, and revocation authority for each one.

A useful benchmark for why this matters is that only 5.7% of organisations report full visibility into their service accounts, which shows how often discovery gaps are the root problem rather than a later control failure.

What teams miss when they treat discovery as a scan

Discovery is often reduced to listing accounts or secrets, but that only creates an inventory, not control. Useful discovery has to answer whether the privilege is still needed, whether it is shared, whether it is excessive, and whether the account is tied to a legitimate owner and lifecycle. That is why a discovery process must connect visibility gaps, overprivilege, and unmanaged credentials rather than treating them as separate problems.

The same mistake shows up when teams equate “found” with “governed.” A dormant account, a long-lived API key, and an actively used production service account are all privileged objects, but they require different decisions. Discovery should therefore feed classification, ownership assignment, and recertification, not just a report.

Teams also miss that discovery quality degrades quickly when it depends on manual self-reporting. If application owners cannot identify their own service accounts or explain why a credential still exists, the issue is not a missing dashboard, it is a broken control model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Discovery and InventoryDiscovery and inventory are central to privileged access risk reduction.
NHI-02 — Lifecycle and OffboardingDiscovery must feed ownership, revocation, and offboarding decisions.
NHI-03 — Secrets and Credential ManagementDiscovery often misses secrets outside the vault and code repositories.
Recommendation — Inventory all privileged identities and secrets before enforcing least privilege or revocation. Tie discovered privileges to owners and remove access when purpose no longer exists. Locate exposed secrets and bring them under managed rotation and control.
NIST CSF 2.0ID.AM-01 — Physical devices and systems inventoriedAsset inventory is the prerequisite for understanding where privileged access exists.
PR.AA-01 — Identities and credentials managedDiscovery must identify privileged identities and their credentials before control can be enforced.
Recommendation — Maintain a complete inventory of systems that can grant or store privileged access. Identify privileged identities and manage their credentials through a governed lifecycle.
CIS Controls v85.3 — Account Inventory and ControlAccount inventory is the concrete control gap behind discovery failures.
6.1 — Establish Access Control PolicyDiscovery must support access policy decisions about who should retain privilege.
Recommendation — Maintain an authoritative inventory of privileged accounts and remove unauthorized ones. Define and enforce access rules that limit privileged access to business need.
NIST Zero Trust (SP 800-207)SC-7 — Policy Enforcement and Least Privilege AccessDiscovery is required to enforce least privilege in a zero trust model.
Recommendation — Use discovery outputs to enforce least-privilege access decisions at policy enforcement points.

Practitioner Guidance

What to prioritise: Start with the inventory questions that drive action, not the ones that produce the longest list. For each privileged account or secret, determine owner, system of record, business purpose, last used date, and revocation path before you discuss vaulting or rotation.

What to verify: A credible discovery process should produce a revocation-ready map, not a discovery spreadsheet. If a team cannot show how it would disable a privileged path without breaking a production dependency, the discovery work is incomplete.

Common mistake: Assuming that PAM implementation will solve undocumented privilege. Tooling can enforce policy only after the organisation knows what privilege exists and who is accountable for it. Without that, PAM becomes a control layer over unknown risk.

Practitioner takeaway: The real test of discovery is whether it reduces the organisation’s unknown privileged surface enough to make least-privilege decisions possible.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org