Teams often treat periodic reviews and email-based JML workflows as if they were sufficient controls. In practice, those methods are slow, noisy, and easy to rubberstamp. They lag behind real identity changes, fail to reflect current access patterns, and leave access requests, revocations, and remediation stuck in queues while risk continues to accumulate.
Why Quarterly Reviews and Manual JML Fail in Practice
Quarterly access reviews and email-driven joiner mover leaver workflow are often treated as control coverage, but they mostly create a governance illusion. They are periodic, slow to reflect change, and heavily dependent on busy managers or approvers making accurate judgments from stale context. When the process is manual, the control tends to measure paperwork completion more than current exposure, which is why excess access survives long after the business need has changed.
The problem is not that reviews are useless; it is that they are miscast as a precision control for a dynamic environment. Access changes do not happen on a quarterly schedule, and leaver events, role changes, temporary assignments, and cross-functional exceptions often happen faster than the review cycle. If the underlying inventory is incomplete, the review simply confirms incomplete data. The Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into service accounts, which is a useful warning for any access process that depends on complete listings before it can work.
In practice, many teams discover the weakness only after a mover event leaves old access intact or a leaver queue has already accumulated delayed revocations.
How the Process Breaks Down Operationally
Manual JML and quarterly access certification usually fail for three mechanical reasons: latency, context loss, and exception drift. Latency means the process reacts after access has already changed. Context loss means reviewers cannot reliably tell whether the access is still needed, because business justification, ownership, and system dependency are scattered across tickets, email, and spreadsheets. Exception drift means temporary approvals become de facto permanent access when no one is responsible for cleaning them up.
A better mental model is to treat JML as a lifecycle signal, not a standalone control. Joiner events should provision the minimum initial access through authoritative HR or identity triggers, movers should recalculate access when role or department changes occur, and leavers should immediately revoke access, not merely flag it for later review. That requires authoritative source alignment, short review windows for high-risk access, and automated reconciliation between identity data and actual entitlements. The Lifecycle Processes for Managing NHIs section is especially relevant here because lifecycle discipline is what prevents stale access from surviving beyond its business purpose.
- Use event-driven updates for joins, moves, and leavers rather than waiting for the next review cycle.
- Make managers attest to business need, but require system owners to validate technical access where privilege is material.
- Separate ordinary access from privileged or sensitive access, because the latter needs faster revocation and tighter evidence.
- Track exceptions with expiration dates, or they will become hidden permanent access.
Teams should also recognise that manual certification is weakest where the entitlement graph is large, the approval chain is fragmented, or the same account spans multiple systems and environments.
What Good Looks Like When Reviews Are Worth Keeping
Quarterly reviews still have value when they are used as a backstop for residual risk, not as the primary source of truth. Strong programmes focus the review on outliers: privileged access, dormant accounts, cross-environment entitlements, and access that was granted through exception. They also reduce reviewer burden by pre-populating business context, flagging stale or inherited permissions, and surfacing access that has not been used recently. That changes the review from a generic approval exercise into a targeted decision on whether the access still belongs.
The strongest JML programmes also measure speed and completeness. If leaver revocation takes days, the process is not functioning as a containment control. If movers routinely retain old permissions, role transition is not being translated into access change. The point is not to review more often for its own sake; it is to shorten the time between business change and access correction. NHI-specific guidance from OWASP Non-Human Identity Top 10 reinforces the same principle for machine access: lifecycle and privilege drift matter because access that is not actively governed tends to persist.
Tighter review cadence often increases operational overhead, so organisations must balance assurance against reviewer fatigue and queue delay. The process tends to break down when every entitlement is treated the same, because low-value certifications drown out the few decisions that actually need human scrutiny.
Risk and Threat Considerations
Weak quarterly reviews and manual JML create persistent excess access, delayed revocation, and poor accountability. That exposure matters because attackers and insiders alike benefit from access that lingers after a role change, a departure, or an exception that was never withdrawn.
Failure mechanism: The control fails when stale entitlements remain active between review cycles, when approvals are rubberstamped from incomplete context, or when revocation tickets sit in queues longer than the access should exist. In environments with shared admin paths, service accounts, or broad inherited permissions, a missed mover or leaver event can preserve a viable path to sensitive systems.
Impact: The practical result is unnecessary privilege, harder containment, and a larger blast radius if an account is abused or compromised. It also weakens audit confidence because a signed-off review may not reflect actual business need or current access state.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 5 — Account Management | Quarterly reviews and JML are account lifecycle controls that need timely disablement and access removal. |
| 6 — Access Control Management | The question centers on excess access and weak entitlement governance across periodic reviews. | |
| 8 — Audit Log Management | Effective review and remediation depend on trustworthy evidence of access use and change activity. | |
| Recommendation — Automate account lifecycle actions and verify disabled or removed access after joiner, mover, and leaver events. Restrict entitlements to current business need and revalidate high-risk access with evidence, not rote approval. Retain access-change and authentication logs so reviewers can validate whether access is still justified. | ||
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication, and Access Control | The issue is timely identity lifecycle governance and current authorization state. |
| PR.AA-04 — Access Permissions Management | Quarterly certification is meant to manage permissions, but it fails when privileges drift. | |
| Recommendation — Align access changes to authoritative identity events and remove stale permissions without waiting for a review cycle. Continuously review and reduce permissions that no longer match the user’s role or business need. | ||
| NIST Zero Trust (SP 800-207) | SP 800-207 — Zero Trust Architecture | Stale JML processes undermine continuous verification and least-privilege access assumptions. |
| Recommendation — Treat access as continuously evaluated and revoke trust when identity or context changes. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | Joiner and mover workflows depend on the quality and assurance of identity lifecycle data. |
| Recommendation — Use stronger identity proofing and lifecycle assurance where access decisions depend on current identity state. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory and Ownership | Manual reviews fail when service and machine accounts are not fully inventoried or owned. |
| Recommendation — Maintain a complete inventory with named owners so every account can be reviewed and retired on time. | ||
Practitioner Guidance
What to prioritise: Put the fastest-changing and highest-impact access under the tightest lifecycle control first. That usually means privileged access, cross-environment entitlements, and accounts tied to contractors, departures, or role changes, because those are the places where stale access becomes material fastest.
What to verify: Do not trust a review result unless the entitlement list is complete, the owner can explain why each high-risk permission exists, and revocation actually removes access in the target system. If the process only proves that someone clicked approve, treat it as evidence of activity, not evidence of control.
Decision rule: If access can materially affect production, sensitive data, or administrative functions, require event-driven correction and an expiration-backed exception path rather than waiting for the next quarterly cycle. Quarterly attestation can support governance, but it should not be the mechanism that keeps high-risk access current.
Practitioner takeaway: The real test is whether identity change and entitlement change move together quickly enough that stale access never becomes the default state.
Related resources from NHI Mgmt Group
- What do teams get wrong about joiner-mover-leaver processes?
- What do security teams get wrong about managing joiner, mover, and leaver access at scale?
- What do teams get wrong about joiner, mover, and leaver automation?
- What do teams get wrong about manual access reviews for disconnected applications?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org