When reviews are not automated and clearly owned, they tend to become inconsistent, slow, and easy to ignore. That can leave inactive accounts and outdated permissions in place, increasing exposure of customer data and making compliance audits harder to defend. Over time, the organisation spends more effort chasing records and less time removing unjustified access before it is abused.
Why Unowned, Manual Reviews Drift Into Access Creep
When access reviews are manual and accountability is vague, they tend to become a recurring administrative task rather than a control. The result is predictable: reviewers defer hard decisions, stale entitlements stay approved by default, and the process loses its ability to remove access before it becomes an exposure. For Salesforce, that is especially damaging because customer data and business workflows often sit behind broadly distributed roles and permission sets.
The core failure is not the existence of a review, it is the absence of a dependable decision loop. Without automation, teams rely on spreadsheets, email chains, and memory. Without a clear owner, nobody feels responsible for chasing exceptions, correcting records, or proving that revoked access actually disappeared. That is how inactive accounts, overbroad permissions, and orphaned access remain in place long enough to matter. A useful lifecycle reference is NHIMG’s NHI Lifecycle Management Guide, which covers the same lifecycle discipline of review, offboarding, and ownership in access-heavy environments.
Manual review also scales badly. As user counts, roles, and integrated applications grow, the review burden increases faster than the governance capacity of the team. The practical consequence is review fatigue, where approvers click through requests to clear backlog rather than challenge unnecessary access. If the control is meant to confirm need-to-know, any workflow that optimises for speed over evidence will slowly turn into a compliance ritual instead of an access-control decision.
What Breaks in Salesforce When Reviews Are Slow or Ignored
The immediate security issue is excessive standing access. In Salesforce, that can mean former employees, contractors, and dormant accounts retaining access to customer records, case data, reports, and connected objects long after their business need has ended. It can also mean permission sets and profiles drifting beyond the role that originally justified them, especially when access changes happen repeatedly without a clean recertification record.
There is also an auditability problem. If reviewers cannot show who approved access, when they approved it, and what was removed as a result, the organisation inherits weak evidence even when the review technically happened. That makes it harder to defend the control to auditors and harder to prove that the business actually governs sensitive access rather than merely records it. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful here because it links access review discipline to governance evidence, not just to policy intent.
The risk compounds in environments with connected apps, automation, and delegated integrations. A stale account may not look dangerous until it is used to export data, alter records, or trigger downstream actions. That is why access review quality should be judged by remediation outcomes, not by how many review tickets were closed. For a broader control baseline, CIS Controls v8 remains a strong fit for account management, access control, and logging discipline.
How to Make Reviews Defensible, Not Just Scheduled
Good practice is to automate the routing, evidence capture, and expiry logic, while keeping the actual approval decision with the right business owner. Automation should remove the drudge work, not the accountability. The point is to make every review produce a visible outcome: approve with justification, remove access, or escalate an exception with a dated owner. Salesforce access review processes work best when they are tied to role ownership and termination events rather than treated as a separate quarterly ritual.
What to verify: confirm that every review cycle has a named owner, a due date, a default-deny path for non-response, and a logged remediation action for every revoked entitlement. Also verify that removals are technically enforced, not merely marked complete in the workflow. If the access model depends on profile and permission-set sprawl, use the review to reduce the number of standing exceptions rather than simply re-approve them.
Decision rule: if a reviewer cannot explain why the access is still needed in the current role, treat that access as removable until proven otherwise. If the answer depends on an exception, require a time-bound expiry and a second review trigger. NHIMG’s Top 10 NHI Issues is a useful companion for understanding why inactive access, excessive permissions, and weak ownership become persistent control failures at scale.
Practitioner takeaway: the control only works when review ownership, review cadence, and removal enforcement are all real, because a review without accountable remediation is just documentation of drift.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Salesforce review drift is an account and entitlement governance problem. |
| 8 — Audit Log Management | Defensible access reviews depend on evidence of who approved and what changed. | |
| Recommendation — Enforce least privilege and remove dormant or excessive Salesforce access. Record review actions and remediation evidence for each entitlement decision. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | The subject concerns access governance, approval, and removal of unjustified access. |
| GV.RM — Risk Management Strategy | Manual, unowned reviews create residual access risk that must be governed explicitly. | |
| Recommendation — Apply access control governance to ensure stale Salesforce permissions are revoked. Set accountable review ownership and remediation SLAs for Salesforce access. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Non-Human Identity Inventory and Ownership | The question centers on accountable ownership and lifecycle control of access paths. |
| Recommendation — Inventory every access path and assign a clear business owner for recertification. | ||
Related resources from NHI Mgmt Group
- What happens when user access reviews are not automated for a system like Symitar?
- What happens when Google Drive access reviews are not automated?
- What happens when Dropbox access reviews are done manually instead of through an automated governance process?
- What happens when access reviews for Concur are not automated?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org