Join our Newsletter — 33% off our NHI Course
Guide · NHI & AI agent lifecycle

NHI & AI Agent Lifecycle Management Guide

Non-human identities (service accounts, workload identities, API keys, tokens, certificates and OAuth grants) outnumber human identities by 50–100x in most organisations, yet they are rarely managed with the same discipline. AI agents now use those same identities to act on their own, at machine speed.

By Lalit Choda (Mr. NHI), NHI Mgmt Group · Updated 4 October 2026

Take the free maturity assessment
The seven stages

NHI & AI Agent Lifecycle Management

Updated for 2026 from my original white paper and The Ultimate Guide to Non-Human Identities, this guide sets out the seven lifecycle processes needed to manage and secure NHI risk: secretless first, continuous rather than periodic, and built for agents. For each stage: what to do for non-human identities, and what changes when the identity is an AI agent.

NHI & AI Agent Lifecycle Management: seven stages

Click or tap any stage to jump to its detail

Agentic AI

Why AI Agents Change the Lifecycle

An AI agent is a non-human identity that makes its own decisions. It inherits every NHI weakness (static secrets, over-privilege, unclear ownership) and adds new ones: it chooses which tools to call, it acts on behalf of people and other agents, and it can be steered by what it reads through prompt injection.

The seven stages still apply. What changes is the speed, the scale and the need to know, at any moment, who an agent is acting for and what it is allowed to do.

The direction is the same for both. Identities issued just in time instead of stored secrets; an owner, a purpose and an end date for every identity; least privilege set from what each identity actually uses; and policy checked at the moment of action, with no standing access. Get it right for your non-human identities and you have the foundation your agents need.

1. Provisioning & Decommissioning

For NHIs and agents: Every identity, whether a service account or an agent, is created through an approved route with an owner, a purpose and an end date.

Joiner, mover and leaver processes are usually weak for NHIs. Static NHIs are created through many different provisioning routes, and the credentials are often handed directly to the person who asked for them, which leads to humans using NHIs inappropriately. The 2026 standard is simple: no NHI without an owner, a purpose and an expiry date, and no credential that a person ever sees.

  • ProvisioningCreate NHIs through code and pipelines (infrastructure-as-code), recording owner, purpose and expiry at creation. Where a static secret cannot be avoided, feed it directly into a secrets vault, with no human intervention or visibility.
  • Workload identity firstBefore issuing any secret, ask whether the workload can use an identity its platform issues at run time instead: a cloud managed identity, workload identity federation or SPIFFE. Dynamic NHIs are secure by design because they are issued just in time and there is nothing to hand over.
  • DecommissioningHave a clear offboarding process for static secrets. When an account is no longer used, or people leave or move role, they may still know the passwords, keys or tokens, which can then be misused internally or in cloud and SaaS environments. Tie decommissioning to the application or service lifecycle as well: when a service is retired, its identities, keys and OAuth grants go with it.
  • RecertificationRegularly confirm that each static NHI is still valid and needed (see Posture Management). Anything past its expiry date or without an owner is disabled first and deleted after a grace period.

OWASP NHI Top 10 (2025): NHI1 Improper Offboarding · NHI9 NHI Reuse

What changes with AI agents

Agents are created in minutes, often by developers or business teams outside IAM. Give every agent its own identity at creation, with a named owner and a stated purpose, and never let it borrow a human's or another service's credentials. Pilots and experiments end quietly, so tie each agent's tokens and keys to the life of its task.

Non-Human Identities

  • Create NHIs via code, with owner, purpose and expiry
  • Prefer workload identity; vault any static secret
  • Decommission with the app, not only on leavers

AI Agents

  • Register each agent at creation, with an owner and purpose
  • One identity per agent — never borrowed credentials
  • Revoke agent tokens and keys when the task ends
↑ Back to the lifecycle

2. Continuous Discovery & Inventory

For NHIs and agents: You cannot govern what you cannot see: one inventory for service accounts, keys, tokens, OAuth grants and agents.

