Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Access Drift

The gap between approved access and actual access.

Access drift is what happens between access reviews. Nuxari detects it continuously, not quarterly.

What is access drift

Access drift is the condition where a user's actual access in an external system differs from what was approved in Nuxari's access baseline. Drift is not inherently malicious. it may result from manual changes made outside approved workflows, integration failures, role inheritance changes, emergency access that was never revoked, or legacy accounts that were never properly offboarded.

Regardless of cause, access drift represents a deviation from the intended security state. Nuxari's job is to detect it, classify it, and surface it with enough context for a human to make an informed remediation decision.

What this means for your organization
Most access governance programs do periodic manual reviews, quarterly at best, annually in many organizations. Access drift can persist for months before it is detected. Nuxari detects drift on a daily or configurable cycle, surfacing it when it appears rather than when the next review is scheduled.

Approved vs. observed access

Approved access is the access state that Nuxari has recorded as intentional and authorized. It is established through completed onboarding workflows, approved access request workflows, or explicit baseline imports during connector setup.

Observed access is what the connector reports as the current actual state from the external system, the ground truth pulled directly from Azure, GitHub, M365, or whatever system is connected.

When observed ≠ approved, a drift finding is created.

Severity classification

SeverityExamples
CriticalOwner/admin role on production without approval
HighElevated role (Contributor vs Reader) on sensitive resource
MediumInactive user with active license assignment
LowPermission present but rarely used; offboarding cleanup candidate

Real examples

Azure role escalation
Approved baseline
Jordan Lee → Reader on Azure Subscription
Observed state
Jordan Lee → Contributor on Azure Subscription
Severity
High
Control reference
AC-6 (Least Privilege)
GitHub org admin outside policy
Approved baseline
Morgan Kim → Member of GitHub Org
Observed state
Morgan Kim → Owner of GitHub Org
Severity
High
Control reference
AC-6 (Least Privilege)
Offboarded user with active license
Approved baseline
Alex Rivera → no active licenses (offboarded 2026-05-15)
Observed state
Alex Rivera → M365 E3 license still assigned
Severity
Medium
Control reference
AC-2 (Account Management)

Evidence at detection

When a drift finding is created, Nuxari immediately captures a snapshot of the observed access state, hashes it with SHA-256, and stores it immutably. Even if the access changes later, either through remediation or external action, the evidence of what was observed at detection time is permanently preserved.

This means that even if a finding is resolved manually outside the platform, the evidence that the deviation existed is retained and auditable.

Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.