Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What is the difference between auditing access inventory…
Governance, Ownership & Risk

What is the difference between auditing access inventory and reviewing onboarding and offboarding processes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Governance, Ownership & Risk

Auditing access inventory answers who currently has access and whether that access still makes sense. Reviewing onboarding and offboarding processes asks how access is granted, changed, and removed over time. The first is a point-in-time control check. The second is a process control that prevents stale permissions from reappearing after cleanup.

Why this distinction matters in practice

These are complementary controls, but they answer different governance questions. access inventory tells you whether the current state is acceptable. Onboarding and offboarding review tells you whether the process that creates and removes access is reliable enough to keep that state clean over time. If you only inspect inventory, you can miss a broken joiner-mover-leaver path that keeps reintroducing the same exposure.

For practitioners, the difference is important because the first control is evidence of present posture, while the second is evidence of control design and operational discipline. A clean inventory with a weak process is usually temporary. A strong process with a messy inventory often means the review cycle or automation is not yet effective enough to suppress drift.

When access spans service accounts, API keys, tokens, or other secret-bearing identities, the gap becomes more consequential because stale entitlements and unrevoked credentials can survive long after the original business need has ended. NHIMG’s Ultimate Guide to NHIs treats lifecycle and offboarding as a core governance issue, and the lifecycle section is especially useful when you need to distinguish current access from the process that created it.

What access inventory testing actually proves

An access inventory audit is a snapshot. It asks whether each account, role, token, or entitlement still has a valid business justification, whether the assigned access matches the principle of least privilege, and whether anything appears excessive, dormant, or orphaned. The strength of this check is precision: it can surface specific overprivilege, cross-environment access, and unused access that no longer belongs.

That precision is also its limit. A good inventory audit can show that access is wrong today, but it does not by itself explain why the problem exists or whether the organisation has a repeatable way to prevent recurrence. If the same exceptions keep appearing every quarter, the issue is not just the inventory, it is the onboarding, transfer, or offboarding path that keeps producing them.

In NHI-heavy environments, that distinction is often visible at scale. NHIMG research notes that NHIs now outnumber human identities by 144:1 in enterprise environments, which means a point-in-time review can be overwhelmed unless the underlying lifecycle controls are strong enough to keep pace with creation and revocation. The broader inventory problem is also why the NHI and Secrets Risk Report is useful for understanding how inventory gaps and overprivilege compound in real estates.

What onboarding and offboarding review is really checking

Reviewing onboarding and offboarding processes is a process-control exercise. It asks whether access is granted only after the right approvals, whether changes are triggered when roles or responsibilities change, and whether removal happens promptly when a person, system, vendor, or workload no longer needs access. The focus is not just whether access exists, but whether the lifecycle that creates access is governed well enough to avoid drift.

This is why offboarding deserves special scrutiny. A weak offboarding path does not just leave old access behind, it creates a pattern where stale permissions, orphaned accounts, and unrevoked credentials reappear after cleanup. The same is true for onboarding when templates, roles, or automation are misconfigured, because over-broad initial access tends to become the default unless someone later catches it in review.

If you want a concrete lifecycle reference point, the NHI Lifecycle Management Guide is the strongest NHIMG source for how provisioning, rotation, and offboarding fit together as one control chain. It is also the better resource when the question is about process reliability rather than just current entitlement shape.

How to decide which control you are actually testing

What to verify: Use an access inventory review when the question is, “Who has access right now, and is it justified?” Use onboarding and offboarding review when the question is, “Is our joiner-mover-leaver process creating and removing access correctly every time?” If the same access exceptions keep recurring, prioritise process review; if the main concern is present-day exposure, prioritise the inventory.

Common mistake: Teams often treat these as interchangeable and only validate the list of accounts. That misses the operational failure mode, which is that a broken workflow can keep repopulating the inventory with the same bad access after each cleanup cycle. A better test is to sample recent joiners, movers, and leavers and trace whether approvals, provisioning, revocation, and evidence retention all happened as intended.

Practitioner takeaway: Inventory audits tell you whether access is acceptable now, but onboarding and offboarding reviews tell you whether it will stay acceptable after the next change event. If the process is weak, the inventory is just a temporary snapshot of a recurring control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementControls who gets access and how revocation is handled across the lifecycle.
5 — Account ManagementCovers account provisioning, modification, and disabling, which underpin onboarding and offboarding.
Recommendation — Review access approval, changes, and removal to keep permissions aligned with business need. Standardise account lifecycle steps so access is created and removed consistently.
NIST CSF 2.0PR.AC — Identity Management, Authentication, and Access ControlSupports both point-in-time access validation and lifecycle governance over access assignments.
Recommendation — Map current access and lifecycle steps to enforce least privilege and timely revocation.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementLifecycle review for access-bearing secrets is central when access is granted and removed over time.
NHI-02 — Identity Lifecycle and Access GovernanceDirectly addresses provisioning, review, and deprovisioning of non-human access.
Recommendation — Inventory credentials and verify rotation, revocation, and offboarding handling. Validate joiner-mover-leaver workflows so access does not persist after need ends.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org