This is the most important place to start an NHI programme: it shows the size of the problem and drives remediation. It is also one of the hardest, because NHIs rarely sit in one identity system. You will deal with multiple identity providers, directory services and local accounts across hybrid cloud, SaaS and on-prem. And it is never finished: new NHIs appear every day, so discovery has to run continuously, not as a one-off project.

  • Directory vs local accountsNHIs in a directory service such as Active Directory are far easier to inventory than accounts defined locally on an operating system or database, which usually need custom feeds that take significant time and effort to build.
  • Cloud, SaaS and third partiesPull NHIs continuously from cloud IAM, identity providers and SaaS admin APIs, including OAuth app grants, SaaS-to-SaaS integrations and personal access tokens. Third-party connections are now a major NHI breach route: in August 2025, OAuth tokens stolen from the Salesloft Drift integration were used to export data from customers' Salesforce instances.
  • ScanningScan source code repositories, SharePoint, Confluence and file systems for plain-text credentials. Anything exposed there can be found by external and internal threat actors. Extend scanning to chat (Slack, Teams), tickets, container images and CI/CD logs: GitGuardian counted 28.65 million new hard-coded secrets on public GitHub in 2025 alone.
  • ContextScanners tell you a credential was found, but rarely which account it belongs to or where it is used. Building that context is the real work. Build the inventory as a map (identity, credential, workload, owner, permissions) so every finding has an owner and a fix.

OWASP NHI Top 10 (2025): NHI2 Secret Leakage · NHI3 Vulnerable Third-Party NHI

What changes with AI agents

Agents add new places to look: agent frameworks, MCP servers, AI platform consoles and the AI API keys behind them. Scan prompts, notebooks and agent configuration as well as code, and keep an agent registry recording what each agent is, who owns it and what it can reach. You cannot govern an agent you do not know exists.

Non-Human Identities

  • Discover continuously across IdP, cloud, SaaS, CI/CD
  • Include OAuth grants, integrations and access tokens
  • Scan code, chat, tickets and images; map to owners

AI Agents

  • Discover agents, MCP servers and AI API keys
  • Scan prompts and agent configs for embedded secrets
  • Keep an agent registry: owner, purpose, access
↑ Back to the lifecycle

3. Classification & Ownership

For NHIs and agents: Owner, privilege and blast radius decide what to fix first, for NHIs and agents alike.

Classify every NHI by its key attributes. With this metadata you can rank risk by level of privilege and blast radius, and fix the riskiest identities first.

  • OwnershipClear ownership drives accountability for risk reduction. Do not underestimate the effort: we have seen global programmes take several years to claim ownership. I would map each NHI to an application or service (which has owners) rather than to a person, so ownership survives team changes.
  • Level of privilegeKnow whether an NHI has admin, write or read access. This can be hard, as it often means understanding each platform's entitlement model.
  • Blast radiusAn account that reaches hundreds or thousands of assets carries far more risk than one that reaches a single asset. Include what it can reach indirectly, through trust relationships and assumed roles.
  • Account usageKnowing whether an account is used enables quick wins: removing inactive and legacy accounts. Usage data is easy to get on some platforms, hard on others, and missing on some. Usage also shows which permissions are actually exercised, the basis for right-sizing in Posture Management.
  • ExposureTag NHIs that touch production, regulated data or the internet, and credentials held by third parties. These come first.

OWASP NHI Top 10 (2025): NHI5 Overprivileged NHI · NHI3 Vulnerable Third-Party NHI

What changes with AI agents

For agents, add two attributes. Autonomy: does the agent only suggest, act with human approval, or act on its own? Delegated access: whose authority is it using, and with which permissions? Flag any agent whose tools can change data, move money or touch production.

Non-Human Identities

  • Own via applications and services, not people
  • Record privilege, blast radius and actual usage
  • Flag inactive, hard-coded and third-party NHIs

AI Agents

  • Record autonomy: suggest, approved or fully autonomous
  • Map delegated access: who the agent acts for
  • Flag agents that can change data or touch production
↑ Back to the lifecycle

4. Posture Management

For NHIs and agents: Least privilege is continuous: right-size access from what each identity actually uses.

Posture management is the continuous hygiene of an NHI programme: finding risky identities and settings and bringing them back to policy every day, not at audit time. In 2026 that means risk-scored findings, and permissions right-sized from real usage rather than guesswork.

