Accountability sits with the teams responsible for correlation, not with the last system that reported a clean status. HR, IAM, IGA, and PAM each own their domain, but no single one owns the cross system truth unless the organisation has a system of record. Governance should treat mismatches as findings and assign remediation clearly.
Why This Matters for Security Teams
A terminated employee with residual access is rarely a single-system failure. It is usually a correlation failure between HR offboarding, IAM deprovisioning, IGA recertification, PAM session control, and any host-level or local account that never reported back. NHI Mgmt Group’s Ultimate Guide to NHIs shows how often organisations lose sight of privileged identities once they leave the central control plane, and the same pattern applies when a host account is invisible to identity tooling.
The practical question is not only “who clicked revoke” but “who owned the mismatch until it was closed.” That ownership matters because a clean status in one system does not mean access disappeared everywhere else. The risk is amplified when host credentials, cached sessions, SSH keys, or local admin accounts are outside the scope of standard identity reconciliation. OWASP’s Non-Human Identity Top 10 captures the broader visibility problem: if the identity is not observable, it is not governable.
In practice, many security teams encounter the breach after the employee has already used the lingering access, rather than through deliberate offboarding validation.
How It Works in Practice
Accountability should be assigned by control domain, then tied together through a single remediation workflow. HR owns the employment state change, IAM owns central deprovisioning, IGA owns access review evidence, and PAM owns privileged session and credential controls. If a host still permits access after termination, the missing link is usually host inventory, endpoint control, or local credential discovery. NIST’s SP 800-53 Rev. 5 is useful here because it separates access enforcement, auditability, and accountability into distinct control families rather than treating them as one task.
Operationally, the best practice is to maintain a reconciliation path that compares the terminated status against every place access can persist:
- central directories and SSO sessions
- endpoint local accounts and cached tokens
- privileged access vaults and managed break-glass paths
- service desks, ticketing, and exception records
- host-based agents, scripts, and scheduled tasks that can re-enable access
If a system cannot be seen by central identity tooling, governance should treat that system as a blind spot until inventory, ownership, and revocation evidence are confirmed. NHI Mgmt Group’s NHI Lifecycle Management Guide is relevant because the same offboarding logic applies to credentials that outlive the user or process that created them. The right control is not simply “remove access in IAM,” but “verify no remaining path exists on the host, and record who validated it.” These controls tend to break down when endpoints are unmanaged, because local accounts and cached credentials bypass the central identity lifecycle entirely.
Common Variations and Edge Cases
Tighter offboarding verification often increases operational overhead, requiring organisations to balance speed of termination against proof of full revocation. That tradeoff becomes visible in remote laptops, contractor devices, lab hosts, and administrative break-glass environments where the authoritative identity source is incomplete. Current guidance suggests treating these cases as exceptions with explicit owner assignment, not as informal clean-up work.
There is no universal standard for this yet, but the direction is clear: if a host is outside central identity visibility, then the system owner, platform team, or endpoint operations team must accept responsibility for proving the account is gone. In complex environments, a terminated employee may still have access through offline credentials, local administrator rights, cached VPN tokens, or forgotten service contexts that were never tied back to HR. That is why the issue should be logged as a governance finding with a named remediation owner, not as a vague IAM discrepancy. The broader NHI risk picture in Top 10 NHI Issues and the breach patterns in 52 NHI Breaches Analysis both show the same lesson: visibility gaps are where accountability fails first, then access persists longer than anyone expected.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity inventory and verification are central to finding hidden host access. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Unknown or untracked identities create the exact blind spot described here. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management requires timely removal of access after termination. |
| NIST AI RMF | GOVERN | Governance assigns accountability when multiple systems share access truth. |
Inventory all identity sources and verify termination across each one before closing offboarding.
Related resources from NHI Mgmt Group
- Who is accountable when a terminated employee keeps access because the app only checks identity at login?
- Who is accountable when a terminated employee still has access to sensitive healthcare records?
- Who should be accountable for access governance when enterprises use a partner to implement identity controls?
- Who is accountable when identity and access management failures expose client information?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org