This process governs access that goes through the formal channel. The access that never goes through the formal channel — that is provisioned directly in systems by administrators, granted through group membership inheritance, created by automated workflows that do not route through the IAM program, or accumulated through the integration of systems that exchange identity attributes — exists outside the formal governance process and may also be outside the formal governance visibility.
The Channels That Bypass Formal Requests
Direct Administrative Provisioning
System administrators with the ability to grant access directly — in the operating system, the database, the application — can provision access without routing through the formal request process. In many organizations, this capability is available to a broad population of administrators and is used regularly for operational convenience: the access request process takes time, and the administrator who needs to unblock a user or grant temporary access for troubleshooting has the technical capability to act immediately. The access granted through direct provisioning may be logged in the system's audit trail. It may not be recorded in the IAM system as a formal access grant with an approval record and a review obligation.
Group Membership Inheritance
Group-based access models assign permissions to groups and add users to groups based on their role or department. When a group's permissions are expanded — because a new resource is added to the group's access scope, or because a permission is added to the group to address an operational need — all users in the group receive the new permission without individual access requests. The permission expansion is a group-level administrative action. The resulting access for each group member was never individually requested, never individually approved, and may not be surfaced in the next access review if the review focuses on user-level access grants rather than on group permission scopes.
Automated Workflow Provisioning
Automated workflows that provision access based on events — new employee creation in the HR system triggering access provisioning across multiple applications, project assignment triggering resource access, role change in the organizational chart triggering access modifications — create access without individual human access requests. The provisioning is automated and based on defined rules. The rules may be correct when they are defined and may not be updated when the access they provision is no longer appropriate for the rule's scope.
System Integration Identity Exchange
When systems integrate, they often exchange identity attributes that affect access decisions. An identity attribute from an HR system that flows to an ERP system may affect which ERP records the user can access, based on the ERP's access rules, without any IAM program involvement. The access is a consequence of the integration design. It was not formally requested by any user, approved by any access authority, or reviewed in any access review that focuses on formally provisioned access.
Building Visibility Into Informal Channels
The governance question for access that was never formally requested is not how to make it go through the formal request process — in many cases, the informal channels exist because they serve legitimate operational needs that the formal process cannot serve at the required speed. The governance question is how to make the access that exists in informal channels visible to the governance program, so that it can be reviewed, assessed, and governed with the same rigor as formally requested access.
Visibility into direct administrative provisioning requires that administrative access grants are logged in a way that is accessible to the access review process, not only in the system's audit trail. Visibility into group permission expansions requires that group scope changes are treated as access governance events, not only as administrative configuration changes. Visibility into automated workflow provisioning requires that the IAM system is aware of what access has been provisioned through automated workflows and for what governance reason.
The access review that includes informally provisioned access alongside formally requested access produces a more complete picture of the actual access landscape. The access review that only covers formally requested access covers the access that went through the governance process and does not cover the access that did not.
Make the informal channels visible to the governance process. The access that was never formally requested is still access that requires governance.
Audit what administrators can do directly. Review group permission scopes, not just group memberships. Include automated workflow provisioning in the access review population. The access exists whether or not it was formally requested.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
