Manual propagation is the process of carrying an approved identity or access change into a target system by human action rather than API automation. It is used when a platform cannot integrate directly with the system. The control relies on workflow discipline, ticket status, and reconciliation to avoid entitlement drift.
Expanded Definition
Manual propagation is the controlled handoff of an approved identity or access change into a target system when direct integration, provisioning APIs, or event-driven sync are unavailable. In NHI operations, it is usually a fallback path for service accounts, API keys, certificates, or role assignments that must be updated by human action but still governed by approval, evidence, and reconciliation. The key distinction is that the change is not automated, even though the control objective remains the same: accurate identity state across systems.
Definitions vary across vendors, because some teams treat manual propagation as a temporary exception while others consider it a standard operating model for legacy platforms. In NHI governance, the process only works when ticket status, approver identity, and target-system confirmation are all traceable. That makes it closely related to lifecycle management, offboarding, and NIST Cybersecurity Framework 2.0 functions such as governance and protection. The most common misapplication is assuming a ticket closure means the access change was actually applied, which occurs when teams do not reconcile the source record against the target system.
Examples and Use Cases
Implementing manual propagation rigorously often introduces delay and verification overhead, requiring organisations to weigh coverage for legacy systems against the cost of slower change execution.
- A legacy payroll platform has no provisioning API, so an access removal request is approved in the IAM system and then entered manually by an operator.
- A certificate renewal is completed in one environment, but the same change must be copied by hand into an edge appliance that cannot be reached by automation.
- A cloud application supports modern identity federation, but a downstream report server still requires a local service account update handled through a change ticket.
- A decommissioned service account is disabled in the source system, then a technician verifies that the same identity is removed from the target system and records proof of completion.
These workflows are common in transitional estates where automation is incomplete, and they are often discussed alongside broader NHI lifecycle guidance in Ultimate Guide to NHIs. For standards-based thinking about process discipline and auditability, NIST Cybersecurity Framework 2.0 is a useful reference point. Manual propagation is especially relevant when a system boundary blocks direct orchestration, but the organisation still needs a measurable control path.
Why It Matters in NHI Security
Manual propagation is not just an operational inconvenience. It is a control point where entitlement drift, stale secrets, and failed offboarding can persist long after an approval has been granted. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, and that 91.6% of secrets remain valid five days after the organisation is notified, which makes human-led propagation a high-risk zone when reconciliation is weak. The NHI problem gets worse when manual steps are undocumented, because responsibility becomes fragmented across teams and shift handoffs.
This is why manual propagation must be treated as a governed exception rather than an informal workaround. It should require clear ownership, evidence of completion, and periodic checks against the source of truth. The broader NHI risk picture in the Ultimate Guide to NHIs shows how quickly unmanaged changes become exposure, especially where secrets and service accounts are involved. Organisations typically encounter the consequences only after a deprovisioning failure, at which point manual propagation becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 | Manual propagation often exists because secret and identity workflows are not fully automated. |
| NIST CSF 2.0 | PR.AC-1 | Access control processes require accurate, timely updates even when changes are handled manually. |
Track every manual identity change, then reconcile source and target states to prevent drift.
Related resources from NHI Mgmt Group
- When does automation help NHI security more than manual review?
- When does Kubernetes RBAC become too manual to govern safely?
- How can organisations reduce manual effort in access certification and evidence collection?
- What is the difference between manual access administration and automated lifecycle governance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org