TL;DR: Frost, GigaOm, and Gartner are converging on the same answer: enterprises need a graph-backed identity control layer that can continuously explain effective access, NHI exposure, and posture drift across systems, according to Veza. That matters because static reviews cannot keep pace with the identity attack surface once NHIs, AI services, and cross-platform entitlements multiply.
At a glance
What this is: The article says identity security is converging on an access graph model that can unify human and non-human access, continuous posture, and governance decisions across systems.
Why it matters: It matters because IAM teams now have to govern effective access, not just directory records, across NHIs, automation, and human identities if they want to reduce attack surface and audit risk.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
👉 Read Veza's analysis of access graph architecture and identity posture
Context
Identity security has moved beyond single sign-on coverage and periodic access reviews. The practical problem is now effective access across cloud, SaaS, data platforms, CI/CD, and AI-connected services, where non-human identities and permissions change faster than traditional governance models can track. For teams trying to close that gap, the Ultimate Guide to NHIs is the core reference point for discovery, ownership, rotation, and offboarding.
Veza’s article frames that problem through analyst convergence rather than product messaging. Frost, GigaOm, and Gartner are all describing different slices of the same issue: if you cannot model who or what can do what on which system, you cannot govern identity risk at current scale. That is why access graphs, posture management, and identity intelligence are becoming the same conversation for IAM, PAM, IGA, and NHI teams.
The first wave of IAM made identity visible enough for compliance. The next wave has to make effective access explainable enough for security operations and governable enough for lifecycle control. That is typical of enterprises that have already standardised core IAM but have not yet unified machine identities, permissions, and review workflows into one decision layer.
Key questions
Q: How should security teams govern non-human identities in cloud environments?
A: Start with complete discovery, because you cannot govern what you cannot see. Then assign ownership, remove unnecessary privilege, enforce short-lived credentials where possible, and require monitoring and revocation processes for every service account, token, and API key. Cloud governance works only when identity lifecycle controls are applied to automation with the same rigor as user access.
Q: Why do access graphs matter for identity governance programs?
A: Access graphs matter because they show effective access, not just directory membership. That allows teams to see inherited privileges, cross-platform entitlements, and hidden pathways into sensitive systems. Without that relationship view, access reviews and remediation are based on incomplete evidence and tend to miss the permissions attackers actually abuse.
Q: What breaks when identity reviews are based only on human-readable directories?
A: Reviews break when they ignore effective permissions created by cloud roles, policy inheritance, and machine-to-machine trust paths. The result is a certification exercise that approves stale records while real access remains excessive or orphaned. In practice, the organisation believes access has been reviewed when the risky entitlement still exists.
Q: How do security teams know whether identity posture management is working?
A: It is working when unused permissions disappear, stale credentials are removed, and high-risk roles are reduced before they are abused. A healthy programme should show fewer orphaned identities, lower standing privilege, and faster remediation of exposed secrets across both cloud estates.
Technical breakdown
Why an access graph changes identity governance
An access graph is a relationship model that connects identities, accounts, roles, policies, resources, and usage into one queryable structure. Instead of asking only who is assigned to a group, teams can ask who can actually take a privileged action on a specific asset after policy inheritance, cloud roles, SaaS entitlements, and data-layer permissions are all resolved. That matters because effective access is usually broader and messier than directory membership suggests. In practice, the graph becomes the evidence layer for reviews, remediation, and attack-surface reduction.
Practical implication: Use the access graph as the system of record for effective access decisions, not just as a reporting layer.
What continuous identity posture management is solving
Identity security posture management is the ongoing evaluation of identity risk after access is granted. The mechanism is continuous discovery, effective-permission calculation, and prioritised remediation when entitlements drift, idle accounts persist, or privilege exceeds business need. Unlike point-in-time access reviews, posture management looks at live relationships and usage so the security team can see whether access is dormant, excessive, or toxic in context. That is why ISPM sits closer to exposure management than classic IAM hygiene.
Practical implication: Track posture as a live control objective and feed findings into tickets, workflow, and entitlement changes.
How NHI governance fits the same model
Non-human identity governance works when service principals, automation accounts, tokens, and API-connected workloads are treated as first-class identities with owners and measurable permissions. The challenge is that these identities are often created for delivery speed and then left outside human review loops. When they are modelled alongside human identities, teams can compare ownership, scope, expiry, and remediation status on the same graph. That creates a workable bridge between NHI security, IGA, and PAM without inventing separate governance systems for each identity type.
Practical implication: Classify NHIs, assign ownership, and review them through the same governance model used for human access.
NHI Mgmt Group analysis
Access graph architecture is becoming the control plane for identity security. The article is really describing a shift from identity inventory to identity decisioning. Once effective access spans cloud, SaaS, data, and automation, static directory views stop being enough for governance, detection, and remediation. Practitioners should treat graph-based visibility as the layer that binds IAM, IGA, PAM, and NHI controls together.
