Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Fixed State

← Back to Glossary
By NHI Mgmt Group Updated October 7, 2026 Domain: Governance, Ownership & Risk

The condition in which a rejected entitlement has been verified as removed and can be marked closed. In mature access review programmes, fixed state means the control has produced an observable change, not just a signed-off decision.

What Fixed State Means in Access Review

Fixed state is the point at which an access review decision has become an actual control outcome. The rejected entitlement has been verified as removed, so the programme can close the item as completed rather than merely approved for action.

This distinction matters because access recertification is only meaningful when the result changes the underlying entitlement set. A review that ends with a decision but no verified removal still leaves the exposure in place, which is why mature programmes treat fixed state as evidence of closure, not just workflow progress.

Why Fixed State Matters

Fixed state is the quality check that separates administrative completion from security completion. It confirms that the access review produced an observable change in the target system, which is what turns a compliance activity into an actual control result.

In practice, fixed state helps teams avoid false closure, where a ticket, attestation, or sign-off looks finished even though the rejected access still exists. That is especially important when reviews feed audit evidence, exception handling, or downstream remediation reporting.

How Fixed State Is Verified

Verification usually means checking the entitlement source, target system, or authoritative access record after remediation has run. The reviewer or control owner needs enough evidence to show the entitlement is no longer present, not merely that removal was requested.

The exact verification method depends on the access model. In some environments, closure may rely on reconciliation against the identity platform; in others, it may require confirming deprovisioning in the application, directory, or downstream system that actually enforces access.

Good fixed-state handling also distinguishes between temporary delay and unresolved failure. If the revocation is pending, blocked, or awaiting another owner, the item is not fixed state yet, even if the original review decision is final.

Common Failure Modes

Fixed state breaks down when programmes confuse decision approval with remediation completion. The most common failure is marking a review item closed before the entitlement has been removed and verified, which creates a gap between governance records and real access.

Another common issue is weak ownership of the final removal step. If the review workflow and the actual access system are not tightly connected, a rejection can sit in a handoff queue and never reach the enforcement point.

That is why fixed state is less about terminology than about control integrity. It tells you whether the review programme is producing trustworthy results or only generating administrative output.

Risk and Threat Considerations

Fixed state reduces the risk of lingering access after a review decision, but only if removal is actually verified. When programmes close items too early, rejected entitlements can remain active long enough to preserve unnecessary access, create audit findings, or leave a path open for misuse.

Failure mechanism: The review process records a rejection, but the deprovisioning step is delayed, blocked, or never reconciled back to the source of truth, so the entitlement remains effective.

Impact: Organisations can end up with stale access that appears remediated on paper while still existing in the target system, weakening least privilege and undermining confidence in the review control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementCovers the lifecycle of accounts and entitlements that must be removed after review.
AU-6 — Audit Record Review, Analysis, and ReportingSupports evidence that remediation was completed and can be traced back to the control action.
Recommendation — Verify that rejected access is actually removed before closing the account-management action. Use audit evidence to confirm the entitlement was removed and the closure is defensible.
ISO/IEC 27001:2022A.5.18 — Access rightsRequires timely review and adjustment of access rights, which includes confirming revocations.
Recommendation — Reconcile access rights to ensure rejected entitlements are removed before closure.
CIS Controls v8CIS-5 — Account ManagementAddresses managing and removing accounts and access that no longer should exist.
Recommendation — Close reviews only after the access change has been verified in the target environment.

Practitioner Guidance

Why practitioners should care: Fixed state should be treated as the closure criterion for access review remediation, not as a documentation detail. If a programme cannot prove removal, it has not yet proven control effectiveness.

Common misunderstanding: Teams sometimes assume a rejected entitlement is “done” once the reviewer signs off. In reality, the useful control signal is the verified disappearance of the access grant from the authoritative system or the enforced target.

Practitioner takeaway: Build closure rules around verified removal, and only mark the item complete when the entitlement is demonstrably gone.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org