Join our Newsletter — 33% off our NHI Course

Human-machine identity surface

The full set of human and non-human actors that can affect a business outcome inside a workflow. It includes people, delegated automations, assistants and autonomous systems, all of which may carry different permissions, owners and revocation rules.

What the human-machine identity surface includes

The human-machine identity surface is broader than a directory of users. It is the complete set of actors, people, delegated automations, assistants, and autonomous systems that can influence a business workflow and therefore deserve explicit ownership, permissioning, and revocation rules.

That framing matters because the same workflow may be touched by a person approving an action, a service account executing it, and an assistant orchestrating it. If one of those actors is unmanaged, the workflow can still succeed while the organisation loses visibility into who actually had authority at each step.

Why it is a security boundary

The practical value of the surface is that it turns a vague “who can do this?” question into a bounded security and governance problem. It forces teams to look at every actor that can affect outcome, not just the most obvious human operator.

For identity programs, that means the boundary is not the login screen alone. It also includes delegated access, machine credentials, service accounts, and agent-driven actions that may inherit trust from a human context but operate with different lifecycle rules and different blast radius.

NHIMG’s Human vs Non-Human Identity is a useful companion when you need to separate human ownership from machine execution in the same workflow.

How the surface expands in real workflows

In practice, the surface grows whenever work is delegated, automated, or chained across systems. A person may start a task, an integration user may move the data, and an assistant or agent may make intermediate decisions before a final human approval.

That complexity is why inventory alone is not enough. The same business process can contain multiple identity types with different authentication methods, entitlements, and revocation paths, which makes ownership and accountability harder to preserve unless the whole workflow is modelled as one surface.

NHIMG’s Identity Convergence Guide helps explain why a unified view is useful when human and machine access meet in the same control plane.

Governance and control implications

Once the surface is defined, governance becomes a matter of assigning the right control to the right actor type. People, automations, and autonomous systems should not share the same assumptions about ownership, approval, rotation, and offboarding.

The main control question is whether each actor has a clear business owner, a justified permission set, and a clean revocation path when the workflow changes. That is especially important where one human identity can indirectly authorise several non-human actions through delegation or embedded credentials.

NHIMG’s NHI Ownership and Accountability Guide is relevant here because ownership is what keeps a broad identity surface governable rather than merely observable.

Risk and Threat Considerations

A wide human-machine identity surface increases the chance that one weak actor, such as an overprivileged automation or a poorly governed assistant, can be used to reach high-value workflow actions. The risk is not only compromise, but also misattribution, where a business outcome is traceable to the wrong identity or no clear owner at all.

Failure mechanism: excessive permissions, shared credentials, stale automations, and unclear delegation chains can create hidden paths for abuse, lateral movement, or unauthorized workflow execution.

Impact: attackers or insiders can alter business outcomes, escalate privilege through trusted automations, or delay revocation because no one can prove which actor should be disabled first.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management This term covers all actors that can affect workflow outcomes and need governed accounts.
IA-5 — Authenticator Management The surface includes credentials and authenticators used by humans, automations, and assistants.
AC-6 — Least Privilege The surface should only include the permissions each actor needs to influence the workflow outcome.
Recommendation — Classify every human and non-human actor on the surface and remove accounts when they are no longer needed. Manage authenticators by actor type and rotate or revoke them when workflow authority changes. Restrict each actor on the surface to the minimum permissions required for its workflow role.
ISO/IEC 27001:2022 A.5.16 — Identity management Identity management covers the actor set that participates in the workflow surface.
A.5.18 — Access rights The surface is governed by who can do what within the workflow.
Recommendation — Maintain an inventory of all actor identities that can influence each business workflow. Assign, review, and revoke access rights according to the actor's role in the workflow.
OWASP Non-Human Identity Top 10 NHI-05 — Overprivileged NHI Non-human actors on the surface can become excessive-power workflow participants.
NHI-01 — Improper Offboarding Actors on the surface must be removed cleanly when their workflow role ends.
Recommendation — Reduce non-human privileges to the minimum needed for each workflow action. Retire workflow identities promptly when the actor, integration, or assistant is no longer required.
OWASP Agentic AI Top 10 ASI03 — Identity & Privilege Abuse Autonomous assistants on the surface can inherit or abuse delegated authority.
Recommendation — Constrain agent authority so delegated actions cannot exceed the workflow permissions they were given.

Practitioner Guidance

What to watch for: Treat the surface as a living map of actors, not a one-time inventory. If a workflow gains a new assistant, integration, or autonomous step, the identity surface has changed and the ownership and revocation model should change with it.

Governance implication: Define the business owner for every actor on the surface, including non-human ones, so that approvals, exceptions, and offboarding can be handled without guessing which identity is actually accountable.