Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Pending Review
Governance, Ownership & Risk

Pending Review

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Governance, Ownership & Risk

Pending Review is the status applied to a submitted skill version before it has been cleared for use. The item may exist in the registry, but it is not yet trusted for installation. This state helps separate submission from approval and prevents unvetted agent behaviour from entering production workflows.

Expanded Definition

Pending Review is a governance state, not a trust decision. In an NHI workflow, it marks a submitted skill version, agent capability, or similar artifact as present in the registry but not yet approved for use. That distinction matters because registration alone does not mean deployment authority. The item can be inspected, scored, and routed through approval, but it should remain blocked from installation, activation, or delegation until review completes.

Definitions vary across vendors on whether Pending Review is treated as a lifecycle phase, an approval queue, or a policy status, but the operational meaning is consistent: the artifact is not production ready. In practice, this status is part of the control plane for agentic systems, where capability changes can alter execution scope, tool access, or data exposure. For governance context, the NIST Cybersecurity Framework 2.0 reinforces the need to manage access and change with formal oversight, while NHIMG’s Ultimate Guide to NHIs treats lifecycle control as foundational to reducing NHI risk.

The most common misapplication is treating Pending Review as a soft approval, which occurs when teams allow queued artifacts to be installed before security, owner, or risk validation is complete.

Examples and Use Cases

Implementing Pending Review rigorously often adds friction to release pipelines, requiring organisations to balance delivery speed against the cost of preventing unvetted agent behaviour from reaching production.

  • A new agent skill is submitted to the registry after code review, but remains Pending Review until security confirms its tool permissions and data scope.
  • An API-integrated automation module is uploaded by a product team, yet installation is blocked because the approval workflow has not cleared the associated secrets handling model.
  • A third-party agent extension is visible in the catalog but cannot be activated until the owner validates purpose, risk, and dependency posture, consistent with the lifecycle discipline described in the Ultimate Guide to NHIs.
  • An engineering team uses the status to separate submission from authorization, aligning internal policy with the access governance expectations reflected in the NIST Cybersecurity Framework 2.0.
  • A high-risk capability remains in Pending Review after detection of an unexpected dependency on privileged credentials, preventing silent expansion into production workflows.

Why It Matters in NHI Security

Pending Review is one of the simplest ways to stop untrusted agent capabilities from becoming operational controls. Without it, organisations collapse submission and approval into a single step, which makes it easy for malicious, buggy, or over-privileged skills to enter the environment before ownership, purpose, and secret access are verified. That failure mode is especially dangerous in NHI security because a single approved capability can be reused at scale across agents, pipelines, and service accounts.

The risk is not theoretical. NHIMG reports that only 5.7% of organisations have full visibility into their service accounts, which means many teams already struggle to see what is active, let alone what should still be awaiting approval. Pending Review helps create a defensible boundary between inventory and trust, and it supports auditability when changes must be reconstructed after an incident. Organisational maturity improves when this state is paired with logging, approver accountability, and least privilege review. Organisations typically encounter the operational importance of Pending Review only after a rejected or compromised skill attempt bypasses informal release habits, at which point the status becomes unavoidable to enforce.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07Pending Review enforces approval gating before NHI capabilities become trusted.
OWASP Agentic AI Top 10A-03Agentic workflows must separate submitted capabilities from executable trust.
NIST CSF 2.0PR.AC-4Access control governance includes validating changes before they gain use authority.
NIST Zero Trust (SP 800-207)SC-2Zero trust demands continuous validation of what can execute and access resources.
CSA MAESTROGOV-05MAESTRO emphasizes governance controls for agent lifecycle and approval boundaries.

Block activation until the NHI artifact passes security review and explicit approval.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org