When the same people can request, approve, and benefit from access, governance loses its control point. That creates conflict of interest, weakens review quality, and makes toxic combinations harder to stop. Attackers look for exactly this kind of shortcut because it lets them turn ordinary approval workflows into a path around policy.
Why separating approval from ownership matters in identity governance
Approval and ownership do different jobs. Ownership establishes who is accountable for the access relationship, while approval is the control that tests whether the request is justified. If the same person can do both, governance turns into a self-affirming process: the check no longer has an independent challenger, and access decisions become easier to rationalise than to question.
That separation is especially important for entitlement-heavy environments, where access requests, role changes, exceptions, and recertifications all feed the same control plane. When ownership is blurred with approval, organisations often lose the ability to answer a basic audit question: who is accountable for the business need, and who is independently responsible for stopping it?
The practical pattern is not just about org charts. It is about control design. A clean identity governance model needs one party to own the resource or entitlement, and a separate party or function to approve the request, particularly for elevated access, shared access, and access that can be combined into toxic combinations. NHIMG’s IAM and IGA Basics explains why the distinction between request, approval, and governance is foundational rather than cosmetic.
What breaks when the same person can request, approve, and benefit
Once request, approval, and benefit are collapsed into one path, review quality drops because the approver is no longer independent from the outcome. That creates conflict of interest, makes rubber-stamping more likely, and allows exceptions to become routine. Over time, the organisation stops enforcing policy and starts documenting whatever already happened.
It also weakens access governance at the point where it matters most, after the request but before the privilege is granted. If the owner is the beneficiary, they have every incentive to prioritise convenience over restraint. That is how excessive access, weak role hygiene, and stale exceptions persist even when a process appears to exist.
For a governance model to stay credible, the approval path must be able to challenge the request, not merely record it. NHIMG’s Segregation of Duties (SoD) Guide is useful here because it shows how toxic combinations emerge when conflicting actions are not separated. The same principle applies whether the access is for a person, a shared account, or a non-human identity.
How attackers exploit weak approval and ownership boundaries
Attackers like governance shortcuts because they reduce the number of barriers between an initial foothold and usable access. If a requester can also influence approval, an attacker who compromises that user can often turn an ordinary workflow into a policy bypass. In practice, that can mean obtaining access that looks formally approved but was never independently challenged.
Weak separation also creates an opportunity for abuse of trust relationships. If ownership records are poor or approval authority is too broad, adversaries can push requests through with minimal scrutiny, then use the resulting access for persistence, privilege escalation, or lateral movement. The control failure is administrative, but the consequence is operational and often security-critical.
NHIMG’s Top 10 NHI Issues and Ultimate Guide to NHIs, Key Challenges and Risks both reinforce the same pattern: when ownership, lifecycle discipline, and access oversight are weak, over-privilege and unmanaged access become easier to sustain.
Risk and Threat Considerations
When approval and ownership are not separated, the main risk is not just process weakness, it is control failure at the exact point where governance should stop bad access from becoming normal. Conflict of interest, rubber-stamping, and toxic combination abuse all increase, especially where access can be accumulated across roles or reused across systems.
Failure mechanism: The same individual or team can influence the request, approve it, and benefit from the resulting access, which removes independent challenge and makes policy exceptions easy to normalise.
Impact: Excessive access is more likely to be granted and retained, audit evidence becomes less trustworthy, and an attacker who compromises one insider or workflow can convert the weakness into unauthorised access or privilege escalation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | Separating approval from ownership prevents self-approval and conflicting access decisions. |
| AC-6 — Least Privilege | Approval-ownership separation helps stop excessive access from being granted and retained. | |
| IA-5 — Authenticator Management | Identity governance failures often involve poor control of credentials and access-enabling material. | |
| Recommendation — Enforce AC-5 so access requests cannot be approved by the same party that benefits from them. Apply AC-6 to ensure approvals grant only the minimum access needed for the stated business purpose. Manage authenticators so access governance decisions are not undermined by uncontrolled credentials. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access control management depends on independent approval and clean ownership boundaries. |
| CIS-5 — Account Management | Account governance fails when owners can approve their own access changes and exceptions. | |
| Recommendation — Use CIS-6 to separate request, approval, and entitlement ownership for sensitive access. Use CIS-5 to maintain accountable ownership for access requests, reviews, and exceptions. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control requires independent governance over who may approve and receive access. |
| A.5.18 — Access rights | Access-right decisions need accountable ownership and independent approval to stay trustworthy. | |
| Recommendation — Apply A.5.15 to keep approval authority separate from entitlement ownership. Apply A.5.18 to review and authorise access rights through independent decision paths. | ||
Practitioner Guidance
What to prioritise: Separate entitlement ownership from approval authority first for privileged, shared, and high-impact access. If the business owner is also the beneficiary, require a different approver or an independent control such as a SoD check before the grant is completed.
What to verify: Check whether your workflow records a real approval decision or just a routed acknowledgement. Good governance produces evidence that someone other than the beneficiary could challenge the request, reject it, or require compensating controls.
Common mistake: Treating “manager approval” as sufficient when the manager is also the access owner, budget owner, or direct beneficiary. That arrangement often satisfies form while defeating function.
Practitioner takeaway: If approval and ownership are not independent, the workflow may still look controlled while functioning as self-approval. The test is whether the process can say no to the person who most wants the access.
Related resources from NHI Mgmt Group
- What happens when data discovery and access approval are separated from governance workflows?
- Why is it important to integrate identity and data governance?
- What is the difference between role-based access and API key governance for NHI security?
- What breaks when AI model ownership is separated from access governance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org