Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Stacked Shares
Governance, Ownership & Risk

Stacked Shares

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Governance, Ownership & Risk

Stacked Shares describes access that accumulates across multiple role changes because old permissions are never removed. A user keeps adding new shares or entitlements over time, creating an oversized access footprint that is difficult to audit and more likely to expose systems beyond current job requirements.

How Stacked Shares Develop

Stacked Shares usually emerge when access provisioning is additive instead of subtractive. Each promotion, team change, or temporary assignment adds new shares or entitlements, while prior permissions remain in place, so the access profile expands far beyond the person’s current duties.

This pattern often reflects a weak deprovisioning process, fragmented ownership of entitlements, or a lack of periodic access review. The issue is not that any single share is unusual, but that the total access footprint grows across events that should have triggered cleanup.

Why Stacked Shares Are Hard to See

Stacked Shares are difficult to detect because the excess access is usually legitimate in isolation. One share may be valid for a prior role, another for a project, and a third for a temporary exception, but the combination creates cumulative access that no longer matches least-privilege expectations.

That makes the condition easy to miss in environments where entitlement history is spread across ticketing systems, IAM workflows, or application-specific permission stores. The practical challenge is not just identifying what a person has today, but understanding why each permission still exists.

Security Implications of Stacked Shares

When permissions accumulate, the exposure is broader than convenience or admin overhead. A user with stacked access can reach more systems, data, or functions than current business need justifies, which increases the blast radius of account misuse, insider error, or compromise.

Overprivileged access is easier to abuse and harder to justify during audits. The longer stacked permissions remain in place, the more they resemble standing access, even when the original entitlement was meant to be temporary or role-bound.

Framework guidance such as NIST SP 800-53 Rev 5 Security and Privacy Controls and NIST Cybersecurity Framework 2.0 both support the need to govern access, review entitlements, and reduce unnecessary privilege over time.

How Organisations Reduce Stacked Access

Reducing stacked access depends on treating entitlement cleanup as part of the identity lifecycle, not as an occasional housekeeping task. Access changes should be tied to role changes, and old entitlements should be removed when they no longer serve a current business purpose.

Periodic recertification helps surface permissions that were never revoked, while role design helps prevent the same user from collecting overlapping access across multiple paths. In practice, the goal is not simply to count shares, but to keep every surviving permission defensible against current need.

For environments with stronger identity controls, NIST SP 800-63 Digital Identity Guidelines helps anchor authentication assurance, while NIST Cybersecurity Framework 2.0 reinforces governance and continuous access management as part of a broader security program.

Risk and Threat Considerations

Stacked Shares create cumulative exposure because each retained entitlement widens the set of systems and data reachable from one account. That makes a normal user error, phishing event, or insider misuse more damaging than it should be.

Failure mechanism: Access additions outpace removals, so old permissions survive role changes and exceptions become permanent.

Impact: The account accumulates excessive authority, making compromise, misuse, and audit failure more likely and increasing the blast radius of any incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementStacked Shares arise when account entitlements are not removed across role changes.
AC-6 — Least PrivilegeStacked Shares create excessive access beyond current job requirements.
IA-5 — Authenticator ManagementStacked access often persists alongside unmanaged credentials that keep surplus access usable.
Recommendation — Track entitlement changes and remove stale access when role or need changes. Constrain each account to the minimum access required for current duties. Control credential lifecycle so old access paths are revoked promptly.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlThe term describes access accumulation that should be governed through access control and lifecycle review.
GV.OC-03 — Roles, Responsibilities, and Authorities Are Established and CommunicatedStacked Shares often persist when ownership of access changes is unclear.
Recommendation — Enforce entitlement review and revocation when roles or access needs change. Assign clear ownership for granting, changing, and removing access.
ISO/IEC 27001:2022A.5.15 — Access controlStacked Shares are an access-control weakness that requires policy and enforcement.
A.5.16 — Identity managementStacked Shares reflect identity lifecycle drift across role changes.
Recommendation — Define and enforce access rules that prevent cumulative excess privilege. Keep identity records aligned with current roles and remove outdated entitlements.

Practitioner Guidance

Why practitioners should care: Stacked Shares are a governance problem as much as an access problem, because they indicate that entitlement ownership is not keeping pace with job changes. If a person’s access cannot be explained in current-role terms, the access model is already drifting.

Common misunderstanding: Teams often treat each share or entitlement as individually approved and assume that approval history proves safety. The real question is whether the combined access set still makes sense after all role changes, exceptions, and temporary grants are considered together.

Practitioner takeaway: Review access cumulatively, not one permission at a time, or stacked entitlements will keep reappearing as “valid” access.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org