By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SailPointPublished August 27, 2026

TL;DR: Access certification for non-human identities is still handled ad hoc, leaving service accounts, machine tokens, and API keys active for years without formal oversight, according to SailPoint. The governance gap is not visibility alone, but the assumption that human review processes can be applied to machine-scale access without redesign.


At a glance

What this is: This is a blog on extending access certification to non-human identities, with the key finding that most NHI governance still breaks down into manual, breach-driven review.

Why it matters: It matters because IAM, IGA, and PAM teams need a review model for service accounts, tokens, and API keys that matches machine scale instead of human-only certification cadences.

By the numbers:

👉 Read SailPoint's blog on access reviews for non-human identities


Context

Non-human identity access reviews are the machine-side equivalent of access certification, but they are usually far less mature than human IAM processes. Service accounts, API keys, machine tokens, and certificates often sit outside the normal joiner-mover-leaver and recertification rhythm, which leaves ownership, expiry, and privilege drift unresolved.

The article argues that the problem is not review in principle, but review at the wrong scale and with the wrong workflow. When a token has no clear owner or expiry, teams need scoped campaigns, automated triage, and auditable decision trails that fit NHI governance rather than forcing a human-access model onto machine identities.

That starting position is typical of most enterprises: human access governance is established, while NHI governance remains reactive and fragmented.


Key questions

Q: How should security teams run access reviews for non-human identities?

A: Security teams should scope reviews by risk pattern, assign every identity to an accountable owner, and require a documented decision for each item in scope. The workflow should allow direct remediation for obvious cases and owner follow-up for the rest. The goal is not just certification but a clean audit trail and a clear end state for each credential.

Q: What breaks when service accounts are excluded from access reviews?

A: You lose confidence that machine access still matches business need, and you also lose the evidence needed to prove control effectiveness. Over time, unused accounts, stale permissions, and shared credentials accumulate, which increases the chance that an attacker can reuse an identity to move through the environment.

Q: How do you know if NHI access certification is actually working?

A: A working programme reduces orphaned, idle, exposed, and over-permissioned credentials while producing clear decision logs for every case. If campaigns only create activity but do not change credential state, ownership clarity, or revocation rates, the control is not governing risk.

Q: Who should be accountable for non-human identity governance?

A: Accountability should sit with the team that owns the workload or automation, with IAM and PAM providing the control model and enforcement. If ownership is split across DevOps, security, and IT without a single decision maker, non-human identities tend to accumulate stale access, untracked secrets, and unclear exception handling.


Technical breakdown

Why access certification breaks down for non-human identities

Access certification depends on a stable subject, a known reviewer, and an entitlement set that can be judged in a human workflow. NHIs disrupt all three assumptions. A service account may not map to a manager, an API key may have no direct owner, and a token may exist across cloud, SaaS, and CI/CD systems at once. That makes standard access review campaigns noisy unless they are filtered by ownership, activity, age, or privilege level. The technical problem is not the absence of review features, but the mismatch between identity inventory and review semantics.

Practical implication: define NHI review scopes by owner, activity, and privilege before running campaigns.

How campaign filters turn NHI sprawl into reviewable subsets

The useful technical pattern here is not blanket certification, but segmentation. Orphaned, idle, non-expiring, exposed, former-employee, and over-permissioned identities are operationally distinct states, and each one points to a different governance failure. Filters let IAM teams isolate a subset that can be actioned quickly, instead of asking owners to assess thousands of irrelevant credentials. This is closer to workload governance than to classic access review, because the campaign is really a control over credential lifecycle state.

Practical implication: build review templates around NHI lifecycle states, not around application lists.

Why auditability matters more when the reviewer is not the operator

NHI certification only works if every decision is traceable, because the person reviewing often is not the person who created or uses the credential. That means the workflow must record reassignment, disablement, owner confirmation, and final disposition with timestamps and context. In machine identity governance, the audit trail is not a report after the fact. It is the evidence that the organisation had control over the identity lifecycle before an incident or audit forced the issue.

Practical implication: require timestamped evidence for each NHI decision, not just final campaign completion.


NHI Mgmt Group analysis

Human certification models do not scale to machine identity governance. Access reviews were built around a stable human subject, but NHIs are often ownerless, hidden across systems, and created outside formal provisioning paths. That means the governance unit is no longer the employee record, but the credential state and its lifecycle context. Practitioners should stop treating NHI review as a variant of user recertification and start treating it as its own control domain.

Campaign scoping is the real control, not campaign volume. A review process that asks owners to validate every token creates fatigue and low-quality decisions. Narrow scoping by exposure, age, privilege, and activity makes the review meaningful because it aligns the question with a real risk signal. That approach is more defensible than broad certification runs that generate activity without reducing attack surface.

