1. Introduction
Based on nearly twenty-five years of experience overseeing Non-Human Identity programs at leading global financial institutions, the gap between the pace of technology adoption and the maturity of the controls designed to govern NHIs has never been wider than it is today.
The NHI landscape has shifted fundamentally. Service accounts, API keys and tokens were already a governance challenge before agentic AI entered the picture, and even then most organisations were struggling to maintain basic visibility and control over them. Agentic AI has compounded that problem significantly, introducing a new class of NHI that is autonomous, dynamic, and capable of chaining actions across systems at machine speed. The gap that already existed has widened considerably.
At the NHI Management Group, tracking this shift across research, community discussions, and direct conversations with practitioners and vendors points consistently to the same conclusion. There is a clear and growing governance gap at the heart of enterprise NHI programs. Most organisations are still running reactive, audit driven controls against a threat surface that is expanding in real time, with limited visibility and almost no runtime protection.
This article sets out a maturity model for NHI and AI identity governance, and maps it against the product platform capabilities organisations need in order to progress. Saviynt’s platform has been used as an example of a leading enterprise identity platform evaluated as part of this research. Saviynt participated from a vendor perspective, drawing on their product capabilities. The goal is straightforward. Give security and identity leaders a framework to assess where they are, identify what is missing, and build a credible path forward.
2. The NHI Governance Problem
NHIs are already the number one identity security risk in most enterprises. Research from the NHI Management Group consistently shows that over 80% of identity related breaches involve a compromised NHI, whether that is a service account, an API key, or an OAuth token [1]. That figure alone should elevate this beyond an IAM team concern and into a board level conversation.
The deeper issue is structural. Governance frameworks in most organisations were designed for human identities and adapted, often poorly, to cover NHIs. The result is a set of persistent gaps that create compounding risk over time.
Lifecycle Ownership Ambiguity
For every NHI in your environment today, can you identify a named owner who is actively accountable for it? For most large organisations the honest answer is no. NHIs are created by developers, inherited by teams, and outlive the people who built them. The Cloud Security Alliance found that only 1.5 organisations in 10 are highly confident in their ability to secure NHIs, against nearly 1 in 4 for human identities [3]. Our own research puts it more bluntly still, with 68% of organisations saying they do not know how to fully address NHI risks [1]. That is not a gap, that is a void.
Succession Management Failures
When a developer leaves or moves teams, what happens to the NHIs and agents they created? In most organisations, nothing happens. This is not a fringe concern. When OWASP published its first Non-Human Identities Top 10 in 2025, improper offboarding came in at NHI1, ranked the single highest risk in the entire list [2]. The Cloud Security Alliance found only 20% of organisations have formal processes for offboarding and revoking API keys, and fewer still have any process for rotating them [3]. The credentials persist, the access persists, and accountability disappears. This is exactly how organisations end up with what Saviynt’s team have aptly called zombie agents, autonomous identities still running, still authenticated, answering to nobody.
Credential Rotation and Certification Gaps
Lack of credential rotation is the single most common cause of NHI related attacks, cited by 45% of organisations, ahead of inadequate monitoring and logging at 37% and over privileged accounts at 37% [3]. OWASP ranks long lived secrets at NHI7 for the same reason [2]. Formal access review and certification processes for NHIs are rare. There is typically no structured recertification of whether a given NHI still needs the access it holds, whether credentials have been used recently or exposed in code, or whether the underlying application is still in production. Without certification, privilege creep becomes invisible and cumulative.
The Agentic AI Amplifier
Everything above was already a serious problem being dealt with by organisations before agentic AI entered the picture. The research on where agent governance currently sits makes uncomfortable reading. In a Cloud Security Alliance survey of enterprises already running agents in production, only 21% maintained a real time registry or inventory of those agents, and fewer than a third, 28%, could reliably trace an agent’s actions back to a human or system across all their environments [4].
