Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What goes wrong when access governance is measured…
Governance, Ownership & Risk

What goes wrong when access governance is measured by activity volume instead of identity population?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Activity volume measures traffic, not governed access. Two environments can generate similar request counts while having very different numbers of identities, ownership boundaries, and review obligations. That makes volume a poor proxy for authorization scope. Teams end up optimising for usage noise instead of knowing which identities actually need lifecycle management and access oversight.

Why activity volume fails as a governance measure

Access governance answers a different question than traffic monitoring. Request counts tell you how often systems are used, but they do not tell you how many identities exist, who owns them, whether access is still justified, or how many reviews and removals are required. A high-volume environment can still be well governed, while a low-volume one can hide serious entitlement sprawl.

The core mistake is treating observable activity as a proxy for control scope. That confuses demand with entitlement. Governance has to track the governed population, not just the amount of movement through the system, because lifecycle obligations attach to identities, roles, and permissions, not to raw request frequency.

When teams optimise to the metric, they often compress their attention onto “busy” systems and miss low-traffic identities that still carry high privilege or stale access. That creates blind spots in ownership, recertification, and offboarding, especially where access is granted once and then left to age quietly.

Why two environments can look equally busy but be governed very differently

Two systems can generate similar request volume and still represent very different governance loads. One may have a small, stable set of identities with clear ownership and tightly bounded entitlements. The other may have many dormant, shared, contractor, or service identities, each with separate review and deprovisioning obligations.

Volume hides structural differences. It does not reveal whether access is concentrated into a few accounts or spread across many, whether roles are cleanly segmented, or whether exceptions are masking excess privilege. That is why the same activity pattern can support radically different conclusions about risk and control effectiveness.

For that reason, governance metrics should distinguish population size, entitlement breadth, review coverage, and access age from operational traffic. In identity and access programmes, the useful question is not “how much access is being used?” but “how many identities and permissions must be actively governed to keep authorization accurate?”

What a better governance measure should capture instead

Better measurement starts with the governed identity population: humans, service accounts, shared accounts, external accounts, and any other identities that can retain access over time. From there, teams should look at ownership clarity, review cadence, last-use evidence, role assignment quality, and whether access removal actually happens after lifecycle events.

That gives you a measure of authorization scope rather than mere activity. It also makes it possible to compare environments fairly, because you can see whether one system is carrying more accounts per reviewer, more privileged grants per role, or more stale access per owner. Those are the conditions that determine whether governance is effective.

For lifecycle-heavy environments, access governance is usually stronger when IAM and IGA Basics are applied to the actual entitlement population, not to traffic patterns. The same applies to Access Reviews and Certification Guide, which focuses review effort on removing access instead of measuring how much the system is used.

Risk and Threat Considerations

Misreading activity volume as governance quality creates a control gap: teams may believe they have a manageable access estate when they actually have an unreviewed or under-owned identity population. That is especially dangerous where dormant, shared, or service identities can keep permissions long after the business need has changed.

Failure mechanism: A usage-based metric understates lifecycle burden, so high-risk accounts are missed during review, and stale access survives because it is not visible in volume-based reporting.

Impact: Excess privilege, delayed offboarding, and weak accountability become more likely, which increases the chance of unauthorized access, audit findings, and incident blast radius.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementAccess governance depends on knowing which accounts exist and need lifecycle control.
Recommendation — Inventory accounts and review their lifecycle so governance is based on identities, not usage volume.
NIST SP 800-53 Rev 5AC-2 — Account ManagementThe question is about governing the account population and its review obligations.
IA-5 — Authenticator ManagementStale access often persists through unmanaged credentials, tokens, and other authenticators.
Recommendation — Track and review accounts by population, ownership, and lifecycle status instead of request counts. Tie credential lifecycle to the identities they enable so old access can be removed decisively.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess-right governance requires reviewing and removing rights across the identity population.
Recommendation — Review access rights by identity population and revoke stale entitlements promptly.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingVolume-based reporting can hide identities that were never removed after lifecycle events.
NHI-05 — Overprivileged NHILow traffic can still mask excessive privilege across accounts and service identities.
Recommendation — Offboard identities by lifecycle event, not by whether their access looks active. Measure privilege breadth directly and reduce overprivileged identities even when activity is low.

Practitioner Guidance

What to prioritise: Measure governed identity count, entitlement count, privileged access count, and stale-access aging before you interpret activity volume. If a dashboard cannot show who owns the access and when it was last reviewed, it is not a governance metric.

What to verify: Confirm that review coverage maps to identities and entitlements, not to log volume. A low-activity system with many service or shared identities should trigger the same or higher governance attention than a busy system with a small, stable user set.

Common mistake: Treating “low usage” as “low risk.” Low usage can simply mean low visibility, while the real governance load sits in dormant accounts, inherited roles, and exceptions that continue to authorize access after the original need has passed.

Practitioner takeaway: Good access governance measures the size and shape of the access estate, not the amount of traffic it produces; if the metric cannot tell you who must be reviewed or removed, it is not answering the governance question.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org