Join our Newsletter — 33% off our NHI Course

What are the signs that an identity programme is still workforce-only?

A workforce-only programme usually cannot explain where service accounts live, which AI identities are active, or which cloud entitlements are disconnected from governance workflows. If identity reviews depend on spreadsheets or manual reconciliation, the programme is not seeing the full identity graph.

How to tell the programme is still workforce-only

The clearest sign is that the programme can name human user populations but cannot account for operational identities that actually drive production access. A workforce-only view usually stops at employee onboarding, MFA, and access review cadence, while the real environment also depends on service accounts, workload identities, API keys, and cloud entitlements that sit outside the review workflow.

That gap shows up in governance language as well as operations. If the identity team talks about joiner, mover, leaver activity but has no inventory of non-human identities, no owner for machine credentials, and no way to explain where privileged automation lives, the programme is describing a subset of identity rather than the full control surface. See the broader NHI control surface in Ultimate Guide to NHIs.

A useful signal is whether the programme can answer three concrete questions without manual detective work: where service accounts live, which identities are tied to automated systems or AI-enabled workflows, and which access paths are governed outside standard recertification. If those answers require spreadsheets, ticket archaeology, or team-by-team memory, the programme is still organised around people rather than identity as an enterprise control plane.

Where the missing coverage usually appears

Workforce-only programmes most often miss identities that are created by systems, not by HR processes. That includes cloud-native service identities, application accounts, certificates, tokens, and delegated access paths that exist because a platform, integration, or pipeline needs them. The programme may still be “strong” for users while remaining blind to the identities that have the highest automation density and the weakest natural ownership.

It also misses lifecycle differences. Human identities have relatively predictable joiner and leaver events, but non-human identities often persist far longer, are copied across environments, or are embedded in tooling where they are not routinely reviewed. When discovery, ownership, rotation, and offboarding are not part of the same operating model, the programme cannot prove that access is governed end to end. The inventory and lifecycle problem is described directly in NHIMG’s Top 10 NHI Issues.

Another common clue is that reporting is built around users, roles, and departments, but not around exposed privileges, dormant machine accounts, or secrets stored outside managed systems. That mismatch means the programme can pass a human access review while still leaving machine access unowned, unrotated, or disconnected from the governance workflow.

What practitioners should check before they call it mature

What to verify: The programme should be able to produce a current identity inventory that includes non-human populations, ownership, last-use data, privilege scope, and rotation status. If the team can only report on workforce users, the control model is incomplete.

What to measure: Look for the percentage of privileged or production identities that sit outside standard recertification, the share of credentials with no clear owner, and the volume of manual exceptions needed to reconcile identity data. Those signals are usually more revealing than general access-review completion rates because they expose the gap between policy and actual control coverage.

Common mistake: Treating cloud entitlement review or secrets management as separate programmes instead of connected identity problems. Once access is delivered through automation, the programme has to govern the actor, the credential, and the lifecycle together, or it will keep rediscovering the same blind spots in different tools.

Practitioner takeaway: A workforce-only programme is not defined by what it protects well, but by what it cannot enumerate, assign, or recertify outside the employee workflow. If the identity team cannot explain machine ownership and machine privilege with the same confidence as human access, the programme is not yet enterprise-wide.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Identity Discovery and Inventory Service accounts and machine identities must be discovered to avoid workforce-only blind spots.
NHI-03 — Credential Rotation and Lifecycle Stale machine credentials are a hallmark of identities outside workforce governance workflows.
NHI-05 — Privilege and Access Governance Disconnected cloud entitlements indicate access paths not governed with the rest of identity.
Recommendation — Inventory non-human identities and assign owners before relying on access reviews. Rotate non-human credentials on a defined cycle and tie expiry to lifecycle control. Apply least-privilege review to machine and cloud access with the same rigor as user access.
NIST CSF 2.0 GV.OC-01 — Organizational Context The programme scope must reflect all identity populations, not only the workforce.
PR.AA-01 — Identity Management, Authentication and Access Control Access control must cover the identities that actually use systems, including non-human ones.
PR.PS-04 — Resilience of Technology Assets Manual reconciliation and missing ownership weaken operational resilience of identity controls.
Recommendation — Define identity scope so the control programme covers human and non-human actors. Extend identity and access controls to service accounts, workloads and automation. Reduce manual identity reconciliation by maintaining authoritative ownership and inventory.
CIS Controls v8 5.3 — Account Management Workforce-only programmes miss non-human accounts that require lifecycle governance.
6.1 — Access Control Management Disconnected entitlements show access paths are not governed across the full identity graph.
6.3 — User Access Review Identity reviews based on spreadsheets are a sign that reviews are not operating on full inventory data.
Recommendation — Track and review all accounts, including service and application identities. Centralise access control decisions for both human and non-human identities. Base access reviews on authoritative inventory rather than manual reconciliation.