Because the console is designed to show one identity, key or policy at a time, while access review requires a complete population view. Without a tenancy-wide inventory, teams cannot reliably identify over-permissioned users, unused credentials or policies that grant more access than intended.
Why OCI Console Visibility Breaks Down for Access Reviews
The OCI console is optimized for operational inspection, not for population-level certification. It can show an identity, key, policy or compartment in context, but access review depends on reconciling all principals, entitlements and standing permissions across the tenancy. That gap is why teams often miss over-permissioning, dormant access and policy paths that remain invisible when reviewed one object at a time.
What the Console Can Show, and What It Cannot Prove
Console views are useful for confirming the current state of a specific resource, but they do not answer the core access review question: “Who has access to what across the estate?” A reviewer needs to compare identities, groups, dynamic groups, policies, API keys and compartment relationships as a complete set, then decide whether each access path is still justified.
That is why the problem is not simply lack of screen real estate. The console fragments evidence across objects, while certification depends on a tenancy-wide inventory, a consistent entitlement model and enough context to judge business need. Without that, the reviewer can see individual permissions but not the full pattern of access accumulation.
Why Tenancy-Wide Inventory Changes the Review Outcome
Access review works when the organisation can enumerate all access-bearing objects, link them to owners and purposes, and compare them against current job function or system need. In OCI, the hard part is often not retrieving a single policy, but proving that the population is complete and current. If discovery is incomplete, certification becomes a partial check rather than an attestation of least privilege.
That is also where unused credentials and stale policies slip through. A console that surfaces one key or one policy does not necessarily reveal whether the same identity has additional indirect access, whether a group still grants broad rights, or whether a dormant credential remains valid. A proper review therefore depends on inventory and correlation, not just inspection.
What Breaks in Practice During OCI Access Reviews
Most breakdowns come from scale and indirection. Reviewers are forced to chase access through compartments, groups and inherited permissions, which makes the review slow and error-prone. As the number of identities and policies grows, the console becomes a navigation tool rather than a control surface.
The other common failure is false confidence. Teams may approve access because a single screen looks acceptable, while missing effective access granted elsewhere or permissions that remain after a role change. The result is certification theatre: the review appears complete, but the actual access estate is still wider than intended.
Risk and Threat Considerations
When access reviews rely on object-by-object console inspection, excessive privilege and dormant credentials are easy to miss. That creates a real exposure path for misuse, account takeover or lateral movement, especially where a single identity can reach multiple compartments or services through inherited policy.
Failure mechanism: The console shows local state for one identity or policy, but access review needs a complete entitlement graph. Missing inventory, indirect grants and unused credentials leave review gaps that attackers or careless operators can exploit.
Impact: Over-permissioned access persists longer than it should, revocation decisions are delayed, and the organisation cannot confidently attest that least privilege is actually enforced.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews depend on complete account and entitlement visibility. |
| AC-6 — Least Privilege | The question is about detecting permissions that exceed intended access. | |
| IA-5 — Authenticator Management | Unused credentials and keys are part of the review gap described. | |
| Recommendation — Inventory accounts and review their continued need regularly. Restrict permissions to the minimum required and remove excess access. Track, rotate, and revoke authenticators on a defined lifecycle. | ||
| CIS Controls v8 | CIS-5 — Account Management | Prescriptive account governance directly addresses review completeness and stale access. |
| Recommendation — Maintain an authoritative account inventory and remove unnecessary access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access review failures arise when access control is inspected piecemeal instead of end-to-end. |
| Recommendation — Define and enforce access control rules with periodic review of all entitlements. | ||
Practitioner Guidance
What to verify: Confirm that your review population includes all human and machine principals, all active credentials, and all policy paths that can confer access. If you cannot produce that inventory first, treat the review as incomplete.
What good looks like: Reviewers see a consolidated entitlement view, clear ownership, and evidence that stale keys, unused policies and inherited access paths are checked as part of the same certification cycle.
Common mistake: Treating console visibility as if it were review completeness. A clean-looking single object is not the same thing as a validated tenancy-wide access picture.
Practitioner takeaway: If access review cannot start from a complete inventory, the OCI console can support investigation, but it cannot by itself support reliable certification.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 5, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org