Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What happens when deprovisioning is not automated for…
NHI Lifecycle Management

What happens when deprovisioning is not automated for users who no longer need access?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: NHI Lifecycle Management

When deprovisioning is delayed or handled manually, access can remain active long after it should be removed. That leaves unnecessary entry points for unauthorized use, especially in environments with many connected applications. Over time, stale permissions also complicate audits because the identity record no longer matches the actual access state.

What goes wrong when offboarding is manual or delayed

When deprovisioning is not automated, access often persists after the business need has ended. That creates a quiet control gap: the account or token still works even though the person no longer should. In practice, the longer the delay, the greater the chance that stale access is overlooked, reused, or inherited by someone else during churn.

Manual removal also scales poorly in connected environments. If a user has access across SaaS apps, internal tools, and cloud systems, each disconnected revocation step becomes another place where access can be left behind. That is why lifecycle management is a core part of NHI governance, not just an administrative cleanup task, as reflected in the NHI Lifecycle Management Guide and the broader Ultimate Guide to NHIs.

Automated offboarding also matters because remediation delay is common. NHIMG research in The 2025 State of NHIs and Secrets in Cybersecurity reports that 91.6% of secrets remain valid five days after notification, which shows how easily stale access can outlive the event that should have triggered revocation.

Why stale access becomes a security and audit problem

Inactive access is risky because it widens the attack surface without adding business value. An old account, API key, token, or entitlement can become an unintended entry point for unauthorized use, especially if the former user leaves on poor terms or the credential is exposed elsewhere. The problem is not only compromise, but also unnecessary privilege persistence.

From an audit perspective, manual deprovisioning breaks the link between the identity record and the actual access state. Reviewers then have to reconcile records across systems, and that slows access certification, exception handling, and incident investigation. The issue is especially visible in environments with excessive permissions or shared access paths, which the Ultimate Guide to NHIs, key challenges and risks section treats as structural governance weaknesses rather than isolated mistakes.

There is also a scale effect. In large estates, a small delay multiplied across many departures creates a backlog of dormant access, and dormant access is hard to distinguish from legitimate access unless revocation is automatic and traceable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingDelayed revocation leaves non-human access active after need ends.
NHI-07 — Long-Lived SecretsManual deprovisioning often leaves credentials valid long after departure.
Recommendation — Automate offboarding so access and secrets are revoked when the lifecycle event occurs. Shorten credential lifetimes and revoke reusable secrets during offboarding.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccounts must be disabled or removed when access is no longer needed.
IA-5 — Authenticator ManagementRevocation must cover passwords, tokens, keys, and other authenticators.
Recommendation — Disable or remove accounts promptly when the business need ends. Revoke or replace authenticators as part of the offboarding process.
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle control is central to preventing stale access.
Recommendation — Maintain timely account disablement and periodic review of active access.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity lifecycle governance requires timely removal of no-longer-needed access.
A.5.18 — Access rightsAccess rights should be revoked when employment or need changes.
Recommendation — Remove identities and related access rights promptly when they are no longer required. Revoke access rights at the point they are no longer justified.

Practitioner Guidance

What to verify: Confirm that revocation is triggered from the source-of-truth lifecycle event, not from a manual ticket that can stall in a queue. If removal depends on a person remembering each downstream system, the control is already weak.

What good looks like: Offboarding should remove active access quickly enough that the identity record, entitlement state, and authentication material converge within the same operational window. Where systems cannot revoke immediately, teams should track and exception-manage the lag explicitly rather than assuming cleanup happened.

Common mistake: Treating deprovisioning as an HR exit checklist instead of an access-control control. The business event is the trigger, but the security requirement is the actual removal of access and any reusable credentials or tokens tied to it.

Practitioner takeaway: The real risk is not just delayed cleanup, it is the period in which an ex-employee or former user still has valid access that the organisation no longer intends to trust.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org