Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when manual access management causes…
Governance, Ownership & Risk

Who is accountable when manual access management causes security and productivity loss?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

Accountability sits with the business and security leaders who own the risk register, access policy, and control outcomes. IT can execute the process, but leadership must decide which applications require stricter controls, where exceptions are acceptable, and how much residual risk the organisation will tolerate. Without named ownership, access sprawl becomes a recurring operational problem.

Why This Matters for Security Teams

Manual access management becomes a business risk when approval chains, exceptions, and ad hoc reviews absorb time without actually reducing exposure. The problem is not just inefficiency. It is accountability drift: leaders define access policy, but operations teams inherit the friction, while users respond by seeking shortcuts. Over time, that pattern creates shadow approvals, stale entitlements, and inconsistent enforcement.

This issue is especially visible in non-human identities, where access is often granted to service accounts, scripts, and integrations that do not follow human work patterns. NHI Management Group’s Ultimate Guide to NHIs notes that NHIs outnumber human identities by 25x to 50x in modern enterprises, which means manual handling does not scale. The OWASP Non-Human Identity Top 10 also treats excessive privilege and weak lifecycle control as recurring failure modes. In practice, many security teams encounter access sprawl only after a business outage, audit finding, or credential leak has already forced the issue.

How It Works in Practice

Accountability should follow decision rights, not ticket handling. Business owners decide which systems need tighter control, what exceptions are acceptable, and what productivity loss is tolerable. Security leaders define the policy boundary, evidence requirements, and review cadence. IT and IAM teams execute the process, but they should not be left to invent policy through exception handling.

For manual access management, the practical question is whether the control is being managed as a business tradeoff or as a technical chore. If approvals take too long, users bypass them. If reviews are too broad, managers rubber-stamp them. If revocation is manual, access lingers long after need has ended. NHI Management Group’s Top 10 NHI Issues highlights that poor rotation, limited visibility, and over-privilege are not isolated mistakes; they are control design failures.

  • Assign a named risk owner for each high-impact application, integration, or access path.
  • Define which approvals are mandatory, which can be pre-approved, and which require documented exception handling.
  • Measure both security outcomes and operational delay, so productivity loss is visible in the governance record.
  • Use policy-backed controls such as NIST Cybersecurity Framework 2.0 to connect access decisions to risk management and accountability.

Where this guidance breaks down is in highly dynamic environments with frequent contractor churn, machine-to-machine integrations, or mixed human and NHI access paths, because manual review cycles cannot keep pace with the rate of entitlement change.

Common Variations and Edge Cases

Tighter access control often increases operational overhead, so organisations must balance faster delivery against stronger evidence and revocation discipline. That tradeoff becomes harder in environments with legacy applications, shared accounts, or unmanaged third-party access. In those cases, the right answer is usually not “more manual review,” but clearer ownership and fewer exceptions.

There is no universal standard for every approval model yet, but current guidance suggests that exception-heavy processes should be time-bound, logged, and reviewed against a named risk acceptance. For NHI-heavy workflows, use lifecycle ownership rather than one-time provisioning. The Ultimate Guide to NHIs and the Regulatory and Audit Perspectives section both reinforce that auditability improves when ownership, rotation, and offboarding are explicit.

Edge cases usually surface where business leaders want the benefit of speed but do not want to own the residual risk, or where security teams are asked to approve exceptions without authority to change the underlying process. That arrangement turns manual access management into a recurring source of both security exposure and productivity loss, rather than a controlled governance function.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Manual access often leaves NHI credentials unrotated or over-scoped.
NIST CSF 2.0PR.AC-4Access permissions must be managed as a risk decision, not a ticket queue.
NIST SP 800-53 Rev 5AC-2Accountability depends on controlled account lifecycle management.
NIST Zero Trust (SP 800-207)SP 2Zero Trust requires continuous verification instead of manual trust assumptions.
NIST AI RMFAI risk governance reinforces named ownership for access-related decisions.

Replace standing access assumptions with continuous, policy-driven authorization checks.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org