The inventory becomes accurate only briefly, then drifts as new hires, new integrations, and ad hoc service accounts are added. Fragmentation returns as systems change, and the organisation loses track of the real identity count again. Continuous discovery and merge mechanics are needed to keep identity sprawl from rebuilding after every cleanup cycle.
How Periodic Cleanups Let Identity Sprawl Return
Periodic cleanup is useful as a reset, but it does not change the underlying identity lifecycle. New integrations, short-lived projects, and ad hoc service accounts appear between reviews, so the inventory looks clean only at a point in time. That creates a false sense of control, because the real problem is continuous creation and reuse, not the cleanup event itself. The best public guidance now treats identity visibility as an ongoing control, not a once-a-quarter task.
The gap matters because identity sprawl is not just a counting problem. Every missed account, key, or token can expand access paths, weaken ownership, and hide unused or overprivileged identities long after the review ends. Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which is exactly why periodic cleanups tend to lag reality instead of controlling it.
In practice, teams usually discover the drift only after another system rollout, integration change, or audit finding has already reopened the gap.
How Continuous Discovery Changes the Operating Model
continuous discovery shifts identity management from episodic review to near-real-time awareness. Instead of waiting for a cleanup cycle, the organisation watches for new machine identities, newly issued credentials, orphaned accounts, and ownership changes as they appear. That matters because identity state changes quickly in cloud, CI/CD, SaaS, and multi-team environments, where manual spreadsheets and periodic attestations cannot keep pace.
The practical difference is that discovery must be paired with merge mechanics. Duplicate detection, ownership reconciliation, and source-of-truth updates keep one integration or one team from creating multiple records for the same identity. Without that merge layer, continuous discovery can still produce fragmentation, just at a faster rate. The goal is not more raw inventory data; it is a stable identity graph that reflects current authentication paths and access scope.
- Monitor creation events across directory services, cloud platforms, CI/CD systems, and application registries.
- Normalise identifiers so the same service account, workload, or API credential is not tracked as separate objects.
- Flag identities that lack an owner, a lifecycle state, or a defined renewal path.
- Reconcile detected identities against approved inventory and decommission records before the next review cycle.
That approach aligns with OWASP Non-Human Identity Top 10, which treats missing visibility and lifecycle control as core failure modes for machine identities. For a broader lifecycle lens, NHI Lifecycle Management Guide helps teams think beyond discovery to ownership, rotation, and offboarding discipline.
These controls tend to break down when identity creation is decentralised across many teams because no single process captures the full inventory.
Where Periodic Review Still Helps, and Where It Falls Short
Periodic cleanup still has value, especially as a governance checkpoint, but it is too slow to be the main control in environments with frequent change. Tighter review cadence often increases operational overhead, requiring organisations to balance assurance against the cost of repeated manual reconciliation. Best practice is evolving toward using cleanup as validation, not as the primary method of discovery.
There is also a tradeoff between completeness and operational speed. A very aggressive cleanup can temporarily remove stale entries, but if it does not fix provisioning sources and ownership logic, the same identities reappear in the next sprint or release cycle. In that sense, the real failure is not the cleanup itself but treating it as the end state.
Current guidance suggests using periodic review for exception handling, stale-object confirmation, and governance evidence, while continuous discovery handles the live inventory. This is especially important where secrets, service accounts, and automation identities are created outside central IAM workflows, because those identities often evade quarterly scrutiny until they become difficult to attribute or revoke.
Risk and Threat Considerations
Periodic cleanup creates a visibility gap that can hide stale, duplicate, orphaned, or overprivileged identities between review windows. That exposure matters because attackers and insiders both benefit from identities that remain active after their business need has changed.
Failure mechanism: New identities are created faster than they are reviewed, ownership becomes unclear, and unused credentials or service accounts remain valid long after the organisation believes they have been cleaned up. This enables trust abuse, persistence, and access drift.
Impact: The organisation can lose control of who or what still has access, increasing the chance of unauthorised access, lateral movement, audit failure, and delayed revocation when an identity is compromised or no longer needed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory and Discovery | Continuous discovery is central to keeping machine identity inventory current. |
| NHI-02 — Ownership and Accountability | Periodic cleanups fail when identities lack clear owners and lifecycle accountability. | |
| NHI-03 — Lifecycle Management | The question is about keeping identity state accurate across creation and cleanup cycles. | |
| Recommendation — Continuously discover all NHIs and reconcile them to a governed source of truth. Assign every NHI a named owner and enforce accountability for its lifecycle. Automate NHI onboarding, renewal, and decommissioning to prevent inventory drift. | ||
| CIS Controls v8 | 6 — Access Control Management | Identity cleanup and drift management are access governance problems. |
| 5 — Account Management | Continuous discovery is needed to keep account inventories aligned with reality. | |
| Recommendation — Review and revoke unused access paths before stale identities accumulate. Maintain an authoritative account inventory and remove obsolete accounts promptly. | ||
| NIST CSF 2.0 | ID.AM — Asset Management | Identity sprawl is fundamentally an inventory and visibility issue. |
| Recommendation — Keep identity assets inventoried continuously instead of relying on periodic counts. | ||
Practitioner Guidance
What to prioritise: Treat discovery coverage as the control objective, not the cleanup event. The first question is whether every identity source that can mint access has a detection path and an ownership field.
Decision rule: If an identity can be created outside central review, do not rely on periodic cleanup to find it later; build continuous ingest and reconciliation first, then use cleanups to validate exceptions and retire stale records.
What to verify: Confirm that duplicate records collapse to one governed identity, that each identity has a clear owner, and that revocation can actually reach the system where the credential is accepted.
Practitioner takeaway: Periodic cleanup is a maintenance task; continuous discovery is the control that keeps identity sprawl from rebuilding faster than governance can see it.
Related resources from NHI Mgmt Group
- How should organisations move from periodic access reviews to continuous identity governance?
- What breaks when organisations rely on vendor questionnaires instead of continuous third-party identity monitoring?
- What breaks when organisations keep asking for full identity records instead of selective attributes?
- What breaks when organisations rely on periodic testing instead of continuous monitoring for AI agent security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org