The compliance consequence follows directly from that. 84% of the same respondents doubted they could pass an audit focused on agent behaviour or access controls [4]. These are organisations that have already deployed. The governance is being retrofitted, if it is being built at all.
“AI agents don’t behave like users. They act autonomously, access systems continuously, and make decisions in real-time. Traditional identity security was never built for that.” Vibhuti Sinha, Chief Product Officer, Saviynt
3. Agentic AI: What Actually Changes
AI agents are NHIs, but treating them as just another static NHI is a category error that carries real consequences. Understanding what fundamentally changes with agentic AI is essential to building governance that works.
Non-Deterministic Behaviour
A traditional, static NHI is deterministic. It does what it is programmed to do, against known targets, on a defined schedule. An AI agent makes decisions. Its behaviour depends on context, on the model version it is running, and on the inputs it receives. The traditional approach of modelling expected behaviour and alerting on deviation becomes significantly harder because the baseline is not fixed. It shifts as the agent’s task scope evolves and as the underlying model is updated.
Dynamic Scope and the Model Update Problem
A static NHI’s capabilities are defined at provisioning and change only when an administrator explicitly modifies them. An AI agent’s effective capabilities can expand when the underlying model is updated, even when its assigned permissions remain unchanged. A new model version may be capable of actions the previous version was not. Without a governance process that triggers recertification of agent permissions on every model update, an agent can quietly gain capabilities nobody ever authorized.
The Multi-Agent Trust Chain
As enterprises adopt agent orchestration frameworks and protocols such as MCP, the Model Context Protocol, agents increasingly interact with other agents, passing identity and permissions along a chain. A single poorly governed agent inside a multi agent workflow can compromise the trust chain for every agent downstream. Each downstream agent assumes the upstream one is legitimate and properly authorised. When that assumption is wrong, the blast radius extends to everything those downstream agents can reach, not just the systems the compromised agent could touch directly.
Machine-Speed Action with No Human Review Loop
Traditional IAM was built around human decision velocity. An agent can execute thousands of actions in the time it takes a reviewer to open a ticket. Governance models that rely on human intervention as a primary control are structurally incompatible with agentic AI. Controls have to operate at machine speed, which means policy enforcement at the point of action rather than post incident review.
Accountability Without a Human Owner
When an AI agent causes harm, through compromised credentials, misconfigured permissions or unintended action chains, the accountability question becomes critical. Who owns the agent? Who approved its access? When was it last reviewed? Without formal registration, named accountability and lifecycle governance from the point of deployment, those questions have no good answers. Regulators are already beginning to ask them. The governance infrastructure needs to be in place before the incident, not assembled in response to it.
Static Controls to Dynamic Trust
Traditional NHI controls relied on static, rule-based detection and periodic remediation, sufficient when identities were passive and predictable. Agentic AI changes this entirely. AI agents spawn dynamically, behave differently after every model update, and can cascade failures at machine speed. Detection must now reason about intent, not just access. Remediation cannot wait for a human approval loop. Automation shifts from convenience to first-line control. Trust is no longer established at provisioning and reviewed periodically, rather it must be continuously revalidated in real time.
“Every AI identity has a birth, life, and retirement. If you don’t govern all three phases, you’re not managing risk, you’re multiplying it.” Vibhuti Sinha, Chief Product Officer, Saviynt
4. The NHI and AI Governance Maturity Model
The NHI & AI governance maturity model runs across five levels, from Ad hoc through to Optimised, and covers traditional non-human identities and AI agents within the same progression. Each level describes a capability state (what your controls actually do) rather than a point on a roadmap.
The critical point is that maturity is never a single number. It varies across at least two dimensions, and any assessment that collapses them into one enterprise score is telling you very little :
· Dimension 1 – The Type of Identity: Certificates, API keys, tokens, secrets, directory service accounts, workload identities and AI agents all carry different risk profiles and are governed by different teams using different tooling.
