Join our Newsletter — 33% off our NHI Course

Tenancy-Wide Identity Inventory

A complete, governed list of every identity object in a cloud tenancy, including users, credentials, policies and software actors. In OCI, this matters because reviewing one profile at a time cannot prove least privilege across the estate.

What a tenancy-wide identity inventory actually captures

A tenancy-wide identity inventory is broader than a user list. It should include every identity-bearing object that can influence access, including human accounts, service identities, credentials, policies, and software actors, so the tenancy can be assessed as one governed estate rather than isolated profiles.

That broader scope is what makes the term operationally meaningful. If inventory stops at named people, the organisation can miss the identities that actually drive cloud access, such as workloads, automation, and delegated software agents. A useful inventory therefore needs clear ownership, consistent classification, and enough detail to show how each object participates in authentication or authorisation.

Why completeness matters for least privilege

The security value of a tenancy-wide inventory is not simply visibility, it is decision quality. Least privilege can only be proven when the organisation can see the full set of identity objects, their relationships, and the permissions they carry across the tenancy.

That is why partial review is weak evidence. Reviewing one profile at a time may expose an obvious overgrant, but it does not reveal estate-wide patterns such as duplicated permissions, stale accounts, inherited roles, or identities that still retain access after a workflow has changed. NHIMG’s NHI Lifecycle Management Guide is relevant here because inventory is only useful when it supports discovery, ownership, review, and offboarding together.

Identity inventory as a governance and control plane

In practice, the inventory acts as the control plane for governance questions. It helps answer who owns each identity object, what type of object it is, which policies apply to it, and whether it still has a legitimate business purpose.

That governance function becomes more important when cloud estates contain many non-human or software-driven actors. The inventory should not treat those objects as edge cases, because they are often the identities that expand fastest and are the hardest to track. NHIMG’s Top 10 NHI Issues and Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs both reinforce the same practical point: inventory, lifecycle, and governance are inseparable when identities are distributed across a tenancy.

How the concept differs from a simple directory export

A directory export or account dump shows objects, but a tenancy-wide identity inventory should show governed context. That means classification, ownership, purpose, privilege scope, and lifecycle status, not just an addressable identifier or display name.

This distinction matters because cloud tenants mix several identity patterns in the same environment. A complete inventory should therefore be able to distinguish a person from a service principal, a workload identity from a certificate-backed actor, and an actively used identity from one that is dormant or orphaned. NHIMG’s Ultimate Guide to NHIs, What are Non-Human Identities is a useful companion because it frames the identity objects that tend to be missed when teams think only in human-account terms.

Risk and Threat Considerations

A partial or stale tenancy-wide identity inventory creates visibility gaps that attackers and administrators alike can exploit. Hidden, orphaned, shared, or overprivileged identities can preserve access long after the business owner believes they are gone, and that weakens both detection and accountability.

Failure mechanism: inventory drift allows identities, policies, or credentials to remain active after ownership changes, decommissioning, or privilege changes, so the organisation cannot reliably prove who can still access what.

Impact: the tenancy accumulates excess privilege, dormant access paths, and audit blind spots, which can increase lateral movement potential, complicate incident response, and undermine least-privilege assurance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Covers lifecycle control of credentials that must be inventoried and governed.
AC-2 — Account Management Directly addresses inventory, ownership, and governance of accounts across the tenancy.
AC-6 — Least Privilege The term exists to support proving excessive access across the full identity estate.
Recommendation — Track and manage all authenticators tied to tenancy identities, including rotation, revocation, and lifecycle status. Maintain a complete account inventory and continuously review account ownership, status, and necessity. Use the inventory to validate least-privilege assignments and remove unnecessary access paths.
NIST CSF 2.0 ID.AM-01 — Physical Devices and Systems Inventoried Maps to the inventory principle that assets and identity-relevant objects must be known and tracked.
PR.AA-01 — Identities and Credentials Issued, Managed, Verified, Revoked, and Audited Covers the governed handling of identities and credentials described by a tenancy-wide inventory.
Recommendation — Maintain a complete inventory of identity-relevant objects and keep it current as the tenancy changes. Link each inventoried identity to its issuance, verification, revocation, and audit status.