Workflow friction creates the most risk when teams are under incident or debugging pressure. In those moments, engineers are less willing to navigate separate interfaces or repeat failed requests, so they gravitate toward broader permissions that reduce delay. The result is not just slower access, but a higher chance of unnecessary privilege expansion.
Why Friction Becomes Dangerous Under Pressure
Workflow friction is most dangerous when privileged work is time-sensitive, especially during incidents, outages, or deep debugging. At that point, the problem is no longer just convenience, it becomes a decision under stress: keep using the normal approval path, or find a faster way to get access. The more painful the legitimate path feels, the more likely people are to seek broader standing access.
In practice, that means friction does not create risk evenly. It matters most when the person requesting access already has a strong operational reason to move fast and a weak tolerance for delay, because the workflow becomes part of the security control surface. When the path is clumsy, the control starts shaping behaviour instead of containing it.
How Friction Turns Into Privilege Expansion
The usual failure mode is not a single malicious choice, but repeated bypass pressure. If engineers expect rejected requests, multiple systems, or slow approvals, they may ask for persistent elevation, shared admin access, or a wider role than the immediate task needs. That trades a small access delay for a larger and longer-lived exposure.
This is where privilege creep begins. A one-off exception can become a habit, then a default, then an assumed entitlement. Over time, teams stop matching access to the task and start matching access to the frustration level of the process. That is why workflow design and privilege design are inseparable in privileged access management.
Signals That the Access Path Is Too Hard
When friction is becoming a security issue, you usually see it in behaviour before you see it in incidents. Repeated failed requests, informal workarounds, “temporary” broad access that never expires, and escalation requests outside normal hours are all signs that the process is not keeping pace with operational reality. If the fastest path is the broadest path, the control is failing at the exact moment it matters most.
The pattern is especially visible when the same few privileged roles are used as catch-all fixes. That often means the workflow is not matching actual job functions, or the access model is too coarse to support urgent work without overgranting. Privileged Access Management Guide is useful here because it frames access around zero standing privilege, just-in-time elevation, and session control rather than permanent convenience.
Risk and Threat Considerations
Under incident pressure, friction increases the odds of unsafe shortcuts, including standing privilege, emergency access sprawl, and overbroad temporary grants. The risk is not just slower response, it is that defenders can unintentionally create the same overexposure they are trying to avoid, while also weakening auditability and accountability.
Failure mechanism: A difficult request path pushes responders toward persistent admin roles, shared credentials, or “just leave it open” exceptions so work can continue. That enlarges the blast radius if the account is misused, phished, or left active after the event.
Impact: Excess privilege can outlive the incident, create hidden lateral movement paths, and make later compromise easier to exploit because access was granted for speed rather than necessity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Friction-driven overgranting directly affects least-privilege enforcement for privileged access. |
| IA-5 — Authenticator Management | Pressure often leads to shared or persistent access material that must still be controlled and rotated. | |
| AC-2 — Account Management | Workflow exceptions and emergency accounts are account-management problems when friction drives bypasses. | |
| Recommendation — Enforce AC-6 to keep urgent access narrowly scoped and time-limited. Apply IA-5 to control, rotate, and expire privileged credentials used in fast-path workflows. Use AC-2 to govern emergency and elevated accounts with clear ownership and review. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Workflow friction becomes an access-control issue when it drives broader-than-needed permissions. |
| A.8.2 — Privileged access rights | The subject is specifically about privileged access expanding under pressure. | |
| Recommendation — Apply A.5.15 to keep privileged access tightly governed and task-specific. Use A.8.2 to review, restrict, and time-bound privileged access rights. | ||
Practitioner Guidance
What to prioritise: Treat incident-time access as a separate design case, not as an edge case. The right question is whether the workflow can grant narrowly scoped access quickly enough that responders do not feel forced to choose between progress and control.
What to verify: Check whether emergency or elevated access has a clear expiry, a named owner, and a review path after use. If access is granted “temporarily” but not time-bounded in practice, the process is converting urgency into standing privilege.
Decision rule: If the task is genuinely urgent, prefer fast, bounded elevation over broad permanent roles. If the only way to move fast is to widen access permanently, the design is too coarse and needs rework before the next incident.
Practitioner takeaway: The most dangerous friction is the kind that shows up when people are already under pressure, because it turns speed into a justification for privilege expansion instead of a reason to keep access tightly bounded.
Related resources from NHI Mgmt Group
- When does JIT access create more risk than it reduces?
- Why do employees with privileged access create a different security culture risk than general users?
- Why do traditional privileged access workflows create security risk in large, distributed environments?
- Why does managing privileged access across heterogeneous systems create so much security risk?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org