When deprovisioning is delayed or handled manually, access can remain active long after it should be removed. That leaves unnecessary entry points for unauthorized use, especially in environments with many connected applications. Over time, stale permissions also complicate audits because the identity record no longer matches the actual access state.
What goes wrong when offboarding is manual or delayed
When deprovisioning is not automated, access often persists after the business need has ended. That creates a quiet control gap: the account or token still works even though the person no longer should. In practice, the longer the delay, the greater the chance that stale access is overlooked, reused, or inherited by someone else during churn.
Manual removal also scales poorly in connected environments. If a user has access across SaaS apps, internal tools, and cloud systems, each disconnected revocation step becomes another place where access can be left behind. That is why lifecycle management is a core part of NHI governance, not just an administrative cleanup task, as reflected in the NHI Lifecycle Management Guide and the broader Ultimate Guide to NHIs.
Automated offboarding also matters because remediation delay is common. NHIMG research in The 2025 State of NHIs and Secrets in Cybersecurity reports that 91.6% of secrets remain valid five days after notification, which shows how easily stale access can outlive the event that should have triggered revocation.
Why stale access becomes a security and audit problem
Inactive access is risky because it widens the attack surface without adding business value. An old account, API key, token, or entitlement can become an unintended entry point for unauthorized use, especially if the former user leaves on poor terms or the credential is exposed elsewhere. The problem is not only compromise, but also unnecessary privilege persistence.
From an audit perspective, manual deprovisioning breaks the link between the identity record and the actual access state. Reviewers then have to reconcile records across systems, and that slows access certification, exception handling, and incident investigation. The issue is especially visible in environments with excessive permissions or shared access paths, which the Ultimate Guide to NHIs, key challenges and risks section treats as structural governance weaknesses rather than isolated mistakes.
There is also a scale effect. In large estates, a small delay multiplied across many departures creates a backlog of dormant access, and dormant access is hard to distinguish from legitimate access unless revocation is automatic and traceable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Delayed revocation leaves non-human access active after need ends. |
| NHI-07 — Long-Lived Secrets | Manual deprovisioning often leaves credentials valid long after departure. | |
| Recommendation — Automate offboarding so access and secrets are revoked when the lifecycle event occurs. Shorten credential lifetimes and revoke reusable secrets during offboarding. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Accounts must be disabled or removed when access is no longer needed. |
| IA-5 — Authenticator Management | Revocation must cover passwords, tokens, keys, and other authenticators. | |
| Recommendation — Disable or remove accounts promptly when the business need ends. Revoke or replace authenticators as part of the offboarding process. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle control is central to preventing stale access. |
| Recommendation — Maintain timely account disablement and periodic review of active access. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity lifecycle governance requires timely removal of no-longer-needed access. |
| A.5.18 — Access rights | Access rights should be revoked when employment or need changes. | |
| Recommendation — Remove identities and related access rights promptly when they are no longer required. Revoke access rights at the point they are no longer justified. | ||
Practitioner Guidance
What to verify: Confirm that revocation is triggered from the source-of-truth lifecycle event, not from a manual ticket that can stall in a queue. If removal depends on a person remembering each downstream system, the control is already weak.
What good looks like: Offboarding should remove active access quickly enough that the identity record, entitlement state, and authentication material converge within the same operational window. Where systems cannot revoke immediately, teams should track and exception-manage the lag explicitly rather than assuming cleanup happened.
Common mistake: Treating deprovisioning as an HR exit checklist instead of an access-control control. The business event is the trigger, but the security requirement is the actual removal of access and any reusable credentials or tokens tied to it.
Practitioner takeaway: The real risk is not just delayed cleanup, it is the period in which an ex-employee or former user still has valid access that the organisation no longer intends to trust.
Related resources from NHI Mgmt Group
- What is the difference between rotating a secret and revoking access?
- What is the difference between rotation and deprovisioning for NHIs?
- Who is accountable when automated deprovisioning does not happen after access review?
- What should organisations do when automated role assignment gives users too much access?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org