Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Access Campaign
Governance, Ownership & Risk

Access Campaign

← Back to Glossary
By NHI Mgmt Group Updated August 28, 2026 Domain: Governance, Ownership & Risk

An access campaign is a structured review cycle in which designated reviewers assess a defined set of users, entitlements, or roles. Campaigns are the operational mechanism for certification at scale, usually organized around business ownership, risk priority, and deadlines that drive remediation and attestation outcomes.

Expanded Definition

An access campaign is a time-bound governance process for reviewing a defined population of entitlements, roles, or users and confirming whether access still matches business need. In NHI operations, the same pattern applies to service accounts, API keys, workflow identities, and agent permissions, although definitions vary across vendors on how broad the review scope should be. NHI Management Group treats an access campaign as a certification workflow, not a technical enforcement mechanism, because the campaign records review decisions while downstream systems perform remediation. That distinction matters when organisations need audit evidence for privileged access, shared accounts, or identities that are owned by applications rather than people. The strongest campaigns are built around data sensitivity, business ownership, and exception handling, not just calendar cadence. For control alignment, the concept maps closely to least-privilege governance in the OWASP Non-Human Identity Top 10 and access review expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls.

The most common misapplication is treating an access campaign as a spreadsheet exercise, which occurs when reviewers approve entitlements without verifying actual system ownership or current runtime use.

Examples and Use Cases

Implementing access campaigns rigorously often introduces reviewer fatigue and remediation backlog, requiring organisations to weigh faster attestation cycles against the cost of incomplete decisions.

  • A quarterly campaign reviews all production service accounts that can reach payment systems, with the application owner deciding whether each secret-backed identity still needs access.
  • A risk-based campaign targets privileged NHI roles first, using the lessons seen in the 52 NHI Breaches Analysis to prioritise identities that touch sensitive infrastructure.
  • An engineering organisation runs a campaign after a system migration to certify which CI/CD tokens, automation users, and cloud roles were left behind and should be removed.
  • A security team pairs campaign results with OWASP Non-Human Identity Top 10 guidance to identify over-privileged accounts that were never mapped to a clear owner.
  • Following a credential exposure event, reviewers use the access campaign to confirm which keys, certificates, or delegated roles should be rotated, revoked, or reissued after the incident.

Campaigns work best when the review list is narrow enough for meaningful validation and broad enough to capture inherited access that would otherwise be missed.

Why It Matters in NHI Security

Access campaigns are one of the few governance controls that can expose hidden NHI sprawl before it becomes an outage, an abuse path, or an audit failure. They matter because service accounts and agent identities often accumulate permissions silently, especially when teams duplicate roles for speed or leave old automation in place after a project ends. In NHI Management Group research, exposed AWS credentials have been observed to attract attacker attempts within an average of 17 minutes, which shows how quickly unreviewed access can become an active intrusion path. That urgency is echoed in the Microsoft SAS Key Breach and the DeepSeek breach, both of which illustrate how quickly exposed or overextended access turns into operational exposure. Campaigns also provide the evidence trail needed to defend decisions when access is retained for legitimate automation rather than removed outright.

Organisations typically encounter the need for access campaigns only after a leaked secret, suspicious automation, or failed audit reveals that nobody can prove why a non-human identity still had access, at which point the campaign becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02Access campaigns expose over-privileged NHIs and stale secret-backed access.
NIST CSF 2.0PR.AC-4Access review campaigns operationalize least privilege and access governance.
NIST SP 800-63IAL2Identity assurance supports trustworthy review of accounts and delegated access.
NIST Zero Trust (SP 800-207)Zero trust requires continuous validation of who or what should keep access.
NIST AI RMFAI systems need governance for roles, permissions, and authorized use of tools.

Review entitlements on a defined cadence and revoke access lacking current business need.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org