Subscribe to the Non-Human & AI Identity Journal
Home FAQ Governance, Ownership & Risk Why do identity-related breaches keep happening even with…
Governance, Ownership & Risk

Why do identity-related breaches keep happening even with access reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated July 5, 2026 Domain: Governance, Ownership & Risk

Access reviews often confirm what is already in the directory, not what is still justified by the business. If the underlying ownership data is wrong or incomplete, reviews validate stale records instead of removing risk. That is why access reviews need live identity context, not just periodic certification.

Why This Matters for Security Teams

Access reviews fail when they are treated as an evidence exercise instead of a live risk control. A review can only attest to what was recorded at the moment of certification, which means it often misses orphaned service accounts, over-privileged API keys, and identities whose business owner or purpose has drifted. NHI Management Group’s Ultimate Guide to NHIs shows how widespread the problem is, with 80% of identity breaches involving compromised non-human identities such as service accounts and API keys.

The core issue is that identity-related breaches are usually caused by stale context, not a missing certification checkbox. If ownership data is incomplete, access reviewers are asked to approve or revoke rights without knowing whether the identity is still tied to an active workload, a valid application path, or a current control objective. That is why access governance must include entitlement context, workload telemetry, and secret lifecycle data. Current guidance from the OWASP Non-Human Identity Top 10 aligns with this view: static records are not enough for non-human identities.

In practice, many security teams encounter the breach only after a long-lived credential has already been reused elsewhere, rather than through intentional review failure.

How It Works in Practice

Effective access reviews for non-human identities need to answer three live questions: what the identity is, what it is doing, and whether that activity is still justified. That requires joining directory data with workload metadata, secret inventory, and usage logs. For example, a service account may still exist in IAM, but if the application it supported was retired three months ago, the right action is removal, not recertification. NHI lifecycle controls described in NHI Lifecycle Management Guide are useful because they connect onboarding, rotation, review, and offboarding into one continuous process.

Security teams should also separate human approval from machine evidence. A reviewer can confirm business ownership, but the system should prove current activity and authorization state through runtime signals. That can include:

  • last-used timestamps for keys, certificates, and tokens
  • workload binding data showing which service or pipeline the identity belongs to
  • scope and privilege checks against current policy
  • secret age, rotation status, and revocation history
  • evidence that the identity is still linked to a live system or approved integration

This is where modern identity security starts to overlap with operational security. The 52 NHI Breaches Analysis shows how often exposed or unmanaged credentials become the entry point, while the OWASP Non-Human Identity Top 10 reinforces that over-permissioning and weak lifecycle hygiene are recurring patterns, not one-off mistakes. These controls tend to break down when identities are embedded in CI/CD, cloud automation, or third-party integrations because ownership becomes distributed and revocation can lag behind deployment.

Common Variations and Edge Cases

Tighter review processes often increase administrative overhead, requiring organisations to balance stronger assurance against the risk of slowing delivery. That tradeoff is especially visible when identities are tied to ephemeral jobs, multi-cloud pipelines, or external vendors. In those cases, a quarterly review may be too slow to catch a credential that was issued for a single deployment, but always-on review can create alert fatigue unless it is scoped to high-risk identities.

There is no universal standard for every environment yet, but current guidance suggests using risk-based review tiers. High-risk NHIs should be reviewed with runtime evidence and automatic expiry, while low-risk automation identities may use lighter attestations if rotation and logging are strong. This is also where ambiguous ownership becomes dangerous: if no named system owner exists, access reviews tend to preserve access by default. The same is true for shadow IT and AI-assisted workloads, where service accounts can be created faster than governance can classify them. NHI Management Group’s Top 10 NHI Issues and the Ultimate Guide to NHIs both highlight the recurring pattern: visibility gaps, weak rotation, and excessive privilege keep stale access alive long after reviewers sign off.

Where access reviews break down most often is not in the approval workflow itself, but in environments where identity state changes faster than the review cycle can observe.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Rotation and lifecycle gaps let stale credentials survive access reviews.
NIST CSF 2.0PR.AA-1Identity proofing and authorization need current context, not static records.
NIST CSF 2.0PR.AC-4Least privilege is undermined when reviews preserve excessive access.

Validate active identity context before certifying access and remove entitlements lacking current justification.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on July 5, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org