Join our Newsletter — 33% off our NHI Course

What breaks when organisations try to manage unmanageable applications with only password managers or network controls?

Password managers only address credential storage, not provisioning, deprovisioning, or policy enforcement. Network controls can block access, but they do not create durable governance over the application itself. The result is partial visibility with weak lifecycle control, which leaves shadow IT risk, access sprawl, and offboarding gaps unresolved.

Why This Matters for Security Teams

Password managers and network controls solve different slices of the problem, but neither creates lifecycle governance over an application that cannot be managed cleanly in the first place. A password manager may store secrets; it does not reliably provision access, revoke access on time, or prove who used what when. Network controls may reduce exposure, but they do not correct ownership gaps, orphaned accounts, or unsafe credential reuse.

That gap is why NHI Management Group consistently frames lifecycle control as the real issue, not just secret storage. The Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs shows that governance breaks when teams rely on tooling without identity ownership, offboarding, and rotation discipline. The scale of the problem is not theoretical: NHI Mgmt Group reports that only 5.7% of organisations have full visibility into their service accounts, which means most teams are enforcing controls against assets they cannot fully inventory.

For teams that assume a perimeter or vault is enough, the failure mode is usually delayed detection, not immediate outage. In practice, many security teams encounter this only after access sprawl or a secrets leak has already exposed the gap.

How It Works in Practice

When an application is difficult to manage, password managers and network controls become compensating measures rather than true control points. A password manager can centralise credentials, but it does not define the application owner, the business purpose, the approval path, or the expiry rules for access. Network controls can restrict reachability, but they do not tell security teams whether an account is still needed, whether it was shared, or whether a service principal should be rotated.

That is why current guidance from NIST Cybersecurity Framework 2.0 and NIST SP 800-207 Zero Trust Architecture pushes teams toward stronger identity-centric control. In NHI practice, that usually means:

  • Inventorying the application and every associated non-human identity, secret, and integration path.
  • Assigning an owner for provisioning, rotation, break-glass use, and offboarding.
  • Replacing shared static secrets where possible with short-lived credentials or token exchange.
  • Enforcing least privilege at the identity layer, not only at the network edge.
  • Tracking use, expiration, and revocation as part of a repeatable lifecycle process.

NHIMG research on the Top 10 NHI Issues highlights why this matters: 79% of organisations have experienced secrets leaks, and 71% of NHIs are not rotated within recommended time frames. Those failures are exactly what password managers and firewalls leave behind when they are treated as the control plane instead of support tools.

These controls tend to break down when the application is embedded in CI/CD, scripts, or third-party workflows because access becomes distributed across too many machines, owners, and release paths to govern manually.

Common Variations and Edge Cases

Tighter network controls often increase operational friction, requiring organisations to balance reduced exposure against the risk of blocking legitimate automation. In some environments, a password manager is still useful as a transitional control, but current guidance suggests it should be paired with identity lifecycle management rather than treated as the endpoint.

Edge cases are common. Legacy applications may not support modern federation, so teams fall back to vaulted passwords while they work toward decommissioning or wrapping the application with stronger controls. Third-party integrations can be even harder because the organisation may not own the downstream secret hygiene or revocation process. In those cases, the main question is not whether access exists, but whether the organisation can prove ownership, rotation, and rapid offboarding.

Where the issue becomes urgent is with secrets that live outside vaults or are never rotated. NHI Mgmt Group notes that Ultimate Guide to NHIs — Regulatory and Audit Perspectives supports treating ungoverned access as an audit failure, not just an operations nuisance. The practical takeaway is that password managers and network controls are necessary in some architectures, but they do not solve the structural problem of unmanageable applications. For that, teams need lifecycle ownership, revocation discipline, and visibility into every non-human credential path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-03 Covers secrets rotation and lifecycle gaps exposed by static password vaulting.
NIST CSF 2.0 PR.AC-1 Identity and access control fail when applications are unmanaged and ownership is unclear.
NIST Zero Trust (SP 800-207) Device trust and dynamic access enforcement Network-only controls do not provide zero trust identity decisions for non-human access.
NIST AI RMF GOVERN Unmanageable applications create governance gaps that AI risk management must account for.
CSA MAESTRO IAM Agentic and machine access needs identity-first governance beyond password storage.

Assign governance, accountability, and lifecycle controls before granting autonomous or machine access.