A true up is an agreement record for licenses or services added after the original contract was signed. It captures mid-term expansion separately from the base agreement, which preserves auditability and gives renewal teams a clearer view of how demand changed over the contract lifecycle.
Expanded Definition
A true up is a contract mechanism used to record added licenses, capacity, or services after the original agreement is in force. In NHI and agentic AI operations, the same pattern appears when consumption grows mid-term and procurement needs a clean record of what changed, when it changed, and why.
Definitions vary across vendors, especially when billing systems, procurement records, and entitlement management platforms all use different labels for the same mid-cycle adjustment. The important distinction is that a true up is not the base contract itself and not a renewal in itself; it is the documented increase that bridges actual usage to the commercial terms already negotiated. That makes it useful for auditability, chargeback, and renewal planning, particularly where service accounts, API keys, or agent runtimes expand faster than the original forecast. The NIST Cybersecurity Framework 2.0 is relevant here because governance and asset visibility depend on knowing what exists, who approved it, and whether it still matches risk appetite. The most common misapplication is treating the true up as a procurement formality only, which occurs when teams add capacity without updating entitlement records or access controls.
Examples and Use Cases
Implementing true ups rigorously often introduces administrative overhead, requiring organisations to weigh contract clarity against the time needed to reconcile usage, approvals, and security review.
- A platform team adds new API keys for a burst of workload and records the expansion as a true up instead of waiting for renewal.
- An AI operations group provisions more agent seats mid-quarter and uses the true up record to align finance, security, and procurement.
- A vendor contract for a secrets manager expands to cover additional projects, with the true up separating added capacity from the original terms.
- An identity team links the true up to entitlement changes so service accounts added after signature can be traced during audit.
For governance context, NHIMG notes in the Ultimate Guide to NHIs that 97% of NHIs carry excessive privileges, which shows why every expansion should be visible beyond finance. The same operational visibility is reinforced by the NIST Cybersecurity Framework 2.0, especially where asset inventories and access governance must stay current as demand changes. In practice, a true up can be the difference between a controlled entitlement increase and an undocumented shadow expansion.
Why It Matters in NHI Security
True ups matter because NHI sprawl often grows faster than security review cycles. When additional service accounts, tokens, certificates, or agent permissions are added without a recorded expansion, organisations lose the ability to reconcile what was approved versus what is actually active. That weakens least privilege, complicates renewal decisions, and can hide overprovisioning that persists long after the original business need has passed.
NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, and 71% of NHIs are not rotated within recommended time frames, which means expansion events can easily become permanent risk if they are not captured cleanly. The Ultimate Guide to NHIs is a useful reference point for understanding why visibility, rotation, and offboarding must follow growth events. True ups also support control mapping under the NIST Cybersecurity Framework 2.0 because governance depends on traceable changes, not just initial approvals. Organisations typically encounter the real cost of an untracked true up only after an audit, incident, or renewal dispute, at which point the term becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | True ups affect lifecycle tracking for non-human identities and their expanding entitlements. |
| NIST CSF 2.0 | GV.OV-01 | Governance and oversight require documented change records for expanding access and services. |
| NIST SP 800-63 | Identity assurance principles depend on knowing when credentials or entitlements change. | |
| NIST Zero Trust (SP 800-207) | Zero Trust depends on continuously knowing and constraining active access, including added capacity. | |
| CSA MAESTRO | Agentic AI governance needs controlled records for added agents, tools, and execution capacity. |
Treat each true up as a change event that triggers revalidation of identity assurance and usage scope.