TL;DR: AAA still matters for enforcing authentication, authorization, and accounting, but StrongDM’s explanation shows it was built for user access patterns, not the scale and volatility of non-human identities, service accounts, tokens, and agentic workloads. That gap makes lifecycle control, rotation, and session oversight the decisive issues, not just centralized access policy.
At a glance
What this is: This article argues that AAA remains useful for access control, but its user-centric design leaves gaps in non-human identity governance.
Why it matters: IAM, PAM, and NHI teams need to treat AAA as a baseline control model, not a complete governance answer for service accounts, tokens, and workload access.
Context
AAA is a three-stage access model built around authentication, authorization, and accounting. In practice, it works best when the identity subject is a person with a relatively stable access pattern and a session that can be reviewed after the fact.
That assumption weakens when the subject is a non-human identity such as a service account, token, certificate, or workload. Those identities can be created, reused, and left standing at machine speed, so the governance problem shifts from controlling a login to controlling lifecycle, scope, and revocation.
The article frames AAA as useful but incomplete for NHI governance because access decisions can no longer be treated as one-time user events. That is a typical gap in modern IAM programmes, not an edge case.
Key questions
Q: What breaks when AAA is used as the only control model for non-human identities?
A: AAA can verify access and log activity, but it does not guarantee that a service account, token, or certificate is still needed. For NHIs, the missing control is lifecycle governance. Without offboarding, rotation, and ownership checks, an identity can remain valid long after the underlying workload or business need has changed.
Q: Why do distributed identity sprawl and non-human identities increase access risk?
A: Distributed identity sprawl increases risk because ownership, entitlement, and approval data become fragmented across many apps and teams. Non-human identities add more machine-created access paths that are harder to track with legacy IGA processes. When visibility is incomplete, organisations lose the ability to spot excessive access, stale grants, and unusual patterns before attackers or auditors do.
Q: What are the signs that AAA is not enough for NHI governance?
A: The clearest signs are stale service accounts, credentials with no expiry, reused tokens across multiple systems, and audit logs that show activity but not a clear owner. Those symptoms indicate the programme can record access events but cannot govern identity lifecycle with enough precision.
Q: Should organisations use Zero Trust instead of AAA for machine access?
A: No. Zero Trust and AAA solve different problems. AAA structures authentication, authorization, and accounting, while Zero Trust adds continuous verification and narrower trust boundaries. For NHIs, teams need both, plus lifecycle controls that ensure credentials do not outlive the workload they were issued for.
Technical breakdown
Why AAA works for users but strains under NHI scale
AAA assumes a fairly linear identity pattern: prove who or what is connecting, decide what it may do, then log the session. That model fits users reasonably well because human access is episodic, attributable, and slower to change. Non-human identities break that pattern because they are often created in bulk, reused across systems, and left active long after the original task has changed. The operational result is that access control becomes a lifecycle problem, not just an authentication problem. In NHI environments, the same credential can sit behind many processes, making policy centralization insufficient on its own.
Practical implication: Map AAA controls to NHI lifecycle management, not just to login enforcement.
How authorization and accounting change for machine identities
Authorization for NHIs is not simply a matter of assigning a role and recording a session. Machine identities often execute unattended, move between services, and access resources on behalf of pipelines, integrations, or workloads. That makes least privilege harder to define at provisioning time and harder to validate later through human-style review. Accounting also becomes more complicated because logs may show the action, but not the original business context or the identity owner who can still justify the access. In practice, teams need to know not just what an NHI did, but whether it still should exist, still needs the same scope, and still has a responsible owner.
Practical implication: Tie authorization and audit logging to ownership, expiry, and revocation for every NHI.
Why zero trust still needs stronger identity lifecycle controls
Zero Trust depends on continuously validating access decisions, but AAA alone does not solve the persistence of machine credentials. If a token, certificate, or service account remains valid for too long, the system can continue to trust an identity that no longer reflects current intent. That is the core mismatch the article points to: centralized policy can be technically correct while lifecycle governance is still weak. For NHI programmes, the critical question is not whether access was approved once, but whether it is still justified now. This is where privilege boundaries, rotation, and offboarding become the real control layer.
Practical implication: Use Zero Trust with expiring, reviewable machine access rather than standing NHI credentials.
Breaches seen in the wild
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AAA is necessary, but it is not an NHI governance model. AAA was designed to control access events, not to govern the full lifecycle of identities that never behave like human users. That matters because service accounts, tokens, and workloads can outlive the access decision that created them. The practitioner conclusion is simple: AAA is a control layer, not a complete governance model for NHIs.