· Dimension 2 – Platform Maturity: Maturity in a well instrumented public cloud estate rarely reflects what is happening on premises, and neither tells you much about databases, mainframe, or the SaaS and third party applications where credentials are often issued outside any central process at all. Most large enterprises are running all of these at once, which means they are running several maturity levels at once.
This is why the assessment has to be risk-based rather than exhaustive. Map maturity across identity type and platform, then weight by exposure e.g. which populations carry the most privilege, reach the most sensitive data, or sit closest to production.
Where privilege is highest and maturity is lowest is where risk concentrates, and that intersection is where remediation effort belongs. Working through the estate uniformly, or improving whichever population happens to be easiest to fix, may produce a better looking dashboard and very little reduction in actual risk.

The NHI and AI Governance Maturity Model. Source: NHI Mgmt Group.
Level 1: Ad hoc
Weak controls, no visibility, unmanaged and stale accounts, secrets hardcoded into source. Most organisations start here whether they acknowledge it or not, and the honest test is simple. If you cannot produce a list, you are here.
On the agentic side this is where agents get deployed with no registration at all, frequently running on credentials inherited from whoever built the proof of concept, and nobody can say how many exist. That last point matters more than it sounds. An unknown population cannot be governed, sized, or budgeted for.
Level 2: Developing
Policies and standards exist on paper, a partial inventory has been built, and controls and hygiene are manual. Audits are ad hoc rather than continuous. Most enterprises we speak to sit here today.
For agents, the sanctioned ones are roughly known while shadow agents remain invisible, and critically, agents are not yet distinguished from other NHIs in the inventory. Treating an autonomous agent as a row in the same table as a batch job service account is how organisations end up applying controls that were never designed for the risk in front of them.
Level 3: Defined
Governance is formally in place, inventory and ownership are established, secrets vaulting is deployed and scanning is integrated into CI/CD pipelines. Ownership is tied to applications and services rather than to individuals, because owners move on and applications persist.
For agentic AI this is where an agent catalogue becomes non-negotiable. Every agent registered, scope documented against intended purpose, and the joiner, mover and leaver framework extended explicitly to cover agents. If an agent has no owner at Level 3, it should not be running.
Level 4: Managed
Provisioning and decommissioning are automated, lifecycle management is in place, secrets are secured and cycled without manual intervention, and monitoring controls are operational. The distinction from Level 3 is velocity. At Level 3 the right processes exist. At Level 4 they run at the speed of the environment rather than the speed of the team.
Agentic governance at this level means behavioural baselining rather than static rules, because agent behaviour is not deterministic enough for fixed thresholds to hold. It means orphan agent detection running continuously. And it introduces the control the previous section pointed to, recertification triggered by model update, so that capability gained through a version change cannot reach production without somebody explicitly approving the access that comes with it. No other NHI type needs this control, because no other NHI type changes what it is capable of on its own.
Level 5: Optimised
Preventive controls operate by default, dynamic just in time credentials replace static ones, access is policy based and context aware, and security is integrated rather than bolted on. This is an architectural shift, from trust based on possession of a secret to trust based on identity, context and policy evaluated at the point of action. The wider industry is converging on the same destination through standards based workload identity and short lived credential architectures. Continuous intelligent detection automatically identifies anomalous NHI behaviour and triggers remediation workflows without human intervention.
For agents, authorisation is evaluated at the moment of action rather than granted up front, and credentials are scoped to a single task invocation so they are worthless outside the context they were issued for. This is also where multi-agent trust chain policy becomes enforceable, with policy evaluated at every link in a chain of handoffs rather than only at the endpoint. That control sits at Level 5 rather than earlier for a practical reason. Without runtime enforcement already in place, there is nowhere for it to run. Moreover, AI agents are continuously monitored for behavioural drift, with intelligent detection automatically revoking or reissuing credentials and triggering remediation at the point of anomaly.
