Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do access reviews become weaker when teams…
Governance, Ownership & Risk

Why do access reviews become weaker when teams ignore activity data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Because reviewers end up certifying entitlements without knowing whether the access is actually used. Usage evidence turns reviews from paperwork into judgement, helping teams remove dormant access and keep privileges aligned with real operations.

Why access reviews weaken without activity data

Access reviews lose force when reviewers are asked to approve entitlements in the abstract, because the decision stops being tied to actual use. In practice, that means inactive access survives longer, reviewers rely on role labels instead of evidence, and the review process drifts toward ritual rather than risk reduction.

Usage data changes the question from “should this person have it on paper?” to “does this access still serve a current business need?” That shift matters because dormant entitlements are easier to miss when the reviewer cannot see whether the access is exercised, who is using it, or whether it has quietly become obsolete.

Without activity evidence, teams also lose a key signal for exceptions and edge cases. A privilege that looks reasonable in a job title may be unnecessary in reality, while a low-profile account can stay approved simply because nobody can tell whether it is serving automation, a backlog workflow, or nothing at all.

What usage evidence changes in an entitlement review

Usage evidence turns an access review into a judgement about current necessity, not just historical assignment. When teams can see logins, resource access, last use, frequency, and related operational context, they can separate actively used access from dormant access and remove the latter with far more confidence.

This is especially important for broad access lists, privileged roles, shared service access, and old accounts that remain technically valid long after the original need has passed. A review grounded in activity data can spot when access is legitimate but stale, when a role is assigned but never exercised, and when a review should trigger a deeper ownership check rather than a simple recertification click.

Used well, activity data also improves review quality over time. It helps teams refine roles, reduce noise in future campaigns, and detect where access decisions are being made too early, too broadly, or without enough operational context.

Why paperwork-style reviews create false confidence

Purely attestation-based reviews are vulnerable to rubber stamping. Reviewers often assume that if access was granted once, it still belongs, especially when they are facing large volumes, stale role names, or incomplete knowledge of how the system is actually used.

The result is a review that confirms entitlement ownership but does not test entitlement necessity. That gap is where privilege creep grows: access accumulates, usage fades, and no one gets a reliable signal that an entitlement has become dormant, redundant, or misaligned with current work.

Activity data does not eliminate human judgement, but it makes the judgement defensible. It gives reviewers a concrete basis for escalating uncertain cases, challenging access that is technically present but operationally dead, and avoiding the common failure mode where “still assigned” gets mistaken for “still needed.”

Risk and Threat Considerations

When activity data is missing, dormant access becomes harder to see and easier to abuse. Reviewers may approve stale entitlements that still work, which increases the exposed access surface and gives attackers or insiders more opportunities to use forgotten permissions, inherited roles, or rarely monitored accounts.

Failure mechanism: The review process validates assignment rather than actual use, so unused access survives and can later be exploited, inherited, or repurposed without clear justification.

Impact: Organisations accumulate privilege creep, weaken their ability to remove dormant access, and increase the likelihood that an unnecessary entitlement becomes a real incident path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingUsage evidence is needed to judge whether access is still exercised.
AC-2 — Account ManagementAccess reviews support account lifecycle decisions, including disabling unused access.
IA-5 — Authenticator ManagementReview campaigns often depend on whether credentials remain in active use.
Recommendation — Use AU-6 to review access activity and flag dormant entitlements for removal. Use AC-2 to review and revoke accounts that lack current business need. Use IA-5 to rotate or retire credentials tied to inactive access.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights must be reviewed against current need, not just prior approval.
A.8.15 — LoggingActivity data comes from logs that make entitlement use visible during review.
Recommendation — Review access rights periodically and remove those no longer justified. Ensure access logging can evidence whether entitlements are actually used.

Practitioner Guidance

What to verify: For each review item, check the last use date, access frequency, and whether the activity matches the stated business purpose. If the reviewer cannot connect the entitlement to observed use, treat that as a prompt for follow-up rather than automatic approval.

Decision rule: If an entitlement has no recent activity and no clear exception owner, remove or suspend it first, then confirm whether the access must be reissued. If the access is active but unusual, escalate for contextual review instead of relying on the role name alone.

What good looks like: Reviewers can see enough usage context to distinguish dormant, incidental, and business-critical access, and access recertification closes with removal of unused entitlements rather than broad sign-off.

Practitioner takeaway: The strength of an access review is not how many entitlements were signed off, but how confidently the team could separate real operational need from historical access that should have been retired.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org