Non-expiring and orphaned credentials expose a lifecycle failure, not just a visibility gap. The article’s templates point to identities that persist without a clear offboarding trigger or accountable owner. That failure mode is central to NHI governance because access can outlive the project, the developer, or the business need. The practical conclusion is that lifecycle ownership must be part of every certification campaign.

Access review fatigue: machine identities create so many low-context items that teams can no longer rely on human-only recertification cadence. This is a governance design problem, not an analyst workflow problem. The implication is that identity programmes need NHI-specific campaign logic that separates high-risk credentials from routine noise.

Audit evidence is the control boundary for NHI reviews. If a campaign cannot prove who reviewed what, when, and why, the organisation has not created governance, only administrative activity. The article correctly leans on exportable logs because machine identities rarely have a clean organisational backstory. Practitioners should treat auditability as a primary success criterion for any NHI certification process.

From our research:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
  • Campaign-based review is only part of the answer. Guide to the Secret Sprawl Challenge shows why exposed credentials also need ownership, rotation, and containment workflows.

What this signals

Access review programmes will keep missing machine risk until they move from employee-centric recertification to credential-centric governance. The practical shift is to treat ownership, expiry, exposure, and privilege as the review dimensions for NHIs, not manager approval. The governance model has to fit the object being reviewed, which is why NHI lifecycle management belongs beside IAM and IGA, not underneath them.

Only 5.7% of organisations have full visibility into their service accounts, which means most certification programmes are operating with incomplete inventory. Without that baseline, review campaigns can only partially reduce risk because they cannot reliably tell owners what exists. Practitioners should expect NHI review maturity to track with inventory quality, not with campaign count alone.

Identity blast radius: once NHI review is tied to owner clarity and privilege scope, the programme starts measuring how far a credential can travel before detection or revocation. That should push teams toward tighter lifecycle controls and better links between access review, secrets management, and privileged access oversight.


For practitioners

  • Scope campaigns by lifecycle state Start with orphaned, idle, exposed, former-employee, non-expiring, and over-permissioned credentials. Use these states to create smaller campaigns that owners can actually complete without review fatigue.
  • Automate first-pass triage Disable idle credentials, reassign obvious ownership, and route only unresolved cases to human reviewers. This keeps campaign effort focused on identities that need judgment rather than cleanup.
  • Require evidence-rich disposition records Capture who reviewed the credential, what decision they made, when it was made, and whether the action was automated or manual. Exportable logs should be treated as the output of governance, not a bonus report.
  • Tie review templates to NHI ownership Make each campaign template resolve one governance question, such as whether the credential still needs to exist or whether it is tied to a current owner or departed employee.

Key takeaways

  • Non-human access reviews fail when organisations reuse human certification models without changing the review object, the reviewer, or the lifecycle signals.
  • The evidence points to a widespread governance gap, with only 20% of organisations formally offboarding and revoking API keys and 97% of NHIs carrying excessive privileges.
  • Practitioners should make campaigns lifecycle-aware, owner-specific, and audit-ready so NHI reviews change credential state instead of producing paperwork.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03NHI-03 covers lifecycle and review gaps for non-human credentials.
NIST CSF 2.0PR.AA-01Identity governance aligns with knowing and managing active identities.
NIST SP 800-53 Rev 5AC-2AC-2 governs account management, including review and removal of inactive access.
NIST Zero Trust (SP 800-207)Zero Trust depends on continuously verifying and limiting access for non-human identities.

Use Zero Trust principles to reduce standing NHI access and force review before privilege persists.


Key terms

  • Identity-Based Access Review: Identity-based access review is the practice of checking who has access, what level of access they have, and whether that access still matches business need. In SaaS environments, it is the most reliable way to uncover dormant accounts and excessive permissions.
  • Orphaned Credential: A secret, token, or service account password that remains active and valid after the NHI it was issued to has been decommissioned, or after the person or system responsible for it has left the organisation.
  • Campaign Scoping: Campaign scoping is the process of defining which identities, accounts, attributes, or ownership categories belong in a review. Good scoping limits noise, focuses reviewers on meaningful access, and reduces the chance that important entitlements are missed or routine items overwhelm the process.
  • Audit Trail: An audit trail is a record of who accessed a system, what they did, and when they did it. For PHI environments, it provides the evidence needed to investigate incidents, support breach determinations, and demonstrate that access was attributable to a specific identity or workflow.

What's in the full article

SailPoint's full blog covers the operational detail this post intentionally leaves for the source:

  • Prebuilt campaign templates for orphaned, idle, high-risk, non-expiring, former-employee, exposed, and over-permissioned NHIs
  • The workflow for triaging credentials before owners are involved, including disablement and reassignment paths
  • How campaign admins export decision logs and track pending, in-progress, and resolved items
  • The provider-console handoff steps for cases that cannot be automated directly

👉 The full SailPoint post shows how campaign scoping, triage, and audit logs work in practice.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org