An access model that assigns permissions to the user profile rather than to each device individually. This approach keeps entitlements consistent across laptops, servers, and virtual machines, making it easier to provision, revoke, and audit access as people move between systems.
How User Centric Access Control Works
User centric access control ties entitlements to the person’s account or profile, so the same access decision follows that user across endpoints instead of being recreated for each laptop, server, or virtual machine. The model is about consistency in authorization, not about the device as the main place where permission is stored.
That shift matters because the control point becomes the user’s identity and role context, which simplifies provisioning and deprovisioning when someone changes teams, leaves the organisation, or temporarily needs additional access. It also reduces the chance that one device has a different permission set from another device the same user can reach.
Where It Fits in Access Governance
In practice, user centric access control sits inside broader IAM and IGA design, where the goal is to make permissions portable, reviewable, and easier to govern over time. It aligns with entitlement management, access reviews, and least privilege because the user profile is the stable reference point for deciding what should be granted and revoked.
This approach is especially useful when people move between workstations, cloud systems, and virtual environments. A well-structured access model helps avoid entitlement drift, where device-by-device permissioning creates inconsistent access paths that are hard to audit and even harder to clean up later.
For a broader treatment of how permission models are compared and applied, see Authorisation Models Guide, which explains how RBAC, ABAC, ReBAC, and policy-based approaches shape access decisions.
Benefits and Operational Trade-offs
The main benefit is administrative simplicity. When permissions follow the user profile, access changes can be handled once and propagated across systems, which reduces repetitive administration and improves the consistency of access enforcement. That also makes access recertification more meaningful because reviewers can evaluate one entitlement set instead of several device-specific variants.
The trade-off is that the user profile becomes a high-value control object. If it is poorly governed, excessive permissions can spread everywhere the user reaches, so the model depends on strong role design, lifecycle discipline, and timely revocation. It also works best when identity data is accurate and synchronised, because stale profile attributes can translate into stale access.
Good governance here usually pairs the model with clear entitlement ownership and regular review. NHIMG’s IAM and IGA Basics is a useful reference for understanding how those governance layers support consistent access control.
Examples and Related Access Patterns
User centric access control is common in environments where the same person needs a predictable access baseline across multiple assets, such as an employee moving from a laptop to a virtual desktop or from a workstation to a server console. The permissions are anchored to the person’s role and policy context, while the underlying system still enforces its own checks at runtime.
It is related to, but not the same as, device centric or session centric control. Device based controls focus on the endpoint’s trust state, while user centric control focuses on what the user is entitled to do regardless of which approved system they use. In mature environments, these models are often combined rather than treated as mutually exclusive.
Where entitlements must stay consistent across cloud workloads and infrastructure, Cloud Workload Identity Guide shows how identity portability is handled for non-human systems, and it highlights the same governance tension between consistency and over-privilege.
For access models that must be reviewed and corrected over time, Access Reviews and Certification Guide explains how recertification closes the loop when access follows a user across many systems.
Risk and Threat Considerations
User centric access control can concentrate risk if the user profile is over-entitled, stale, or poorly reviewed, because the same permission set may be effective across many systems at once. That makes role creep, dormant access, and weak revocation more consequential than in isolated device-specific schemes.
Failure mechanism: Excessive or outdated entitlements remain attached to the user profile and continue to work wherever the user authenticates, creating broad unauthorized access potential and making cleanup harder after role changes or departures.
Impact: A single governance failure can expose multiple systems at once, increase the blast radius of compromise, and make access audits less trustworthy because the permission state no longer matches the current business need.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | User-centric access depends on governed credentials and profile-linked access lifecycle. |
| AC-2 — Account Management | This term is about access attached to user accounts across systems. | |
| AC-6 — Least Privilege | User-centric access should limit each profile to only the permissions it needs. | |
| Recommendation — Manage user credentials so profile-based access can be issued, rotated, and revoked cleanly. Centralize account lifecycle actions so user access stays consistent across systems. Restrict each user profile to the minimum permissions required for its role. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access decisions tied to user profiles are governed by access-control policy and enforcement. |
| A.5.18 — Access rights | The term centers on granting, reviewing, and removing user access rights over time. | |
| Recommendation — Define and enforce access-control rules that keep user entitlements consistent and reviewable. Review and revoke user access rights as roles and system needs change. | ||
| CIS Controls v8 | CIS-5 — Account Management | User-centric access is implemented through account lifecycle and entitlement management. |
| CIS-6 — Access Control Management | The model requires centralized enforcement of permissions across devices and systems. | |
| Recommendation — Maintain accurate account lifecycle controls so access follows the user correctly. Apply centralized access controls to keep entitlements consistent across platforms. | ||
Practitioner Guidance
Why practitioners should care: The model is valuable only when the user profile is treated as a governed entitlement object, not as a static convenience layer. That means ownership, review cadence, and revocation timing matter as much as the initial permission grant.
What to watch for: Watch for profiles that accumulate access across teams, projects, or systems without a matching removal process, especially where users move frequently or temporary access becomes permanent. Those are the situations where user centric design turns into permission accumulation.
Practitioner takeaway: Use the model to standardise access, but verify that lifecycle controls are strong enough to keep the profile authoritative.
Related resources from NHI Mgmt Group
- How should organisations automate user access reviews without weakening control quality?
- How should security teams automate user access reviews without losing control quality?
- How should security teams reduce user access review fatigue without weakening control?
- What breaks when user access reviews are the main identity control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org