A connectivity graph shows how identities, applications, and resources are linked. A composite access graph adds depth by tying those links to actual resources, permissions, and activity, so teams can see whether access is merely possible or genuinely used. That distinction matters for governance because it improves review quality, exposes hidden privilege paths, and supports faster, more accurate risk decisions.
Why Connectivity and Composite Access Graphs Serve Different Governance Questions
A connectivity graph is useful when you need to understand relationships: which identities can reach which applications, which services touch which resources, and where trust edges exist. A composite access graph goes further by combining those relationships with permission states and observed activity, so the question shifts from “could this identity get there?” to “does this access path exist, and is it actually exercised?” For identity security, that difference matters because latent access is often the real governance problem, not just connectivity itself.
That is why composite views are better suited to privilege review, entitlement cleanup, and exposure analysis. They reduce the chance that teams overreact to nominal reachability while missing standing permissions that are never used, or conversely assume a path is safe because it is quiet in logs. The practical value is in separating structural access from operational access, which improves triage and makes reviews more defensible. The Ultimate Guide to NHIs shows how visibility gaps and excessive privileges commonly travel together, which is exactly why graph depth matters here. In practice, many teams only discover that distinction after a stale entitlement has already survived several access reviews.
How Composite Access Graphs Work in Practice
In practice, a connectivity graph is usually the first layer of discovery. It maps nodes and edges: users, service accounts, workloads, apps, APIs, storage, and the trust relationships between them. That is valuable for seeing blast radius and upstream dependencies, but it does not always tell you whether a permission is active, inherited, dormant, or truly necessary. Composite access graphs add those missing dimensions by joining identity relationships to entitlement data, resource objects, and usage signals.
This matters because identity security decisions are rarely made on connectivity alone. A path may exist through federation, token delegation, shared credentials, or role inheritance, yet still be harmless if the permission is no longer granted or no workload ever uses it. Composite graphs help teams separate structural risk from actual access behaviour, which is especially useful for cleanup campaigns, access certification, and investigations into hidden privilege paths. The OWASP Non-Human Identity Top 10 is useful context because it frames recurring failure patterns around over-privilege, lifecycle gaps, and weak visibility. When teams work with high-fidelity composite graphs, they can ask a sharper set of questions:
- Which identities have a path to a resource, and which ones have confirmed effective permission?
- Which access edges are inherited through roles, groups, or delegation rather than explicitly assigned?
- Which paths exist only on paper because they are never used in observed activity?
- Which access chains create meaningful escalation potential across systems or environments?
The operational win is cleaner governance: reviewers can focus on risk-bearing access rather than every theoretical link, and investigators can trace activity back to the exact entitlement state that enabled it. The model breaks down when entitlement sources are fragmented across platforms, because incomplete telemetry makes “composite” look more confident than it really is.
Where the Difference Becomes Operationally Important
Tighter graph depth often increases data integration and maintenance overhead, so organisations need to balance analytical precision against collection quality. A connectivity graph is easier to build and easier to reason about, but it can understate risk by treating all paths as equally meaningful. A composite access graph is more operationally demanding, yet it is better suited to decisions that depend on whether access is merely possible or actually effective. NHIMG research reports that 97% of NHIs carry excessive privileges, which is a strong reminder that entitlement quality, not just topology, is where most governance problems concentrate.
There is also a trade-off in how teams interpret quiet access. Best practice is evolving, but silence in activity data should not automatically be read as safety. Some service identities are low-volume by design, some are seasonal, and some are dormant but still capable of action. The right interpretation depends on whether the graph ties edges to permissions, resource scope, and recency of use. That is why composite graphs are strongest when they support exception handling, not just reporting. They help teams decide whether an entitlement should be removed, monitored more closely, or retained as a justified exception. In practice, that distinction matters most where identity sprawl, third-party access, or cross-environment trust has made the access map larger than the human review process can reliably inspect.
Risk and Threat Considerations
The main risk is false confidence. A connectivity graph can show that an access path exists without revealing whether the path is authorised, active, overbroad, or exploitable, which can leave latent privilege and hidden escalation routes in place. Composite access graphs reduce that blind spot, but only when permission and activity data are complete enough to support a real governance decision.
Failure mechanism: Teams rely on structural connectivity to infer control strength, then miss dormant entitlements, inherited permissions, or delegated access that still permits abuse. In adversarial scenarios, that gap supports privilege escalation, lateral movement, and stealthy persistence through identities that appear low risk at the topology layer.
Impact: Excess access remains undetected, review decisions become less defensible, and responders lose time reconstructing whether a path was merely possible or actually used. The result is slower containment and a larger blast radius when an identity or credential is compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | Visibility and Discovery — Visibility and Discovery | Composite access graphs improve machine-identity visibility and expose hidden access paths. |
| Recommendation — Map NHI relationships and entitlement state together to find hidden privilege paths. | ||
| CIS Controls v8 | 5 — Account Management | The question centers on distinguishing access edges from effective account privileges. |
| 6 — Access Control Management | Composite graphs support tighter entitlement review and removal decisions. | |
| Recommendation — Inventory and review accounts against actual privilege use, not connectivity alone. Enforce least privilege by removing access that is not justified by current need. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | The topic is about how identities, permissions, and access paths are governed. |
| Recommendation — Validate effective access paths and align identity permissions to business need. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Hidden access and over-privilege create conditions attackers can abuse with valid identities. |
| Recommendation — Hunt for abused legitimate access where graph paths reveal reachable resources. | ||
Practitioner Guidance
What to prioritise: Use the composite view first when the decision involves removal, certification, or exception approval. Use the simpler connectivity view when the goal is dependency mapping or finding where trust edges exist. Treat them as different instruments, not competing versions of the same control.
What to verify: Before trusting a composite graph, confirm that it joins at least three things consistently: the identity edge, the effective permission, and the usage signal. If any one of those is missing, the graph may still be useful, but it should not be treated as evidence that access is truly low risk.
What practitioners underestimate: The hardest part is not graph construction but data freshness. A graph that is technically rich but stale can be more dangerous than a plain connectivity map, because it creates the appearance of precision while hiding changes in privilege state.
Practitioner takeaway: The practical distinction is that connectivity tells you where access could exist, while composite access tells you where access actually matters, and governance should always follow the latter.
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between data-centric security and an access graph in enterprise identity governance?
- What is the difference between privileged identity management and privileged access management?
- What is the difference between reviewing human access and reviewing NHIs?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org