TL;DR: Frost, GigaOm, and Gartner are converging on the same answer: enterprises need a graph-backed identity control layer that can continuously explain effective access, NHI exposure, and posture drift across systems, according to Veza. That matters because static reviews cannot keep pace with the identity attack surface once NHIs, AI services, and cross-platform entitlements multiply.
At a glance
What this is: This is an analysis of why access graph architecture is emerging as the control layer for identity security, with analysts converging on continuous visibility, effective access, and posture management.
Why it matters: IAM, IGA, PAM, and NHI teams need a decision layer that reflects effective permissions in real time, not directory snapshots, if they want to govern cloud, SaaS, and machine access at current scale.
Context
Identity control models break when the programme can no longer answer who or what can take an action on which system, using current entitlements rather than stale records. That gap becomes more visible as NHI sprawl, AI services, and cross-platform permissions increase the number of access paths that matter.
The article argues that an access graph is becoming the practical control layer above IdP, IGA, and PAM because it can normalize identities, permissions, and effective access across systems. In that model, governance shifts from periodic review to continuously explainable access and posture management.
Key questions
Q: How should IAM teams improve access request governance without adding friction?
A: Start by simplifying the request model, not by adding more approval layers. Each request template should map to a specific entitlement set, an explicit approver path, and a clear business purpose. That reduces ambiguity, shortens manual handling, and makes the resulting approval decisions easier to audit and defend.
Q: Why do non-human identities need separate governance attention in platform roadmaps?
A: Because service accounts, tokens, and automated access do not behave like human logins. Their risk sits in lifecycle, scope, and revocation, so a roadmap that only improves user experience can leave the hardest governance problems untouched. Separate attention prevents NHI controls from being assumed rather than verified.
Q: What are the signs that identity posture management is not working?
A: Common warning signs include unknown identities, inconsistent ownership, privileges that survive role changes, and federation paths that nobody can explain. If teams only notice these issues during audits or incidents, the posture model is already behind the environment.
Q: What should security teams do when access reviews do not match real-world privilege?
A: They should treat the mismatch as a model problem, not a reviewer problem. If certification workflows are based on directory groups while privilege is actually determined by inheritance, federation, and policy chains, the governance layer needs effective-access intelligence before reviews can be trusted.
Technical breakdown
Why effective access is harder than directory access
Directory data tells you what an account is supposed to have, not what it can actually do once roles, policies, groups, inherited entitlements, and cross-platform mappings are applied. Access graphs compute effective permissions by traversing those relationships across clouds, SaaS, and data systems, which is why they are more useful for governance than static inventory. They also expose transitive access paths, where a seemingly narrow role can still reach sensitive resources through chained privileges. That matters because identity risk is usually hidden in the relationships between objects, not in the objects themselves.
Practical implication: model and review effective permissions, not just assigned roles or directory group membership.
How access graphs change NHI governance
Non-human identities become governable only when they are first-class objects with owners, permissions, and lifecycle state. An access graph makes that possible by connecting service accounts, automation identities, app registrations, and machine credentials to the resources they can reach and the policies that grant that reach. Without that graph, NHIs remain scattered across clouds, SaaS tools, CI/CD pipelines, and data platforms with no common ownership or risk model. The technical shift is from treating NHIs as isolated accounts to treating them as nodes in a live entitlement network.
Practical implication: assign ownership and review scope from the graph, not from the original provisioning source.
Why continuous posture matters after access is granted
Identity security posture management starts where provisioning ends. Once access exists, the relevant question is whether it has drifted into excessive, orphaned, or unused states as systems change. Access graphs support that by recomputing risk as identities, policies, and workloads change, then surfacing excess privilege, dormant access, and toxic combinations for remediation. This is why posture management cannot be a yearly certification exercise. The control point moves to the live entitlement layer, where risk can be measured and reduced before it becomes an incident.
Practical implication: use continuous entitlement analysis to trigger remediation as access drifts, not after audit season.
Threat narrative
Attacker objective: The objective is to exploit hidden or overextended identity paths to reach sensitive systems and data through privileges the organisation did not realise were still active.
- Entry begins when identities are created across cloud, SaaS, CI/CD, and AI services faster than governance can track ownership and effective permissions.
- Escalation occurs when inherited entitlements, stale access, and cross-platform role chains produce more privilege than the directory record suggests.
- Impact follows when teams cannot answer who can act on which data or how quickly access can be changed, leaving identity-driven incidents harder to contain.