Non-human identity governance is no longer a side program. The named risk domain now sits alongside human access because machine identities are where scale, sprawl, and hidden privilege accumulate fastest. That is consistent with the Ultimate Guide to NHIs and OWASP NHI thinking, which both treat discovery, ownership, and privilege right-sizing as structural controls. The practitioner conclusion is straightforward: if NHIs are not separately measured, they are not governed.
Identity security posture management is the operational form of exposure management for identity. The point is not another dashboard, but continuous recalculation of who can do what and whether that access still makes sense. This matters because access drift is often invisible until an incident or audit finds it. Teams should fold identity posture into security operations, not leave it trapped inside annual governance cycles.
Access reviews only work when they are tied to effective permissions. Traditional certification against directory groups misses the permissions that emerge from inheritance, role chains, and cross-platform entitlements. That is why graph-backed review scopes matter more than larger review campaigns. The practical conclusion is to review the access that actually exists, not the access the directory says should exist.
Identity intelligence is becoming an integration problem, not a point-tool problem. The market signal across Frost, GigaOm, and Gartner is that practitioners need a shared truth across IdP, PAM, cloud, SaaS, and data systems. Separate inventories cannot answer security questions fast enough when regulators, insurers, and boards ask for evidence on demand. The implication is that identity programmes will increasingly be judged on decision speed, not just coverage.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Another finding from the same research shows that 97% of NHIs carry excessive privileges, which explains why identity graphs and continuous review matter.
- For a broader lifecycle view, Ultimate Guide to NHIs also shows that only 20% of organisations have formal offboarding and API key revocation processes.
What this signals
Identity posture will increasingly be judged as an exposure-management discipline. The next programme maturity jump is not another access review cycle. It is the ability to continuously explain effective access, ownership, and privilege drift across humans and NHIs in one operating model. That shift aligns naturally with the NIST Cybersecurity Framework 2.0, especially where governance, identify, protect, and detect need a shared evidence base.
Graph-backed governance will become the practical answer to NHI sprawl. With machine identities spreading across cloud, SaaS, data, and AI workflows, teams will need a single decision layer that can feed IAM, PAM, and IGA actions. The OWASP Non-Human Identity Top 10 is increasingly relevant here because the recurring failures are still ownership gaps, overprivilege, and poor lifecycle control.
Access intelligence is now a board-facing capability, not just an admin function. When auditors and insurers ask who can do what on critical systems, identity leaders need an answer that is current, defensible, and reducible to action. That is why access graph models and continuous posture signals will keep replacing static evidence packs as the standard for identity governance programmes.
For practitioners
- Stand up a single effective-access model Unify identities, entitlements, policies, and resources in one graph or equivalent decision layer so reviews and remediation run on live access rather than directory records.
- Treat NHI ownership as mandatory governance metadata Assign an accountable owner to every service principal, automation account, connector, and token so unowned machine access can be reviewed and removed on a defined cadence. Connect that process to the Ultimate Guide to NHIs for lifecycle patterns.
- Move identity posture into operations Track excessive privileges, dormant access, and toxic combinations continuously, then route findings into ITSM, IAM workflows, or PAM approvals so the issue becomes a change, not just a report.
- Rebuild access reviews around effective permissions Scope certification campaigns to actual effective access across cloud, SaaS, and data systems, and exclude reviews that only confirm stale group membership.
Key takeaways
- The article’s central claim is that identity security now depends on an access graph that can explain effective permissions across humans and NHIs.
- The governance gap is not visibility alone, but the inability to continuously turn identity relationships into accountable remediation.
- Practitioners should move from periodic access certification to live identity posture management tied to ownership, effective access, and change workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centres on NHI discovery, ownership, and governance gaps. |
| NIST CSF 2.0 | PR.AC-4 | The post is about managing access permissions and effective entitlement control. |
| NIST Zero Trust (SP 800-207) | 3.1 | The access-graph model supports continuous verification and least-privilege enforcement. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to excessive-permission reduction across human and NHI access. |
Apply Zero Trust principles to identity decisions by continuously validating access paths and entitlements.
Key terms
- Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
- Identity Security Posture Management: Identity security posture management is the continuous assessment of identity configuration, privilege, and exposure across an environment. It focuses on drift, overprivilege, and control gaps so teams can see where IAM, PAM, and NHI governance are failing before those gaps become incidents.
- Effective Permissions: Effective permissions are the access an identity can actually use after role inheritance, scope, and policy are applied. In Azure AI environments, they often matter more than the assigned role name because inherited rights can widen access to data, logs, and secret stores.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- How Veza maps access graph relationships across IdPs, clouds, SaaS, and data systems for effective-permission analysis
- The patent-backed architecture behind graph normalization, risk inference, and governance workflow integration
- Specific analyst references and report names that map Frost, GigaOm, and Gartner language to the platform model
- Product-level examples of Access Intelligence, Access Monitoring, and Access AI in live environments
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org