Frameworks and standards such as GDPR, PCI DSS, and NIST expect organisations to manage identity lifecycles carefully, including revocation and audit evidence. In practice, that means proving old access is removed, secrets are purged, and changes are traceable. Without those controls, organisations face compliance gaps, audit findings, and avoidable breach exposure.
Why This Matters for Security Teams
Identity decommissioning is not a housekeeping task. It is the point where organisations prove that access has ended, credentials can no longer be used, and audit evidence still survives. Frameworks such as GDPR, PCI DSS, and NIST expect lifecycle control over identities, secrets, and permissions because stale access is a common source of exposure. The risk is even sharper for non-human identities, where service accounts, API keys, and automation tokens often outlive the system that created them.
NHIMG research shows why this matters operationally: only 20% of organisations have formal processes for offboarding and revoking API keys, and 91.6% of secrets remain valid five days after notification. That gap turns decommissioning into a live attack path, not a compliance checkbox. The lifecycle view in the Ultimate Guide to NHIs aligns closely with the control intent in NIST Cybersecurity Framework 2.0, especially where asset and access governance intersect.
In practice, many security teams encounter revoked identities only after a breach review shows the old secret was still usable weeks later.
How It Works in Practice
Control of identity decommissioning starts with a complete inventory of both human and non-human identities, then links each identity to an owner, purpose, and shutdown trigger. When a user leaves, a system is retired, or an application is replaced, the organisation must remove entitlements, revoke active sessions, expire tokens, delete or rotate keys, and preserve evidence that the action occurred. For NHI estates, this often means coordinating IAM, PAM, secrets management, CI/CD, and application owners in one workflow.
Current guidance suggests treating decommissioning as a workflow with proof, not a manual ticket. The most defensible pattern is: identify the identity, validate the business dependency, revoke access, purge secrets, and verify that no downstream integration still trusts the old credential. That approach reflects the control expectations described in the Ultimate Guide to NHIs — Standards and the audit emphasis in Ultimate Guide to NHIs — Regulatory and Audit Perspectives.
- Revoke access at the source system, not just in the directory layer.
- Expire or destroy tokens, API keys, certificates, and delegated grants.
- Confirm removal with logs, screenshots, or API evidence suitable for audit.
- Track exceptions where a credential must remain temporarily active for migration.
NIST SP 800-53 Rev 5 Security and Privacy Controls reinforces this lifecycle expectation by requiring organisations to manage account and access removal as part of control operation. These controls tend to break down when credentials are embedded in code, because revocation becomes a search problem across pipelines, repositories, and runtime services.
Common Variations and Edge Cases
Tighter decommissioning controls often increase operational overhead, requiring organisations to balance speed of change against confidence that access is truly gone. That tradeoff is most visible in shared service accounts, long-lived integrations, and regulated environments where evidence retention matters as much as the revocation itself.
Guidance versus consensus is still uneven in a few areas. There is no universal standard for how quickly every secret must be destroyed after retirement, but best practice is evolving toward short TTLs, immediate revocation for high-risk credentials, and automated verification of downstream dependencies. For legacy systems, organisations may need compensating controls such as network restriction, monitoring, and staged cutover windows rather than instant deletion.
For non-human identities, the hardest edge case is often an identity that is technically decommissioned but still referenced by an application, pipeline, or vendor integration. The Top 10 NHI Issues and the breach patterns in 52 NHI Breaches Analysis show that hidden dependencies and delayed revocation are recurring failure modes. That is why current guidance favors continuous inventory, not periodic cleanup.
Where organisations rely on manual approvals, cross-team coordination, or unmanaged secrets outside vaults, decommissioning controls lose reliability fastest.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity lifecycle and revocation support access control hygiene. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management requires provisioning, disabling, and removal controls. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Covers lifecycle handling for non-human identities and their credentials. |
| NIST AI RMF | Lifecycle governance applies to AI systems whose identities persist beyond use. | |
| CSA MAESTRO | Agentic systems need shutdown and revocation steps to prevent lingering access. |
Assign ownership for AI identities and require decommissioning proof when systems are retired.
Related resources from NHI Mgmt Group
- Which frameworks require stronger identity governance controls for sensitive access and regulated data?
- What breaks when organisations treat the DVS trust mark as a branding exercise instead of a compliance control?
- How do organisations know if their authentication platform is actually aligned with modern federal identity guidance?
- How should organisations map security controls to SOC 2 requirements without creating redundant work across frameworks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org