They create audit risk because the organisation cannot easily prove that access was isolated, controlled, and attributable from start to finish. If secrets are exposed to the user or the connection bypasses the broker, auditors must trust logs that come after the fact. Strong evidence comes from enforced session mediation, not retrospective reconstruction.
Why direct sessions weaken auditability
Direct database and SSH sessions create audit risk because they collapse the control boundary. The user can interact straight with the target, so the organisation loses clean mediation over who accessed what, under which approval, and with which effective privileges. That makes the evidence trail dependent on logs, host artifacts, and later reconstruction rather than on enforced session control.
In practice, the problem is not only that a session happened, it is that the session may be hard to prove as isolated and attributable end to end. Once a password, key, token, or forwarded credential is available to the operator, the auditor has to trust that the action stayed within the intended scope unless the session was brokered and recorded.
Where the audit gap actually comes from
The biggest gap is between authentication and accountability. A direct session can satisfy login, yet still leave unanswered questions about command-level activity, data touched, lateral movement, or whether the same secret was reused outside the intended route. When the connection bypasses the broker, session metadata becomes thinner and the resulting evidence is easier to dispute.
This is why mediated access is stronger than retrospective log review. With a brokered session, the control point can enforce time bounds, inject credentials without revealing them, record activity, and preserve attribution across the full path. Direct access can still be legitimate, but it usually demands stronger compensating evidence to reach the same audit standard.
- For SSH, the main audit weakness is often key sprawl, shared keys, or long-lived access paths that make ownership and revocation difficult; SSH Key and SSH Certificate Management Guide is a useful control reference.
- For database access, exposed credentials or configuration shortcuts can eliminate meaningful separation between the requester and the target; the MongoBleed breach and Firebase misconfiguration exposure 2024 show how exposure and weak controls turn access into an evidentiary problem.
- Where privileged administration is expected, session brokering, recording, and command oversight materially improve auditability; Privileged Session Management Guide explains the control pattern in operational terms.
Why brokers, recordings, and injected credentials matter
Session mediation matters because it turns access into something the organisation can attest to, not just observe after the fact. If the broker authenticates the operator, injects the secret, records the interaction, and timestamps the session boundary, auditors can verify that the operator did not need durable knowledge of the secret and did not independently establish an uncontrolled path.
That distinction is especially important for systems that hold sensitive data or support privileged actions. A direct SSH shell or database client may be convenient, but convenience is not a control. If the session can be opened without mediation, a review may show that the organisation relied on trust in the operator and on logs that may not prove isolation, least privilege, or non-repudiation by themselves.
SOC 2 Trust Services Criteria (AICPA) is a useful external anchor when you need a formal assurance lens for control evidence, because it pushes teams to show that access was governed, monitored, and supportable by auditable records.
Risk and Threat Considerations
Direct sessions increase the chance that a compromise, misuse, or dispute cannot be cleanly bounded. If a secret is exposed to the user, copied into a client, or reused outside the intended workflow, the organisation may be unable to distinguish approved administration from unauthorized activity using logs alone.
Failure mechanism: the session bypasses mediation or reveals the credential, so the environment loses an enforceable control point and must reconstruct trust from incomplete evidence after the event.
Impact: audit findings become harder to defend, access reviews become weaker, and any later incident can be argued, rather than proven, because attribution and isolation were not preserved at the time of access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Direct sessions need auditable evidence of who did what and when. |
| IA-5 — Authenticator Management | SSH and database sessions depend on credential handling, rotation, and exposure control. | |
| AC-6 — Least Privilege | Direct sessions often widen effective privilege unless mediated and constrained. | |
| Recommendation — Log privileged session events with enough detail to reconstruct access and actions. Manage secrets so direct access does not depend on long-lived reusable credentials. Limit direct administrative access to the minimum necessary privileges and duration. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about controlling and evidencing access paths to sensitive systems. |
| A.8.15 — Logging | Audit risk depends on whether session records are sufficient for later proof. | |
| Recommendation — Define and enforce access rules that keep administrative sessions controlled and attributable. Ensure logs preserve evidence of session activity, boundaries, and accountability. | ||
Practitioner Guidance
What to verify: confirm that the access path enforces mediation, records the full session, and does not expose reusable secrets to the operator. If the answer depends on host logs, manual screenshots, or after-the-fact correlation, treat the control as weaker than it appears.
Decision rule: if the session can reach production data or privileged commands, prefer brokered access with credential injection and recording; if direct access must remain, require a documented exception with compensating monitoring and tighter review.
Practitioner takeaway: The audit question is not whether someone logged in, but whether the organisation can prove control, scope, and attribution without reconstructing the story later.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org