Application-based reviews can miss access granted through groups, and they can miss excessive access that only becomes obvious when multiple apps are viewed together. A person may pass several app-level certifications while still holding too much access in aggregate. Without person-level and group-level reviews, coverage gaps and hidden privilege accumulation remain.
Why Application-Only Access Reviews Miss the Real Exposure
Application-based certification can answer a narrow question well: who should retain access inside one system. The problem is that identity risk is rarely confined to one application. Group membership, inherited entitlements, shared roles, and cross-application privilege combinations can leave a person looking compliant in each individual review while still being over-privileged overall. That gap matters because access decisions are cumulative, not isolated.
This is where broader identity governance changes the outcome. A person-level view reveals whether access is appropriate across the full identity, not just inside a single target system. A group-level view shows whether a hidden membership is acting as an access multiplier. Without those lenses, reviewers often approve what appears locally justified while missing the combined effect. Current guidance on identity governance and control testing increasingly favours this aggregated view because the failure mode is not just one excessive grant, but many small grants that add up.
For teams trying to reduce residual privilege, the key issue is not whether an application review exists, but whether it is capable of seeing inherited and overlapping access. In practice, many organisations only discover the gap after a user has passed multiple app-level certifications and still retains a privilege set no single reviewer intended.
How Broader Identity Governance Changes the Review Model
A broader governance model starts by treating the identity as the review unit and the application as only one evidence source. That means aggregating direct entitlements, group membership, role inheritance, and any delegated access paths before a certification decision is made. The reviewer should see the effective access picture, not just the application-local assignment list.
This matters because app-level workflows often hide the mechanism that actually grants access. A user may not hold a direct entitlement in the application, yet still reach the same data through an upstream directory group, a nested role, or a shared access policy. If the review tool only presents the application layer, the reviewer is forced to certify without understanding whether the access came from a central entitlement or an inherited path. A broader view also helps identify toxic combinations, such as a modest set of permissions spread across several systems that together enables a much larger action set.
Practically, stronger governance uses three review lenses together:
- Person-level review to assess the full access footprint of a user or service account.
- Group-level review to catch inherited access and hidden propagation paths.
- Application-level review to confirm whether the local permission remains justified.
That combined model is especially important where directory groups are reused across many applications, because a local approval can unintentionally preserve access in multiple places at once. The review evidence should therefore show not only what was approved, but also what was inherited and why it remained in scope. The Ultimate Guide to NHIs is useful here because it frames governance as a lifecycle problem, not a point-in-time approval exercise. Application-only certification breaks down when entitlement inheritance is centralised in directories or role engines, because the reviewer cannot see the true effective privilege without correlating multiple upstream sources.
Where App-Level Reviews Still Help, and Where They Do Not
Tighter certification usually improves local accountability, but it also increases reviewer workload, so organisations have to balance speed against coverage. App-level reviews still have value when a system has genuinely isolated permissions and no inheritance from groups or shared roles. In those environments, the review can confirm ownership, business need, and recertification cadence for that single application.
Best practice is evolving toward a decision rule: if access can be inherited, aggregated, or reused across systems, app-only review is not sufficient on its own. If the application is highly siloed and the entitlement model is simple, app-level certification can be one layer within a broader governance program. The dangerous case is a mixed environment, where some access is direct and some is inherited, because that creates a false sense of completeness. Reviewers may believe they have covered the identity when they have only covered a slice of the entitlement graph.
The most common failure is treating “approved in the app” as equivalent to “appropriate for the person.” Those are not the same control outcome. Where identity governance is mature, access certification is evidence of one control point, not the whole control system. Where that maturity is absent, the review process tends to preserve historical access rather than remove unnecessary privilege.
The NIST Cybersecurity Framework 2.0 supports this broader governance perspective by emphasizing ongoing identification, protection, and governance of access-related risk, while the OWASP Non-Human Identity Top 10 is especially relevant where shared groups and machine-access patterns create inherited privilege across many systems. These controls tend to break down when entitlement inheritance is distributed across directories, roles, and application-specific policy layers because no single reviewer sees the whole effective access path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory and Ownership | Identity review needs complete ownership and inventory of access paths. |
| NHI-03 — Secrets and Credential Management | Excess access review gaps often leave long-lived access paths intact. | |
| Recommendation — Maintain a complete inventory of identities and inherited access before recertifying any account. Rotate or revoke overbroad access paths when certification reveals unjustified privilege. | ||
| CIS Controls v8 | 6 — Access Control Management | The question concerns reviewing and removing excessive access across systems. |
| Recommendation — Review access centrally so inherited and cross-system permissions are removed together. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Broader identity governance is an access-control issue across the environment. |
| GV.RM — Risk Management Strategy | App-only reviews create residual privilege risk that needs governance treatment. | |
| Recommendation — Apply identity governance across users, groups, and applications to verify effective access. Treat review scope gaps as governance risk and expand certification to aggregate identity exposure. | ||
Practitioner Guidance
What to prioritise: Start with identities that have access to multiple critical applications, especially where group membership or role inheritance is involved. Those are the cases most likely to pass app-level review while still accumulating excessive privilege across the estate.
What to verify: Confirm that the certification workflow shows effective access, not only direct application grants. Reviewers should be able to see inherited entitlements, upstream groups, and any access path that would survive an app-local approval alone.
Decision rule: If a user can reach production data through more than one entitlement path, do not rely on application-only certification as the final authority. Treat it as partial evidence and require aggregation at the identity level before approval or renewal.
Common mistake: Assuming multiple clean app approvals equal low risk. In practice, the risk often sits in the overlap between systems, where each reviewer sees a narrow slice and no one sees the combined privilege.
Practitioner takeaway: The real governance question is not whether each application looks justified in isolation, but whether the identity remains least-privileged after inheritance, grouping, and reuse are taken into account.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org