Because they only capture a point in time. In hybrid estates, access changes continuously across cloud platforms, infrastructure, and business systems, so a certification can be valid when signed and stale almost immediately after if the entitlement is combined with other access or used in a different context.
Why periodic certification misses the real access picture in hybrid estates
Periodic reviews are built to confirm whether a named entitlement should still exist, but hybrid environments change faster than the review cycle. Cloud roles, infrastructure permissions, application accounts, API access, and delegated administration can all evolve between certification dates, so the review reflects yesterday’s state rather than today’s risk.
That gap is why access review programs often look complete while still missing combinations that create enterprise exposure. A single entitlement may appear harmless in isolation, yet become material when it is combined with another role, reused across environments, or inherited through a connector or group that the reviewer does not see clearly.
Hybrid complexity also weakens reviewer judgment. Without a unified view of ownership, context, and effective access, reviewers can only approve or revoke what the certification tool exposes, not what the estate actually allows. That is where Access Reviews and Certification Guide and IAM and IGA Basics are useful, because they frame access review as a governance process, not a checkbox event.
Why point-in-time certification breaks down across cloud, apps, and infrastructure
Hybrid estates introduce moving parts that do not age together. Cloud entitlements may be granted through role assumption, app permissions may be inherited through nested groups, and infrastructure access may be managed separately from business-system entitlements. When those layers are reviewed on different cadences, the organisation can certify a partial truth and miss the combined path to misuse.
That is especially problematic when access is not just broad, but contextual. A permission that is acceptable in a dev account may be risky in production, and a token, service account, or delegated role may be harmless until it is paired with another control failure. The entitlement has not changed, but the enterprise risk has.
This is why lifecycle and remediation matter as much as the review itself. If the review does not trigger timely removal, rotation, or reclassification, it becomes an audit artifact rather than an access control. The strongest supporting view is lifecycle-aware governance, such as NHI Lifecycle Management Guide and Joiner-Mover-Leaver (JML) Guide, because they connect entitlement validity to change, offboarding, and revocation.
What hybrid risk looks like when access is certified but still dangerous
Enterprise risk is missed when certification focuses on existence rather than effect. A user, service account, or administrator can pass review and still retain enough access to move laterally, combine privileges, or act through a stale session or long-lived credential. In hybrid environments, that risk is multiplied by inconsistent visibility across platforms and by the fact that a single identity often touches multiple control planes.
Risk also emerges from role design and segregation failures. If review owners cannot see toxic combinations, over-broad roles, or reused privileges across systems, they may approve access that looks acceptable in a narrow system view but is dangerous at the enterprise level. Segregation of Duties (SoD) Guide and Role Mining and Role Design Guide help explain why bad role architecture makes periodic review inherently incomplete.
Finally, the risk scales with hidden or poorly inventoried access. If you do not know which identities exist, where they authenticate, or what they can reach, then certification is only validating the visible fraction of the estate. That is why access reviews should be paired with inventory and visibility work, not treated as a standalone control.
Risk and Threat Considerations
Hybrid access review failure creates a control gap that attackers can exploit, because stale approvals often sit next to active paths into production systems, cloud tenants, and sensitive business applications. The enterprise may believe access is governed, while the real exposure comes from access combinations, inherited permissions, and credentials that outlive the review window.
Failure mechanism: Point-in-time certification misses post-review entitlement drift, hidden inheritance, and cross-system privilege combinations, so access that was acceptable on the review date becomes excessive or abusable before the next cycle.
Impact: The organisation can keep approving access that enables privilege escalation, lateral movement, separation-of-duties violations, and audit blind spots, especially where cloud and on-prem systems are governed separately.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Periodic access reviews are part of account lifecycle control and entitlement governance. |
| AC-6 — Least Privilege | Hybrid access reviews miss risk when excessive access persists across systems and roles. | |
| AU-6 — Audit Review, Analysis, and Reporting | Review programs need evidence and analysis to detect drift between certification cycles. | |
| Recommendation — Review and remove accounts or entitlements that no longer match current business need. Enforce least privilege so approved access stays limited to required functions. Correlate audit evidence with entitlement changes to spot stale approvals sooner. | ||
| CIS Controls v8 | CIS-5 — Account Management | Access reviews and deprovisioning belong to practical account control in hybrid environments. |
| Recommendation — Centralize account review and remove access that no longer has a current owner or purpose. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Hybrid certification is an access-control governance activity that must reflect current permissions. |
| Recommendation — Define access review rules that account for current system state and business need. | ||
Practitioner Guidance
What to prioritise: Treat review quality as a visibility problem first. If reviewers cannot see effective access, ownership, environment, and inherited privilege in one place, the certification is not evidence of control, only evidence of a process.
What to verify: Check whether the review workflow can surface nested roles, cross-environment access, service and automation accounts, and recent entitlement changes before sign-off. If it cannot, use the review only as one input to remediation, not as a control assertion.
Decision rule: If access can materially change faster than the certification cadence, move high-risk entitlements to event-driven or exception-based review, and reserve periodic certification for lower-risk populations and governance reporting.
Practitioner takeaway: In hybrid estates, the control objective is not to certify access once, it is to keep review decisions close enough to operational reality that they still describe the enterprise risk you actually have.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org