Automation enforces the workflow, but it does not prove that the access model is still correct. Access reviews are what catch stale permissions, role creep, and exceptions that were valid once but are no longer justified. Without periodic review, automation can scale the same entitlement decisions across the estate.
Why automation and reviews answer different questions
automated provisioning is a control over how access gets created and removed. Access reviews are a control over whether the access still belongs there. The distinction matters because a workflow can be perfectly executed and still be based on an outdated rule, an exception that has outlived its purpose, or a role that has slowly expanded beyond the original job need.
That is why review and provisioning are complementary, not interchangeable. Provisioning gives you consistency and speed; review gives you assurance that the entitlement model still reflects current business reality. In mature programmes, the review cycle is the check against drift, not a backup for failed automation.
For teams building the operating model, the practical question is whether the provisioning rule is still trusted enough to keep scaling. NHIMG’s IAM and IGA Basics frames this split clearly: provisioning automates assignment, while governance validates the policy behind it.
What access reviews catch that automation will not
Access reviews are the place to find stale access that remains technically valid but no longer makes operational sense. That includes role creep after repeated promotions or transfers, exceptions granted for a project that has ended, inherited entitlements that were never revisited, and access that was correct at join time but is wrong now.
They also expose where automation is faithfully repeating a bad decision. If the source of truth, role design, or approval logic is wrong, provisioning will simply reproduce that error at scale. Periodic review is what gives you a chance to challenge the rule itself, not just the individual assignment.
This is especially important when review has to reach beyond named users. NHIMG’s Access Reviews and Certification Guide emphasises that review campaigns should remove access, not just document it, and that context is needed to avoid rubber-stamping. NHIMG’s IAM and IGA Basics is useful here too because it connects reviews to entitlement governance rather than treating them as a compliance ritual.
Why the best review programmes focus on drift, exceptions, and scale
At scale, automation can create a false sense of completion. Every new hire, transfer, application, or machine account may be provisioned correctly at the moment of request, yet the estate still accumulates access that is no longer aligned to current duties. Reviews are the mechanism that slows that accumulation down and forces the organisation to decide whether legacy access should survive another cycle.
The highest-value reviews focus on the edges of the model: high-risk roles, exceptions, shared access, dormant assignments, and privileges that are not exercised often enough to be self-evident. Those are the places where automation is most likely to keep quiet while risk grows.
For practitioners, the useful source of truth is not whether the workflow ran, but whether the entitlement still has a named owner and a current justification. NHIMG’s Access Reviews and Certification Guide and Role Mining and Role Design Guide both support that operating model by tying review outcomes back to role quality and access governance.
Risk and Threat Considerations
Automated provisioning becomes risky when it is treated as proof of entitlement correctness. If review lapses, the same stale role logic can be propagated across hundreds or thousands of accounts, which turns a local modelling error into broad excess access and larger blast radius.
Failure mechanism: outdated role definitions, unremoved exceptions, and dormant entitlements survive because the provisioning engine continues to apply them consistently while no one challenges whether they still match current duties.
Impact: organisations accumulate role creep, excessive privilege, and unused access that can be abused later, especially if an account is compromised or an internal transfer was never reconciled.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Automated provisioning and periodic review are core account lifecycle controls. |
| AC-6 — Least Privilege | Reviews are needed to correct privilege creep that automation can preserve. | |
| IA-5 — Authenticator Management | Provisioning often assigns credentials or access material that must be reviewed over time. | |
| Recommendation — Use AC-2 to require periodic review and removal of unnecessary access. Apply AC-6 to keep entitlements limited to current job need. Use IA-5 to govern credential lifecycle and revoke stale access material. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | The subject is about verifying and revising user access rights over time. |
| A.5.15 — Access control | Provisioning and review are both access-control mechanisms in the ISMS. | |
| Recommendation — Review access rights regularly and remove rights that are no longer justified. Define access control rules that require periodic recertification of assigned access. | ||
| CIS Controls v8 | CIS-5 — Account Management | Automated provisioning plus review maps to managing account lifecycle and access creep. |
| Recommendation — Implement account reviews to remove access no longer required. | ||
| OWASP ASVS | V8 — Authorization | The question concerns whether assigned access remains appropriate after automation. |
| V6 — Authentication | Provisioned access often depends on authenticating identities whose grants must still be justified. | |
| Recommendation — Verify authorization decisions stay aligned with current business need. Ensure authentication-linked access is periodically revalidated and removed when stale. | ||
Practitioner Guidance
What to verify: Treat the review as the control that validates the entitlement model, not the individual automation step. Verify that each review campaign can identify the owner, business purpose, last-used signal, and exception status for the access being certified.
Decision rule: If access was granted through automation but cannot be explained in current business terms, review it as a governance failure, not a workflow success. If the answer depends on “that is just how the role is built,” test the role design itself.
What good looks like: Provisioning creates fast, consistent access, and reviews reliably remove access that no longer has a clear owner, current justification, or active business need. NHIMG’s Segregation of Duties (SoD) Guide is a useful companion when review results need to be translated into enforceable access constraints rather than ad hoc cleanup.
Practitioner takeaway: Automation should scale the approved model, while access reviews prove the model still deserves to be approved.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org