5. Operationalising the Model: The Saviynt Approach
Saviynt launched Zuma, its enterprise AI identity security platform, in July 2026. Zuma extends the existing converged IGA and PAM platform to cover NHIs and AI agents, and its approach maps closely to the progression outlined above. According to Saviynt, it is built on the same identity security data fabric as the rest of the platform, so AI identity governance does not become a separate silo alongside human and non-human identity [6].
Why Convergence Matters
One of the most persistent obstacles in enterprise NHI and AI identity programs is fragmentation. Secrets management sits with DevOps, PAM is owned by cyber, IGA handles human identities, and NHIs and AI identities fall into the gaps between all three. Governance split across disconnected tools will always have seams, and those seams are where risk accumulates. Saviynt states that treating NHIs and AI agents as first-class identities within the same governance framework used for human access removes the reconciliation overhead and closes the coverage gaps fragmentation creates.
The Three Pillars
● Zuma Insights – Discover: Replaces manual inventory and ad-hoc audits with continuous, automated discovery and risk surfacing across AI agents, service accounts, API keys and NHIs. Surfaces over-privileged, orphaned and unowned identities through a risk findings view and access graph. Saviynt believes that adopting Zuma Insights can help organisations to move from Level 1 to higher levels of maturity.
● Zuma Governance – Manage: Assigns ownership, automates lifecycle controls and formalises access governance. Covers automated ownership assignment and succession, formal registration, access request workflows, automated certifications, and audit-ready compliance evidence. Secrets, tokens and service credentials are governed as first-class NHIs rather than as a separate discipline. Saviynt believes that adopting Zuma Governance can help organisations to move from Level 3 to higher levels of maturity.
● Zuma Access – Protect: Runtime protection running from content filtering through to Intent-Aware Runtime Authorisation, or IARA, which evaluates identity, intent, context, risk and policy before each agent action executes. Adds a runtime agent deactivation that blocks a misbehaving agent in the moment rather than only removing it from governance, and dynamic just-in-time credentials provisioned at runtime that expire immediately after use. Saviynt believes that adopting Zuma Access can help organisations move from Level 4 to higher levels of maturity.
Capability Mapped to Maturity Level
The NHI Management Group has mapped Saviynt’s capabilities against the NHI and AI Governance Maturity Model.
NHI and AI capabilities from Zuma are mapped to the levels they can help organisations achieve maturity, i.e each capability unlocks at the maturity level where it becomes operationally relevant. Example: By adopting continuous discovery of AI and NHIs, organisations move from level 2 (Developing) to Defined and beyond. By rolling out full ownership and succession management controls, organisations can achieve a level 3 (Defined) and above.

Disclaimer: The mapping above is a sample and reflects a non-comprehensive list of capabilities documented by Saviynt during review, which were available at the time of the launch of the Saviynt Zuma product
Advantages and differentiators of the Zuma approach
Zuma, the enterprise AI Identity Security platform, offers a more cohesive framework for visibility, governance, and enforcement. This approach is highly beneficial for clients seeking to streamline the security and operationalisation of both NHIs and AI identities.
A unique feature of Zuma is its ability to track timeline changes for both NHIs and AI agents, which is particularly valuable for clients aiming to progress beyond “defined” maturity levels. By combining ownership with tracked timelines, organisations can ensure that every agent is registered, its scope is documented against its intended purpose, and the joiner-mover-leaver framework is explicitly extended to cover autonomous agents.
The combination of JIT credentials and IARA at runtime is currently unique in the industry. Organisations seeking the highest level of maturity in adopting NHIs and AI identities should evaluate the Zuma Access capabilities available at the time of this publication.
6. Recommendations and Call to Action
Assess Maturity Per NHI Type, Not Per Organisation
The most common mistake is overestimating where you are, and the second most common is scoring the whole estate as one number. Assess across both dimensions, identity type and platform, then weight the result by privilege and exposure so effort lands where risk actually sits. A secret manager in place does not put you at Managed. Documented policies do not mean enforced controls. If you cannot produce an inventory for a given population, that population is at Level 1 regardless of what the programme dashboard says.
