Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should security teams do when users accumulate…
Governance, Ownership & Risk

What should security teams do when users accumulate conflicting access over time?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Security teams should recertify the combined permission set, not just the latest role change, and remove any incompatible entitlement pair before the next approval cycle. The goal is to restore separation across request, approval, administration, and execution paths so the same identity cannot complete the full sensitive process.

Why Conflicting Access Builds Up Instead of Staying Consistent

Conflicting access usually appears when a person changes roles, projects, or approval paths but old entitlements are never fully removed. The problem is not the newest grant by itself, it is the inherited combination. A user can end up with permissions that are each reasonable on their own but unsafe together, especially when approvals are handled as isolated events rather than a full entitlement review.

That is why the control question is not “was this role approved?” but “what does this identity now have in aggregate?” When access accumulates over time, the risk is role overlap, privilege creep, and broken separation of duties across request, approval, administration, and execution tasks. IAM and IGA Basics is useful here because it frames access as a governed set of entitlements, not a series of disconnected changes.

Security teams should treat the effective permission set as the real object of review. If two entitlements together let the same user request, approve, and execute the same sensitive process, the access model has drifted even if each entitlement was independently justified at the time.

What Security Teams Should Review Before the Next Approval Cycle

The right review unit is the combined entitlement set, including inherited access, temporary elevation, shared platform roles, and any exceptions that have quietly become routine. A recertification that only checks the latest ticket or the most recent role assignment will miss toxic combinations that were created earlier.

Teams should also compare access against business function boundaries, not just technical groups. The goal is to restore separation across request, approval, administration, and execution paths so the same identity cannot complete an entire sensitive workflow end to end. Access Reviews and Certification Guide is relevant because it emphasises review designs that actually remove access and close the loop, rather than producing another attestation record.

Where the conflicting access includes standing privilege, the review should not stop at documentation. The team should decide whether the user needs permanent entitlement at all, or whether the access should be converted to time-bound elevation. Just-in-Time Access and Zero Standing Privilege Guide supports that decision point because it treats standing privilege as the condition that keeps toxic combinations alive between review cycles.

For access tied to administration or operational control, separate the person’s normal job access from the privilege they need only occasionally. If a single role bundle is doing both, it becomes harder to prove segregation and harder to revoke only the dangerous part when responsibilities change.

How to Prevent Recurring Access Creep

Prevention depends on governance discipline, not just periodic cleanup. Security teams should define which entitlement combinations are incompatible, check them at approval time, and force removal of the older grant when a new one would create an unsafe overlap. That is more reliable than hoping quarterly review will catch every conflict after the fact.

Where machine, application, or workload identities are part of the same access ecosystem, the same principle applies: review the effective rights set, not only the last issued credential or newest trust relationship. Cloud Workload Identity Guide is useful because it shows how temporary credentials and federated access still need lifecycle control to avoid privilege accumulation.

For high-impact administrative paths, align the cleanup with privileged access workflows so revocation is not delayed until a separate governance meeting. Privileged Access Management Guide is the natural companion when the conflicting access includes admin rights, break-glass accounts, or elevated session capability.

In practice, the strongest safeguard is an access model that can answer one question quickly: if this user keeps every grant they have accumulated, can they still bypass separation of duties? If the answer is yes, the control has not been restored yet.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementConflicting access accumulates through unmanaged entitlement changes and recertification gaps.
AC-5 — Separation of DutiesThe issue is a user combining roles that should remain separated across request and execution.
AC-6 — Least PrivilegeConflicting access often reflects privilege creep and excess rights surviving role changes.
Recommendation — Review and remove incompatible entitlements as part of ongoing account management. Enforce incompatible access pairings so one identity cannot complete the full sensitive process. Limit standing rights to the minimum needed and revoke outdated access promptly.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control requires governing who retains which permissions as roles change over time.
A.5.18 — Access rightsAccess rights management directly covers review, adjustment, and removal of outdated permissions.
Recommendation — Maintain access rules that recertify and correct accumulated entitlements. Recertify accumulated access and remove incompatible rights before the next cycle.

Practitioner Guidance

What to prioritise: Start with the combinations that create irreversible or high-impact action, especially where one identity can both initiate and complete a sensitive workflow. Those conflicts deserve immediate removal before the next approval batch.

What to verify: Confirm that recertification is evaluating the full effective permission set, including inherited roles, temporary elevation, and exception paths. If the review only looks at the latest access change, it is not testing the real exposure.

Decision rule: If two entitlements are individually legitimate but jointly violate segregation of duties, preserve the business function only by removing or time-bounding one side of the combination. Do not accept “both were approved” as a sufficient control outcome.

Practitioner takeaway: Conflicting access is a lifecycle problem, not a point-in-time approval problem, so the control objective is to keep access combinations safe over time, not merely defensible at the moment they were granted.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org