Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when access requests and access reviews…
Governance, Ownership & Risk

What happens when access requests and access reviews are managed in separate workflows?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Governance, Ownership & Risk

When requests and reviews are separate, teams often fix symptoms after access has already been granted rather than controlling the grant process itself. That split creates extra ticketing, inconsistent approvals, and more manual handoffs between security and IT. A unified approach helps teams govern both who gets access and whether that access should continue.

Why separating requests from reviews creates governance drift

Access requests decide whether access should be granted now; access reviews decide whether existing access still makes sense later. When those workflows are split, the organisation no longer evaluates the same entitlement through one continuous governance path. That gap makes it easier for approvals to become stale, for reviewers to inherit incomplete context, and for exceptions to survive long after the original need has changed.

The practical problem is not just duplication. A separate review process often starts with a list of accounts or entitlements that has already drifted from the original request record, so reviewers are forced to judge access without the full approval rationale, business owner, or expiry context. In access governance terms, that weakens the connection between lifecycle control and recertification, which is exactly where stale privilege tends to accumulate.

Where this matters most is in environments with many entitlements, shared approval chains, or frequent role changes. The more handoffs that exist between ticketing, provisioning, and review, the more likely teams are to approve based on operational convenience rather than current need. A unified workflow reduces that friction because the same system can preserve request intent, approval evidence, expiration, and review outcome as one auditable record.

  • Requests answer: should access start?
  • Reviews answer: should access continue?
  • Separate systems often lose the thread between those two decisions.

Operational failure modes teams should expect

When access requests and access reviews are not connected, several predictable failure modes appear. Approvals can be granted in one tool but never surfaced in the review queue, reviewers may see entitlements without knowing why they were granted, and revocation actions can be delayed because no single team owns the end-to-end record. That creates extra manual work and makes it harder to enforce least privilege consistently.

This is also where the control weakens under scale. The more identities, applications, and business units involved, the more “normal” it becomes to accept partial visibility and human reconciliation. NHIMG’s Top 10 NHI Issues highlights visibility gaps, excessive permissions, and ownership problems as recurring governance failures, and those same patterns show up whenever access decisions are fragmented across workflows.

In practice, a split workflow often produces three symptoms: duplicated approvals, inconsistent review decisions, and slow removal of access that no longer has a current owner. If the request path and review path do not share the same identity, entitlement, and approval metadata, teams tend to optimise for getting the ticket closed rather than for preserving access discipline.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v85 — Account ManagementSeparating requests and reviews weakens account governance and recertification.
6 — Access Control ManagementThe question is about how access decisions are controlled across grant and review workflows.
Recommendation — Centralise account approval and review records so access can be governed and re-certified from one source. Enforce least-privilege access decisions through a single access control workflow.
NIST CSF 2.0PR.AC — Access ControlUnified request and review workflows directly support access governance and ongoing entitlement control.
GV.OC — Organizational ContextWorkflow separation creates governance drift between business justification and access ownership.
GV.RM — Risk Management StrategySplit workflows increase stale-access risk and weaken continuous risk treatment.
Recommendation — Align access grants and recertification under PR.AC so entitlement decisions stay consistent. Define clear ownership for request and review outcomes so governance stays traceable. Treat access review drift as a managed risk and set escalation thresholds for overdue recertification.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementAccess workflows often govern credentials and access material that must be reviewed as part of lifecycle control.
NHI-04 — Lifecycle and OffboardingThe answer depends on connecting access grant with continued entitlement review and eventual removal.
NHI-06 — Privilege and AuthorizationSeparate workflows often allow excessive or outdated access to persist across approval cycles.
Recommendation — Track credential-bearing access objects through one lifecycle so grant and review stay linked. Bind access review to lifecycle milestones so stale entitlements are removed on schedule. Use one authorization path for both initial approval and ongoing privilege validation.

Practitioner Guidance

What to verify: Confirm that the approval record, entitlement source, expiry date, and reviewer evidence are linked to the same access object. If those elements live in separate systems, treat that as a control weakness, not just a process inconvenience.

What to prioritise: Tie request, grant, and recertification to one ownership model so the approver, reviewer, and revoker are all operating from the same authoritative data. That matters most for privileged access, long-lived entitlements, and access paths that are hard to reconstruct after the fact.

Common mistake: Treating reviews as a cleanup mechanism for poor request design. If reviews are expected to catch bad grants routinely, the workflow is already compensating for a broken grant process.

Practitioner takeaway: The goal is not to run two access controls in parallel, it is to make access approval and access continuation part of one governed lifecycle so stale privilege is prevented, not merely discovered later.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org