  • Excessive permissionsNHIs are often highly privileged, and many are over-privileged. Bring them back to least privilege, using usage data to remove what each NHI has not used.
  • Inactive accountsOutdated, redundant or unused NHIs add risk with no benefit. Removing them improves security and simplifies operations.
  • Shared accountsNHIs shared across applications break segregation of duties and least privilege, and make rotation and clean-up risky because the dependencies are unknown.
  • Environment segregationUsing the same NHI in production and non-production creates lateral movement risk.
  • Cloud and pipeline settingsLong-lived cloud access keys, over-broad trust policies and pipelines that deploy with static cloud keys are posture findings in their own right.

OWASP NHI Top 10 (2025): NHI5 Overprivileged NHI · NHI6 Insecure Cloud Deployment Configurations · NHI8 Environment Isolation · NHI9 NHI Reuse

What changes with AI agents

Agent posture is mainly about tools and scopes. Review which tools each agent can call and the OAuth scopes behind them, find long-lived or over-scoped tokens held by agents and MCP servers, and keep one identity per agent per environment. A shared agent credential makes both investigation and revocation far harder.

Non-Human Identities

  • Right-size permissions from actual usage
  • Remove inactive NHIs; fix cloud and CI/CD settings
  • No shared NHIs; separate prod and non-prod

AI Agents

  • Review agent tool permissions and OAuth scopes
  • Find long-lived or over-scoped agent tokens
  • One identity per agent, per environment
↑ Back to the lifecycle

5. Secretless Credentials

For NHIs and agents: The best credential is one that is never stored: issued at run time, short-lived and scoped to the task.

Remediating NHI credential risk now starts with one question: does this workload need a stored secret at all? Remove the secret where you can, vault what you cannot, and rotate what remains. Moving plain-text credentials into a vault is still essential for legacy and third-party systems, but it is a step on the way, not the end goal.

  • Secretless firstReplace stored secrets with short-lived credentials the platform issues at run time: cloud managed identities, workload identity federation (for example a CI/CD pipeline using OIDC to reach the cloud with no stored keys) and SPIFFE/SPIRE for workloads across clusters and clouds.
  • VaultingMigrating credentials out of code into a vault is no small task: it must work at global scale and high volume, and be resilient. Support runtime, agent-based and build/deploy-time integration patterns for strategic and legacy applications, decide how credentials are onboarded (central inventory feeds or application teams), and define account namespaces to support rotation and reporting.
  • RotationRotation reduces leaver and transfer risk, removes exposure in legacy code and version history, and uncovers hidden dependencies and sharing. It is also hard: if you do not know every script and application using a credential, rotating it can break things. Automate rotation, tightly coupled to your vault; manual rotation does not scale. Regulators now expect it: PCI DSS v4.0 (mandatory since 31 March 2025) bans hard-coded passwords for system and application accounts and requires periodic change based on risk.
  • Strong authenticationReplace passwords with certificates, signed tokens or mutual TLS, keep any remaining secrets encrypted with securely managed keys, and scope every credential to one workload and one environment.

OWASP NHI Top 10 (2025): NHI2 Secret Leakage · NHI4 Insecure Authentication · NHI7 Long-Lived Secrets

What changes with AI agents

Agents should never hold long-lived secrets. Issue short-lived, task-scoped credentials from a vault or workload identity, and keep secrets out of prompts, context windows, logs and agent memory, where they can leak or be read by the model. Rotate AI API keys on a schedule and revoke immediately on any sign of exposure.

Non-Human Identities

  • Go secretless: workload identity, OIDC, SPIFFE
  • Vault what cannot be removed; never hard-code
  • Automate rotation once dependencies are mapped

AI Agents

  • Issue short-lived, task-scoped agent credentials
  • Keep secrets out of prompts, logs and agent memory
  • Rotate AI API keys; revoke on any exposure
↑ Back to the lifecycle

6. Detection & Response

For NHIs and agents: Every action is tied to an identity and its owner, so misuse is spotted and shut down in minutes.

