Because a certification confirms an entitlement, not the sensitivity of the repository behind it. If the access review process does not consume data classification and data-access evidence, it can approve accounts that still reach highly sensitive content. That is why identity-only governance creates false confidence in unstructured-data environments.
Why identity reviews miss the data exposure problem
Identity reviews answer a narrow question: should this principal still have this entitlement? That is useful, but it is not the same as asking what repository, dataset, or business record sits behind the entitlement. When the review process lacks data classification and data-access evidence, it can certify access that is technically valid but operationally too broad for the sensitivity of the content.
This is why identity-only governance often performs well on paper and poorly in unstructured-data environments. The reviewer sees an account, a role, or a group membership, but not the actual sensitivity of the folders, shares, chats, documents, or exports that the account can still reach. Access certification therefore becomes a control over permission structure, not a control over exposure.
In practice, the gap is usually created by weak context, not weak reviewers. If the review workflow does not surface file labels, repository ownership, last-access evidence, or downstream data classification, the reviewer has no basis to decide whether a permission is merely expected or genuinely excessive. A clean review can still leave highly sensitive content reachable.
What changes when data sensitivity is part of the review
Once classification and usage evidence are included, the review shifts from “who has access” to “who has access to what, and should they still need it.” That distinction matters because sensitive data exposure is often hidden behind broad entitlements, inherited group membership, shared drives, collaboration spaces, or legacy access paths that look ordinary in an identity report.
This is especially important in environments with loosely governed repositories, where content moves faster than entitlement models. A role may be reasonable for the application, but the repository behind it may now contain source code, customer material, credentials, regulated records, or other sensitive content. A certification process that does not see that change cannot catch the exposure.
For practitioners, this means the quality of the review depends on evidence quality. The review must be able to distinguish between an account that has nominal access and an account that actually touches sensitive material. Without that distinction, the process can remove risk from the spreadsheet while leaving the real exposure untouched.
Why this creates false confidence in unstructured-data environments
Unstructured-data platforms are difficult because sensitivity is not always encoded in the entitlement itself. A shared folder, wiki, collaboration channel, object store, or document library may be open through a legitimate identity path, yet contain material whose exposure would be unacceptable if the review only looked at the access record.
That is why identity-only certification can become a compliance exercise rather than a security control. It confirms that access exists, but not whether the content is still appropriate for that access. In that situation, the organisation may assume the review reduced exposure when it only confirmed persistence of the entitlement.
For a useful comparison point, identity governance resources such as Identity Data Quality and Identity Fabric Guide and the Identity Visibility and Intelligence Platforms (IVIP) Guide both point to the same operational reality: reviews only improve when identity data is joined to authoritative context and observable access signals.
That same pattern appears in Ultimate Guide to NHIs, Regulatory and Audit Perspectives, where access review and audit obligations are tied to governance evidence rather than isolated entitlement records. The control objective is not merely to list access, but to show that access remains justified against the thing being protected.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Reviewing access against data sensitivity is a risk treatment decision. |
| ID.AM-01 — Physical devices and systems within the organization are inventoried | Exposure review depends on knowing which repositories and assets are in scope. | |
| Recommendation — Define review criteria that incorporate data sensitivity and access evidence. Maintain an inventory of repositories and data assets subject to access review. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Overbroad access to sensitive repositories is the core failure mode. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Actual-access evidence is needed to validate whether review decisions match exposure. | |
| Recommendation — Reassess access assignments against least-privilege needs for the protected data. Use access logs and usage evidence to validate certification decisions. | ||
| ISO/IEC 27001:2022 | A.5.12 — Classification of information | Sensitivity classification must inform whether access remains appropriate. |
| Recommendation — Classify information so reviewers can judge entitlement against sensitivity. | ||
Practitioner Guidance
What to verify: Do not trust a certification outcome unless the reviewer could see the repository classification, data owner, and recent-access context for the asset behind the entitlement. If the review platform cannot show those three elements, it is not testing exposure, only permission.
Decision rule: If an identity review cannot prove that a principal’s access maps to the current sensitivity of the data it reaches, treat the result as incomplete and follow up with data owner validation. If the review can prove that mapping, the certification becomes materially more defensible.
Common mistake: Teams often assume that recertifying a role or group automatically reduces sensitive-data risk. In reality, the real control is the join between identity evidence and data evidence, not the attestation event by itself.
Practitioner takeaway: Identity reviews are necessary for governance, but they only become exposure controls when they are anchored to data classification and actual access context.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org