Breaches seen in the wild
- BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
- reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Access graph architecture is becoming the control plane for identity governance. The old model assumed identity records, access reviews, and periodic certifications were enough to describe risk. That breaks once effective permissions are distributed across clouds, SaaS, data platforms, and machine identities. Practitioners now need a live entitlement model that can explain access relationships on demand, not a static ledger of approvals.
NHI governance fails when machine identities are treated as side effects of human IAM. Non-human identities are not a separate inventory problem. They are part of the same access graph as users, roles, and policies, which means ownership, effective permissions, and lifecycle state must be governed in one model. Separate tooling may collect facts, but only a unified graph can make those facts operational for remediation and review.
Identity security posture is the missing bridge between IAM and exposure management. Boards and regulators now expect identity risk to be measured like any other control domain, which means posture cannot stop at successful authentication or completed review campaigns. The discipline is shifting toward continuous assessment of excess privilege, dormant access, and transitive paths to sensitive assets. That makes identity exposure a standing security problem, not an annual compliance event.
Graph-backed governance is where Next Gen IGA is heading. The market is moving away from directory-centric certification toward decisions grounded in effective access, usage context, and relationship analysis. That does not replace IdP, PAM, or IGA systems of record. It changes the decision layer above them, and practitioners should expect future governance programmes to be judged on their ability to explain and reduce real access paths.
Effective privilege is the named concept that should anchor this category. Access is only governable when the organisation can calculate what an identity can actually do after inheritance, federation, and policy evaluation. The implication is that privilege reviews built on assigned roles alone will remain incomplete, while access graphs make effective privilege visible enough to govern.
From our research library:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Effective privilege: access governance is only reliable when teams can explain what an identity can actually do after inheritance, federation, and policy evaluation. That shifts the control question from who approved access to what reach the identity really has across cloud, SaaS, and data systems.
Identity programmes that still depend on periodic reviews will keep missing machine access drift because access changes faster than certification cycles. The practical shift is toward continuous entitlement analysis, where excessive privilege, dormant access, and transitive paths become standing exposure signals rather than audit findings.
NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs. That scale is why access graphs are moving from architecture preference to governance necessity.
For practitioners
- Stand up an access graph as the decision layer Normalize identities, groups, roles, policies, and resources from IdP, cloud, SaaS, and data systems so reviewers can see effective access rather than isolated records.
- Treat non-human identities as governed assets Assign owners, lifecycle state, and review scope to service accounts, app registrations, automation identities, and CI/CD tokens inside the same entitlement model used for people.
- Shift reviews to effective permissions Scope access reviews around actual reach to sensitive systems, inherited entitlements, and transitive paths instead of directory groups or simple approval history.
- Instrument identity posture continuously Track excessive privileges, dormant access, and risky privilege combinations as standing exposure signals, then route them into workflow systems for remediation.
- Keep IdP and IGA, but move decisions up the stack Use existing identity systems as sources of record while placing the access graph above them for analysis, certification, and lifecycle decisions.
Key takeaways
- The article’s core argument is that access graphs are becoming the control layer that lets teams govern effective access across users, workloads, and machine identities.
- The governance problem is not visibility alone. It is the gap between assigned access and real privilege once policies, inheritance, and cross-platform relationships are evaluated.
- Practitioners should move identity decisions onto a live entitlement model so reviews, posture management, and remediation reflect actual access paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on hidden and excessive machine access across a growing NHI estate. |
| NHI-01 — Improper Offboarding | The article repeatedly points to stale identities and access that outlives its original purpose. | |
| Recommendation — Map machine accounts to effective privileges and reduce any access that exceeds current task scope. Review NHI offboarding paths and revoke identities that no longer have a business owner or active use. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The access graph is about governing who can do what across systems and data. |
| Recommendation — Use PR.AA-05 to align entitlement review with effective access instead of directory snapshots. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article focuses on account ownership, review, and lifecycle control across human and machine identities. |
| Recommendation — Apply account management controls to maintain ownership, review cadence, and revocation for all identities. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The risk narrative is about identity paths that enable deeper access and broader reach. |
| Recommendation — Map excessive access paths to credential access and lateral movement opportunities in your detection plan. | ||
Key terms
- Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
- Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
- Identity Security Posture Management: Identity security posture management is the continuous assessment of identity configuration, privilege, and exposure across an environment. It focuses on drift, overprivilege, and control gaps so teams can see where IAM, PAM, and NHI governance are failing before those gaps become incidents.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org