Split-path identity describes a situation where a human or workflow is governed through one identity channel while an AI agent or machine process uses another. The result is inconsistent accountability, because one actor is visible to governance and the other is not.
What Split-Path Identity Means in Practice
Split-path identity is not a single control failure, but a governance pattern where the person or workflow that initiates an action is tracked through one identity path while the software or agent that actually executes it is tracked through another.
The security significance is that accountability can fragment: approvals, audit logs, and access decisions may point to a human account while the real runtime authority sits with a separate automation, service, or agent identity. That makes review, attribution, and revocation harder even when each individual identity appears valid.
Where Split-Path Identity Shows Up
This pattern commonly appears when teams bolt automation onto human workflows without aligning the identity model end to end. A request may begin with a user login, pass through a workflow engine, and end with a machine credential or agent token that performs the actual action.
In mature environments, the split is often intentional, for example to separate approval from execution or to let an workload identity specification represent a non-human runtime actor. The problem arises when that second path is invisible to policy, not recorded with enough context, or not tied back to the originating request.
NHIMG’s Ultimate Guide to NHIs is useful here because split-path identity often depends on the interaction between human identity and service, API, token, or workload identity.
Why Split-Path Identity Creates Security Friction
The core issue is mismatch between governance and execution. A reviewer may believe they approved one actor, but the actual privilege used at runtime belongs to another, which weakens least-privilege enforcement and complicates audit trails.
That mismatch also makes lifecycle controls brittle. If the machine or agent identity is not discovered, inventoried, or offboarded with the same rigor as the human side, old paths can remain active after ownership changes, workflow changes, or staff departure.
NHIMG’s NHI Lifecycle Management Guide is directly relevant because split-path setups usually fail when provisioning, rotation, offboarding, and visibility are treated as separate problems.
How to Recognize the Pattern
Look for places where one identity is used for intent and another is used for execution, especially in delegated workflows, orchestration platforms, copilots, bots, and API-driven automation. The red flag is not the presence of two identities by itself, but the absence of a clear binding between them.
A healthy implementation preserves traceability from user action to machine action, so investigators can answer who approved, what executed, which privileges were used, and where the authority came from. NHIMG’s Identity Security Programme Guide helps frame that ownership problem across human, non-human, and AI-agent identities.
Risk and Threat Considerations
Split-path identity increases the chance that attackers, insiders, or misconfigurations can abuse a hidden execution path while governance continues to show a clean human-facing trail. It is especially risky when the machine or agent side has broader permissions, longer-lived credentials, or weaker monitoring than the initiating user path.
Failure mechanism: The control plane authenticates or authorizes one identity, but the runtime action is carried out by a different identity that inherits trust without inheriting the same visibility, review, or revocation controls.
Impact: Audit gaps, privilege creep, difficult incident reconstruction, and delayed revocation can all result, and the hidden path can become a persistence route after compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-9 — Service Identification and Authentication | Split-path identity often hinges on service or workload execution authority. |
| IA-5 — Authenticator Management | Split-path identity depends on the lifecycle of tokens, keys, and other credentials. | |
| AU-2 — Audit Events | The pattern creates accountability gaps that must be observable in logs. | |
| Recommendation — Bind service and workload actions to distinct authenticated identities. Rotate and revoke execution credentials on the same lifecycle as the workflow. Log the initiating identity, the execution identity, and the handoff event. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | The term is fundamentally about mismatched identity governance and access control. |
| GV.OC-01 — Organizational Context | Split-path identity affects accountability and ownership across roles and systems. | |
| Recommendation — Map each workflow step to the identity that is actually authorized to act. Assign clear ownership for the human-to-machine identity handoff. | ||
Practitioner Guidance
Governance implication: Treat the binding between the initiating identity and the execution identity as a first-class control object. If that relationship cannot be reviewed, logged, and revoked, the organisation does not really control the workflow, it only controls the front door.
Practitioner takeaway: The question is not just whether each identity is valid, but whether the handoff between them is observable and accountable end to end.
Related resources from NHI Mgmt Group
- How should security teams split identity governance from implementation work?
- What breaks when identity governance is split across vaults, IGA, and PAM tools?
- Who is accountable when identity governance and enforcement are split across tools?
- When is a split residency model not acceptable for identity governance?