Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk On-Demand Revocation
Governance, Ownership & Risk

On-Demand Revocation

← Back to Glossary
By NHI Mgmt Group Updated August 26, 2026 Domain: Governance, Ownership & Risk

On-demand revocation is the ability to remove access immediately when a risk, role change, or offboarding event occurs. It is a core SaaS governance capability because delayed removal leaves valid credentials and entitlements available for misuse long after access should have ended.

Expanded Definition

On-demand revocation is the operational capability to remove access as soon as a trigger occurs, such as offboarding, privilege reduction, contract termination, compromise, or policy violation. In NHI and SaaS governance, this applies to service accounts, API keys, tokens, certificates, and delegated application access, not just human users.

Definitions vary across vendors because some tools treat revocation as a permission change, while others require token invalidation, key deletion, session termination, and downstream sync. NHI Management Group treats the term as complete access cessation, including any standing credential that could still authenticate after the event. That makes it closely related to the lifecycle controls described in the Ultimate Guide to NHIs and to the control intent in NIST Cybersecurity Framework 2.0.

The practical distinction is speed and completeness. A role change that leaves a token valid for hours is not meaningful revocation in an agentic environment, because tools may keep acting autonomously after authority should have ended. The most common misapplication is treating ticket closure or directory deprovisioning as revocation when the live credential, cached token, or connected SaaS entitlement still remains active.

Examples and Use Cases

Implementing on-demand revocation rigorously often introduces workflow complexity, because security teams must balance immediate containment against application availability, auditability, and dependency discovery.

  • A developer leaves a team and the organisation immediately disables their cloud API keys, revokes active sessions, and removes CI/CD secrets tied to their account.
  • A service account is flagged during incident response and its certificates are invalidated while the application is switched to a replacement identity.
  • A third-party integration is terminated and all delegated OAuth grants, refresh tokens, and embedded secrets are removed from connected SaaS platforms.
  • An AI agent exceeds its approved scope and operators revoke its tool credentials before it can continue issuing actions through downstream systems.
  • A high-risk alert triggers emergency access removal, followed by verification that no cached tokens or replica credentials remain active across environments.

These patterns are discussed in the context of NHI lifecycle control in the Ultimate Guide to NHIs, and they align with the identity assurance and lifecycle expectations in NIST SP 800-63 when credentials must be promptly invalidated after trust is withdrawn.

Why It Matters in NHI Security

On-demand revocation is one of the clearest indicators of whether NHI governance is real or merely documented. NHI Management Group reports that only 20% of organisations have formal processes for offboarding and revoking API keys, and 91.6% of secrets remain valid five days after the targeted organisation is notified, which shows how slowly real-world containment often occurs. That delay is especially dangerous for NHIs because compromised credentials can continue acting without human approval, often across multiple SaaS platforms at machine speed.

In security operations, revocation is the difference between containing an event and merely acknowledging it. If secrets, tokens, or service accounts remain live after a compromise, the organisation can suffer lateral movement, data extraction, or unauthorised automation even after the original event is detected. The control also matters for Zero Trust programs, because access that cannot be withdrawn immediately is access that was never fully governed.

Organisations typically encounter the operational importance of on-demand revocation only after a breach, offboarding failure, or failed audit reveals that a supposedly removed identity still had working access, at which point revocation becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Covers revocation gaps in NHI lifecycle and access removal.
NIST CSF 2.0PR.AC-4Least-privilege access must be removed promptly when no longer needed.
NIST SP 800-63Identity assurance depends on timely invalidation of authenticators after trust ends.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous verification and rapid access withdrawal.
OWASP Agentic AI Top 10AGENT-05Agentic systems need prompt tool-access shutdown when behavior changes or risk emerges.

Automate deprovisioning so credentials and entitlements are withdrawn as soon as access is unjustified.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org