Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who should be accountable for extending access controls…
Governance, Ownership & Risk

Who should be accountable for extending access controls across managed and unmanaged work environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with identity, security, and platform owners together, because extending access controls affects authentication policy, device trust, and application governance. IAM teams define the control model, security teams define risk tolerance, and operations teams ensure the policy works across devices and apps that employees actually use.

Why This Matters for Security Teams

Extending access controls across managed and unmanaged work environments is not just an endpoint policy issue. It changes how identity is asserted, how device trust is evaluated, and how applications decide whether a session should be allowed. When the same person uses both corporate-managed laptops and personal devices, the control model has to work without assuming a single device posture or network boundary. That is why identity, security, and platform ownership cannot be separated.

Current guidance suggests aligning this problem to the broader access governance model used in the NIST Cybersecurity Framework 2.0 and the OWASP Non-Human Identity Top 10, because both reinforce that access decisions should be tied to risk, context, and lifecycle control rather than static trust. NHIMG’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which is a warning sign for any environment where controls must span multiple device states and policy domains.

In practice, many security teams discover that access control gaps are not caused by a missing policy, but by inconsistent enforcement after a user moves outside the managed estate.

How It Works in Practice

The practical model is shared accountability. IAM owns the authentication and authorisation logic, security defines acceptable risk and assurance thresholds, and operations or platform teams make sure those controls actually function across SaaS, internal apps, VDI, browser access, and mobile workflows. The control stack usually combines conditional access, device posture checks, multifactor authentication, and session policies that can adapt when the device is unmanaged or partially trusted.

For controls to hold up, the organisation needs clear answers to three questions: who is requesting access, what device or session context is present, and what level of assurance is required for this application or data set. That is where policy design matters. NIST SP 800-53 Rev. 5 supports this kind of layered control thinking through access enforcement, monitoring, and least privilege requirements. On the implementation side, NHIMG’s Lifecycle Processes for Managing NHIs reinforces the need for lifecycle visibility and revocation discipline, which becomes even more important when unmanaged endpoints increase the number of places access can be exposed.

  • Use policy tiers so managed devices receive broader access than unmanaged ones.
  • Require stronger authentication and shorter sessions when device assurance is low.
  • Define which apps are blocked, limited, or allowed read-only outside the managed estate.
  • Log access decisions centrally so exceptions can be reviewed and tuned.

These controls tend to break down when legacy applications cannot evaluate device context or when business units bypass the standard identity stack to keep access working quickly.

Common Variations and Edge Cases

Tighter access control often increases user friction and support overhead, requiring organisations to balance assurance against productivity. That tradeoff becomes especially visible in BYOD, contractor access, and frontline environments where managed devices are not realistic. In those cases, the answer is not to relax accountability, but to assign it more clearly: security sets the minimum control bar, IAM implements the access logic, and platform teams own the exceptions needed to keep the business running.

There is no universal standard for this yet, but best practice is evolving toward context-aware access rather than one-size-fits-all role design. That means some users get permanent access only on managed endpoints, while unmanaged access is time-bound, scoped, and often read-only. NHIMG’s Key Challenges and Risks is useful here because it highlights how visibility gaps and excessive privilege compound quickly once controls span more than one operating model. For teams looking for a broader risk inventory, the Top 10 NHI Issues page is a practical companion for understanding how identity governance problems surface when access expands faster than oversight.

The main edge case is when unmanaged access is allowed into sensitive systems without per-session assurance checks. In that environment, the policy may exist on paper, but the effective control is too weak to be trusted.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Access control must adapt across device and session risk.
NIST SP 800-63Identity assurance changes when users authenticate from untrusted devices.
OWASP Non-Human Identity Top 10NHI-03Lifecycle control and revocation discipline matter when access expands beyond managed assets.
NIST AI RMFRisk governance needs clear accountability for dynamic access decisions.
NIST Zero Trust (SP 800-207)AC-6Zero Trust requires least privilege regardless of device ownership.

Define access rules by assurance level and enforce them consistently across managed and unmanaged endpoints.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org