Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why does automated provisioning still need access reviews?
Governance, Ownership & Risk

Why does automated provisioning still need access reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Automation enforces the workflow, but it does not prove that the access model is still correct. Access reviews are what catch stale permissions, role creep, and exceptions that were valid once but are no longer justified. Without periodic review, automation can scale the same entitlement decisions across the estate.

Why automation and reviews answer different questions

automated provisioning is a control over how access gets created and removed. Access reviews are a control over whether the access still belongs there. The distinction matters because a workflow can be perfectly executed and still be based on an outdated rule, an exception that has outlived its purpose, or a role that has slowly expanded beyond the original job need.

That is why review and provisioning are complementary, not interchangeable. Provisioning gives you consistency and speed; review gives you assurance that the entitlement model still reflects current business reality. In mature programmes, the review cycle is the check against drift, not a backup for failed automation.

For teams building the operating model, the practical question is whether the provisioning rule is still trusted enough to keep scaling. NHIMG’s IAM and IGA Basics frames this split clearly: provisioning automates assignment, while governance validates the policy behind it.

What access reviews catch that automation will not

Access reviews are the place to find stale access that remains technically valid but no longer makes operational sense. That includes role creep after repeated promotions or transfers, exceptions granted for a project that has ended, inherited entitlements that were never revisited, and access that was correct at join time but is wrong now.

They also expose where automation is faithfully repeating a bad decision. If the source of truth, role design, or approval logic is wrong, provisioning will simply reproduce that error at scale. Periodic review is what gives you a chance to challenge the rule itself, not just the individual assignment.

This is especially important when review has to reach beyond named users. NHIMG’s Access Reviews and Certification Guide emphasises that review campaigns should remove access, not just document it, and that context is needed to avoid rubber-stamping. NHIMG’s IAM and IGA Basics is useful here too because it connects reviews to entitlement governance rather than treating them as a compliance ritual.

Why the best review programmes focus on drift, exceptions, and scale

At scale, automation can create a false sense of completion. Every new hire, transfer, application, or machine account may be provisioned correctly at the moment of request, yet the estate still accumulates access that is no longer aligned to current duties. Reviews are the mechanism that slows that accumulation down and forces the organisation to decide whether legacy access should survive another cycle.

The highest-value reviews focus on the edges of the model: high-risk roles, exceptions, shared access, dormant assignments, and privileges that are not exercised often enough to be self-evident. Those are the places where automation is most likely to keep quiet while risk grows.

For practitioners, the useful source of truth is not whether the workflow ran, but whether the entitlement still has a named owner and a current justification. NHIMG’s Access Reviews and Certification Guide and Role Mining and Role Design Guide both support that operating model by tying review outcomes back to role quality and access governance.

Risk and Threat Considerations

Automated provisioning becomes risky when it is treated as proof of entitlement correctness. If review lapses, the same stale role logic can be propagated across hundreds or thousands of accounts, which turns a local modelling error into broad excess access and larger blast radius.

Failure mechanism: outdated role definitions, unremoved exceptions, and dormant entitlements survive because the provisioning engine continues to apply them consistently while no one challenges whether they still match current duties.

Impact: organisations accumulate role creep, excessive privilege, and unused access that can be abused later, especially if an account is compromised or an internal transfer was never reconciled.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAutomated provisioning and periodic review are core account lifecycle controls.
AC-6 — Least PrivilegeReviews are needed to correct privilege creep that automation can preserve.
IA-5 — Authenticator ManagementProvisioning often assigns credentials or access material that must be reviewed over time.
Recommendation — Use AC-2 to require periodic review and removal of unnecessary access. Apply AC-6 to keep entitlements limited to current job need. Use IA-5 to govern credential lifecycle and revoke stale access material.
ISO/IEC 27001:2022A.5.18 — Access rightsThe subject is about verifying and revising user access rights over time.
A.5.15 — Access controlProvisioning and review are both access-control mechanisms in the ISMS.
Recommendation — Review access rights regularly and remove rights that are no longer justified. Define access control rules that require periodic recertification of assigned access.
CIS Controls v8CIS-5 — Account ManagementAutomated provisioning plus review maps to managing account lifecycle and access creep.
Recommendation — Implement account reviews to remove access no longer required.
OWASP ASVSV8 — AuthorizationThe question concerns whether assigned access remains appropriate after automation.
V6 — AuthenticationProvisioned access often depends on authenticating identities whose grants must still be justified.
Recommendation — Verify authorization decisions stay aligned with current business need. Ensure authentication-linked access is periodically revalidated and removed when stale.

Practitioner Guidance

What to verify: Treat the review as the control that validates the entitlement model, not the individual automation step. Verify that each review campaign can identify the owner, business purpose, last-used signal, and exception status for the access being certified.

Decision rule: If access was granted through automation but cannot be explained in current business terms, review it as a governance failure, not a workflow success. If the answer depends on “that is just how the role is built,” test the role design itself.

What good looks like: Provisioning creates fast, consistent access, and reviews reliably remove access that no longer has a clear owner, current justification, or active business need. NHIMG’s Segregation of Duties (SoD) Guide is a useful companion when review results need to be translated into enforceable access constraints rather than ad hoc cleanup.

Practitioner takeaway: Automation should scale the approved model, while access reviews prove the model still deserves to be approved.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org