Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› First 90 Days
Governance, Ownership & Risk

First 90 Days

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Governance, Ownership & Risk

The first 90 days are the period when a new employee is still learning systems, norms, and obligations, which makes their behavior harder to interpret and more likely to create exposure. In security practice, this window is often treated as a heightened observation phase for access review, training reinforcement, and anomaly detection.

What the First 90 Days Really Represent

The first 90 days are a transition window, not just an onboarding milestone. During this period, people are still learning systems, policies, reporting lines, and acceptable behavior, so their actions are harder to judge and more likely to create avoidable exposure.

For security teams, that makes the period useful as a practical boundary for heightened observation, faster feedback, and tighter validation of access decisions. It is less about assuming bad intent and more about recognizing that unfamiliarity increases the chance of mistakes, shortcuts, and blind spots.

Why This Window Matters for Security and Access

The first 90 days often carry more uncertainty than steady-state employment because the new joiner is still building context. That affects how teams interpret activity, especially where access, exceptions, or unusual requests are involved.

In practice, this is the period when temporary permissions, role fit, and task boundaries deserve closer review. A new employee may need broader guidance, but that does not mean broader standing access should become the default. If the role touches privileged workflows, the early period is where excessive access is easiest to normalize before anyone notices the mismatch.

This is also why observation should not be limited to log review alone. Training reinforcement, manager check-ins, and access reconciliation work together, because unusual behavior in the early days can reflect confusion, incomplete enablement, or policy drift rather than maliciousness.

Common Failure Modes in the First 90 Days

The main failure mode is misalignment between what the person is allowed to do and what they actually understand. New employees may over-reach to get work done, accept unsafe shortcuts, or rely on informal instructions that do not match policy.

A second failure mode is normalization. If a temporary exception remains in place through the initial ramp-up, it can quietly become the new baseline. That creates lingering exposure because temporary access, informal approvals, and incomplete supervision are easiest to lose track of when the team is focused on productivity.

Security teams also need to account for signal quality. An unusual access pattern in the first 90 days is not automatically suspicious, but it should be interpreted against the role, the onboarding stage, and the expected learning curve. This is where Agentic AI Identity Risk Board Briefing is a useful reminder that early-stage risk management often depends on defining what good looks like, even when the operating model is still settling.

How to Use the First 90 Days as a Control Window

The first 90 days are most valuable when treated as a structured review period. Teams can use it to validate whether access matches the role, whether training has been absorbed, and whether the new employee’s activity patterns are consistent with expected learning.

That does not mean turning onboarding into surveillance. It means using the window to confirm that the person can operate safely with the access they have, and to correct mismatches before they become embedded. This is especially important where business pressure encourages fast provisioning or broad exceptions.

Because the period is time-bound, it is also a natural checkpoint for closing the loop: review outstanding exceptions, confirm manager confidence, and decide whether the person has moved from observation into normal operating expectations.

Risk and Threat Considerations

The first 90 days create a predictable exposure period because new employees are both less familiar with controls and more likely to be granted provisional access or informal latitude. The risk is usually not one dramatic event, but a cluster of small permission, process, and judgment failures that accumulate before the organization tightens oversight.

Failure mechanism: temporary access stays open too long, exceptions are not revisited, and early behavior is misread as normal while the employee is still learning the environment.

Impact: unnecessary data exposure, overextended privileges, weak accountability, and a larger blast radius if the new account, workflow, or onboarding path is abused or compromised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers lifecycle handling of credentials during early employment access
AC-2 — Account ManagementDefines account provisioning, review, and disabling for users in transition
AU-6 — Audit Record Review, Analysis, and ReportingSupports heightened observation and anomaly review during the onboarding window
Recommendation — Review and revoke onboarding credentials before they outlive the new-joiner transition window. Reconcile new-user accounts and temporary exceptions during the first 90 days. Monitor early user activity for unusual patterns and investigate exceptions promptly.
NIST CSF 2.0PR.AA-01 — Identity Management, Authentication, and Access ControlDirectly addresses access control and identity governance for new personnel
Recommendation — Validate that new-employee access matches role needs and is removed when no longer justified.
CIS Controls v8CIS-5 — Account ManagementCovers lifecycle control over accounts, permissions, and exception cleanup
Recommendation — Track onboarding accounts, temporary access, and revocation dates through the first 90 days.

Practitioner Guidance

Why practitioners should care: the first 90 days are often the best time to catch access mismatch, unsafe habits, or incomplete enablement before they harden into routine. A short, explicit review window is usually more effective than waiting for annual recertification or a later incident to reveal the problem.

Practitioner takeaway: treat the first 90 days as a controlled transition, not a grace period, and close the loop on access, training, and expectation-setting before the window ends.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org