Prioritise by Risk, Not Completeness
Focus initial effort on the highest risk accounts. Broad privileged access, credentials unrotated for over twelve months, and accounts with no identifiable owner. Targeted remediation in these areas delivers meaningful risk reduction without requiring a multi-year programme budget to be signed off first.
Extend Joiner, Mover, Leaver to AI Agents Now
Every AI agent should have a registered identity and a named owner from deployment. When that owner moves or leaves, the agent should be subject to the same offboarding review applied to human identities. OWASP ranks improper offboarding as the number one NHI risk [2], and only 20% of organisations have a formal offboarding process for API keys today [3], so the failure mode here is well evidenced and entirely predictable. This is the single most avoidable gap in most AI programmes.
Push for Platform Consolidation
Fragmented tooling across secrets management, PAM, IGA and AI governance creates reconciliation overhead and coverage gaps. Consolidation onto a platform that treats all identity types within a unified framework removes the seams where risk accumulates and reduces the operational burden on already stretched teams.
Build the Board-Level Narrative
Enterprise Strategy Group found that roughly two-thirds of organisations have suffered a successful cyberattack originating from a compromised NHI, and that 57% of those compromises definitively received board-level attention, with a further 37% indicating their board may have gone into the detail of the incident [5]. Boards are already aware of this risk category. The opportunity is to get ahead of it with a proactive investment narrative covering current maturity per population, target state, funding required, and the cost of inaction. Regulators across financial services, healthcare and critical infrastructure are already asking specific questions about NHI controls. Being ahead of that conversation is considerably better than being reactive to it.
7. Conclusion
NHI governance is not a compliance checkbox. It is a strategic capability that underpins the security of everything else an organisation is trying to do, including safe AI adoption.
The identity perimeter has shifted. It is no longer defined by the edge of the network or the boundary of the human workforce. It is defined by every credential, every token, every NHI and every AI agent that holds access to systems and data. In most organisations that population is growing faster than the frameworks designed to govern it.
The convergence of identity security and AI governance is not a future consideration. It is happening now, in production environments, across every major industry. Organisations that build mature NHI governance infrastructure today will be the ones that can scale AI adoption safely. Those that do not will be managing the consequences of ungoverned autonomous agents in environments they no longer fully control.
That is not a position any security leader wants to be in. And with the right framework and the right platform capabilities behind it, it is entirely avoidable.
References
[1] NHI Management Group, The Ultimate Guide to Non-Human Identities, Section 4: Key Research on NHIs. nhimg.org
[2] OWASP, Non-Human Identities Top 10, 2025. owasp.org/www-project-non-human-identities-top-10
[3] Cloud Security Alliance, The State of Non-Human Identity Security.
[4] Cloud Security Alliance, survey on enterprise readiness for autonomous AI agents, February 2026. Based on 285 responses collected September to October 2025.
[5] Enterprise Strategy Group, Managing Non-Human Identities, 2024.
[6] Saviynt, Zuma launch materials and product documentation, July 2026. saviynt.com/products/zuma
“This paper was commissioned by Saviynt. Research, analysis and conclusions are those of the NHI Mgmt Group.”
About the Author
Lalit Choda, known in the industry as Mr NHI, is the founder and CEO of the NHI Management Group (nhimg.org), the premier authority on Non-Human Identity research, education and governance. With nearly 25 years of experience in IAM, PAM and NHI, including running some of the largest global NHI regulatory programs in financial services, Lalit is a keynote speaker, podcast host, and author of The Ultimate Guide to Non-Human Identities.
About Saviynt
Saviynt’s identity platform manages and governs human, non-human and AI access across an organisation’s applications, data and business processes. With Zuma, its enterprise AI identity security platform, Saviynt helps organisations build, run and scale AI with confidence. For more information, visit saviynt.com.