This is one of the hardest controls to deliver well, and one of the most critical: a threat actor will always find a way to discover and misuse an NHI credential. The good news is that NHIs are predictable, with the same calls from the same places, which makes anomalies easier to see than with people. The goal is response in minutes, not just detection.

  • Behaviour baselinesThe volume of events, the number of platforms and the uneven quality of their data make reviewing every event impossible. Baseline each NHI's normal behaviour (source, timing, API calls, data volume) and alert on deviations.
  • Human use of NHIsUnderstand why people use NHIs. Uses teams consider business as usual need to be rooted out, or you will never see the wood for the trees.
  • False positivesTune detections continuously so real threats stand out.
  • Automated responseAgree playbooks in advance that revoke or rotate a credential, disable the identity and notify its owner when a leak or anomaly is confirmed. A leaked-secret alert should trigger revocation, not a ticket.

OWASP NHI Top 10 (2025): NHI10 Human Use of NHI · NHI2 Secret Leakage

What changes with AI agents

Agents generate far more activity than traditional NHIs, and their behaviour changes as they choose different tools. Log every agent action and tool call against the agent's identity and its owner, baseline normal behaviour, and alert on new tools, unusual data volumes or timing. Watch for prompt injection: an attacker steering an agent's legitimate access without ever stealing a credential.

Non-Human Identities

  • Baseline each NHI; alert on deviations
  • Detect humans using NHIs
  • Revoke or rotate automatically on leaks

AI Agents

  • Log every agent action and tool call
  • Alert on unusual agent behaviour
  • Watch for prompt injection misusing agent access
↑ Back to the lifecycle

7. Preventive Controls

For NHIs and agents: Zero standing privilege: no always-on access for NHIs or agents; access is granted just in time and checked at the moment of action.

Prevention is where the programme pays off: stop secrets being created and leaked, remove standing access, and enforce policy at the moment of access. In 2026 these are mainstream practice, not future state.

  • Stop secrets at sourceAs part of a DevSecOps shift-left approach, scan code at check-in and block any commit that contains a secret. Code platforms now do this by default for new public repositories (GitHub push protection, since March 2024); extend it to private repositories and CI/CD.
  • Zero standing privilegeMove from static to dynamic secrets through workload identity, so there is nothing long-lived for attackers to steal. Grant elevated access just in time, scoped to the task and revoked automatically when it ends.
  • Real-time policyMove from after-the-event detection and response to real-time protection: anomaly detection and policy enforcement at, for example, the identity control plane or transport layer, blocking inappropriate access as it happens. Express policy as code and evaluate it on every request.
  • Standards to watchWorkload identity is being standardised: the IETF WIMSE working group (workload identity across multi-system environments) and OAuth 2.0 Token Exchange (RFC 8693) for delegation. These are the same building blocks AI agents now rely on.

OWASP NHI Top 10 (2025): NHI7 Long-Lived Secrets · NHI2 Secret Leakage

What changes with AI agents

For agents, prevention means guardrails evaluated in real time on what each agent may do, a tested kill switch that suspends an agent and revokes its access at once, and human approval before high-risk actions such as payments, deletions or production changes.

Non-Human Identities

  • Block secrets at check-in and in pipelines
  • Zero standing privilege: just-in-time access
  • Enforce policy at the moment of access

AI Agents

  • Enforce real-time guardrails on agent actions
  • Keep a tested kill switch for every agent
  • Require human approval for high-risk actions
↑ Back to the lifecycle
Next steps

Where to Start

Start with continuous discovery and inventory: you cannot secure what you cannot see, and that now includes OAuth grants, third-party integrations and your AI agents. Then classify by privilege and blast radius, fix the worst posture issues, and remove stored secrets wherever you can, vaulting the rest. Detection and response and preventive controls build on that foundation.

Not sure where you stand? Take the free NHI & AI Governance Maturity Assessment for your level and top risks in about five minutes.

Take the lifecycle with you. The diagram and all seven stages, for NHIs and AI agents, in a two-page PDF.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

Free PDF by email

Get the guide

Enter your details and we’ll email you a download link.

Fill in all fields marked * and tick the PDF box to continue.