NHI governance fails when access review is treated as sufficient. The article’s central weakness is the assumption that logging and policy enforcement can substitute for lifecycle control. Non-human identities can remain valid long after the business need changes, so accounting tells you what happened, not whether the identity should still exist. The practitioner conclusion is that review without offboarding is incomplete.
Centralized access policy does not eliminate credential persistence risk. AAA centralizes decision-making, but it does not by itself rotate secrets, expire tokens, or remove stale service accounts. That is why NHI governance has to move from static permission assignment to continuous identity hygiene. The practitioner conclusion is to treat persistent machine credentials as a governance defect, not just an access-control detail.
Least privilege is necessary, but lifecycle scope is the real differentiator for NHIs. The article reinforces that least privilege still matters, yet for NHIs the harder problem is keeping scope aligned as systems change. A machine identity can be correctly scoped at creation and still become over-permissioned through reuse, copy-forward, or neglected revocation. The practitioner conclusion is to govern scope drift as a lifecycle event, not an isolated configuration issue.
Named concept: AAA lifecycle gap. The article exposes a gap between access enforcement and identity lifecycle governance. AAA can authenticate, authorize, and record activity, but it does not ensure the identity is still needed, still owned, or still safe to retain. The practitioner conclusion is to close that gap with offboarding, rotation, and ownership controls for every non-human identity.
What this signals
AAA lifecycle gap: The real issue for NHI programmes is not whether access can be authenticated and logged, but whether the identity can still be trusted after the original need changes. That shifts the control objective toward expiry, ownership, and revocation rather than static policy alone.
AAA remains a useful baseline for access control, but machine identities expose the limits of models built around human sessions. Teams that still measure success by login enforcement alone will miss the larger governance problem of credential persistence and scope drift.
For practitioners
- Map AAA to NHI lifecycle controls Review where authentication, authorization, and accounting exist today, then identify where service accounts, API keys, and tokens bypass revocation and ownership checks.
- Inventory every non-human identity Create a current inventory of service accounts, secrets, certificates, and workload identities, including owner, purpose, scope, and expiry status.
- Enforce expiration and rotation for machine credentials Set explicit lifetime limits for tokens and certificates, and require rotation when the original business purpose or system ownership changes.
- Review authorization scope after every workload change Revalidate privileges when applications are moved, cloned, or integrated so that copied permissions do not become permanent overreach.
- Tie accounting data to offboarding decisions Use session logs to identify dormant identities, then remove access when the identity is no longer associated with an active service owner.
Key takeaways
- AAA remains relevant, but it does not fully govern non-human identities that can persist, spread, and be reused across systems.
- The main gap is lifecycle control, not just authentication or logging, because machine credentials can stay active after the original use case ends.
- Practitioners should pair AAA with inventory, rotation, offboarding, and ownership checks to keep NHI access aligned to current business need.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article centers on stale machine identities that remain active after their use case changes. |
| NHI-05 — Overprivileged NHI | The article warns that centralized policy does not prevent machine identities from retaining excess scope. | |
| NHI-07 — Long-Lived Secrets | The article's core gap is persistent credentials that outlive the access decision that created them. | |
| Recommendation — Inventory NHIs so you can revoke identities that no longer have an active owner or business purpose. Revalidate NHI scope whenever the workload or integration changes to prevent permission creep. Set explicit expiry and rotation rules for tokens, certificates, and service account credentials. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | AAA maps directly to access authorization and entitlement control in identity programmes. |
| Recommendation — Review entitlements regularly so machine identities retain only the permissions their current job requires. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article highlights why machine identity accounts need lifecycle governance and account oversight. |
| Recommendation — Manage service accounts like first-class accounts by tracking owners, purpose, and removal dates. | ||
Key terms
- Authentication, Authorization, and Auditing: Authentication, authorization, and auditing are three related access-control functions. Authentication confirms identity, authorization decides what that identity can do, and auditing records the activity for review and compliance. Together they provide a fuller control model than login-only integration.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Credential Lifecycle: Credential lifecycle is the process of issuing, rotating, expiring, and revoking secrets, certificates, and tokens across their usable life. For non-human identities, lifecycle discipline is the core control that separates temporary access from persistent exposure.
- Accounting Trail: An accounting trail is the logged record of who or what accessed a system, when it happened, and what activity occurred. It supports audit and investigation, but on its own it does not prove the identity should still exist or still have the permissions it used.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 1, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org