Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What happens when employee-built apps are not tied…
NHI Lifecycle Management

What happens when employee-built apps are not tied to lifecycle governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: NHI Lifecycle Management

Apps keep running after ownership changes, offboarding occurs, or the original builder moves on, which creates orphaned access and unclear accountability. The fix is to bind app ownership, sensitive actions, and removal steps to the same lifecycle record.

How does lifecycle governance change the fate of employee-built apps?

When employee-built apps are not tied to lifecycle governance, the app outlives the person, not the role. Ownership, access, secrets, and shutdown steps drift apart, so a tool that began as a productivity shortcut becomes a persistent business dependency with no clear custodian.

That gap matters because employee-built apps often connect to data, APIs, and internal workflows with privileges that were never reviewed as rigorously as formal software. Without a lifecycle record, the organisation loses the ability to answer basic questions such as who can change it, who must approve it, and who is responsible when the builder leaves.

Why orphaned apps create more than an ownership problem

Orphaning is not just an administrative issue. When ownership changes are not captured, access review, rotation, and retirement stop happening at the right time, which can leave dormant integrations live long after they should have been reassessed. A useful way to think about this is to treat ownership as a lifecycle control, not a documentation field, as reflected in NHIMG’s NHI Lifecycle Management Guide and NHI Ownership and Accountability Guide.

That is especially important for employee-built apps because the biggest failure mode is quiet continuity. The app still works, so teams assume it is healthy, but the person who understands its purpose may have changed team, left the company, or moved on to something else. At that point, security review and operational ownership become fragmented across HR, IT, and the business function that originally requested the app.

Lifecycle governance also determines whether the app can be discovered, classified, and retired in time. The same pattern shows up in broader identity practice, and the Joiner-Mover-Leaver (JML) Guide is useful because it links movement and exit events to access cleanup rather than treating them as separate processes.

What breaks first when the original builder leaves?

The first break is usually accountability. If no one inherits the lifecycle record, the app becomes a shadow dependency that persists because no one feels authorised to touch it. The second break is control consistency, because sensitive actions such as key rotation, integration revocation, or app deletion no longer have a clear owner or change path.

That can leave long-lived access behind in the form of tokens, API keys, shared inboxes, or app-specific credentials. When those credentials remain valid after the builder departs, the app may still reach internal systems even though its maintenance context has disappeared. Examples of this pattern appear in breach reporting around unrevoked credentials, including the Coupang Signing Key Breach and the Internet Archive breach 2024.

A second practical risk is reuse. Builders often copy a working app pattern into a new department or project, then the lifecycle controls remain uneven. That is how one undocumented tool becomes several, and why governance needs a consistent rule for handoff, periodic review, and retirement rather than a one-time approval.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementCovers reassignment, review, and removal of app access as people leave or roles change.
IA-5 — Authenticator ManagementApplies to tokens, keys, and secrets that employee-built apps use to keep running.
Recommendation — Link app ownership and access review to account lifecycle events so orphaned access is removed promptly. Rotate or revoke app credentials when ownership changes or the app is retired.
ISO/IEC 27001:2022A.5.18 — Access rightsSupports reviewing and removing app-related access when responsibility changes.
Recommendation — Review and remove app access rights on mover and leaver events.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingOrphaned employee-built apps persist when builders depart without cleanup.
NHI-07 — Long-Lived SecretsEmployee-built apps often fail when tokens and keys outlive their owners.
Recommendation — Bind app shutdown and credential removal to offboarding workflows. Set expiry, rotation, and revocation rules for app secrets.

Practitioner Guidance

What to verify: Every employee-built app should have a named business owner, a technical owner, and a documented offboarding path that includes secret rotation or revocation, dependency review, and deletion criteria. If any one of those is missing, the app is already operating with incomplete governance.

Decision rule: If the app can authenticate to production data, messaging, or workflow systems, treat lifecycle ownership as mandatory control scope, not optional admin hygiene. If it cannot be cleanly reassigned on mover or leaver events, it should be constrained until ownership is fixed.

What good looks like: Ownership changes automatically with the lifecycle record, access reviews are triggered by role change, and retirement can be executed without needing the original builder to be available. That is the state where the app remains useful without becoming orphaned.

Practitioner takeaway: The real control objective is not simply to know who built the app, but to ensure the organisation can always answer who owns it now, who can change it, and how it will be safely removed.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org