By NHI Mgmt Group Editorial TeamBased on SailPoint: “Bringing access reviews to your non-human identities” (August 27, 2026)

TL;DR: Access certification for non-human identities is still handled ad hoc, leaving service accounts, machine tokens, and API keys active for years without formal oversight, according to SailPoint. The governance gap is not visibility alone, but the assumption that human review processes can be applied to machine-scale access without redesign.


At a glance

What this is: This is a SailPoint analysis of why access certification for non-human identities breaks down when teams apply human review processes to service accounts, machine tokens, and API keys.

Why it matters: It matters because IAM and IGA teams need a governance model for machine access that can handle ownership, scope, inactivity, and offboarding without relying on human-centric review habits.


Context

Access reviews are a governance control, not just an audit exercise. They depend on a stable owner, a reviewable permission set, and a cadence that matches how long access remains active. Those assumptions hold reasonably well for human identities, but they break down when the subject is a service account, machine token, or API key.

For non-human identities, the problem is not only visibility. It is also lifecycle mismatch: credentials can persist with no obvious owner, no expiration, and no meaningful business context for a manager to certify. That is why machine access often stays live until an incident or compliance review forces the issue.


Key questions

Q: What breaks when access reviews do not include machine and AI identities?

A: Review cycles miss the identities that often move the most data and inherit the most privilege. As a result, excessive access can persist in service accounts, pipelines, and AI-connected workflows even when human user access looks clean. The control fails because the review scope is too narrow for the actual access graph.

Q: Why do certificates create governance issues for non-human identities?

A: Because certificates are often attached to devices, servers, APIs, and service accounts that do not behave like people. Those identities can outlive their intended use, accumulate privilege, and remain difficult to track unless lifecycle controls and ownership are explicit. The governance problem is not the certificate itself, but the unmanaged identity it represents.

Q: How should IAM teams prioritise which non-human identities to review first?

A: Start with credentials that are orphaned, idle, exposed, non-expiring, former-employee-linked, high-risk, or over-permissioned. That approach reduces noise and lets teams fix the most dangerous machine access before sending unresolved items to application owners.

Q: How do organisations make NHI access reviews auditable?

A: They need a campaign record that shows who reviewed each credential, what decision was made, what action followed, and when the item closed. That evidence turns certification into a defensible governance control instead of an informal checklist.


Technical breakdown

Why access certification breaks for machine identities

Access certification was built for human governance workflows. Reviewers can interpret a name, a team, a role, and a business justification. Non-human identities do not naturally map to that structure. A token may exist because a developer created it months ago, a service account may power an application no one actively remembers, and an API key may be embedded in tooling with no visible business owner. The result is not simply missing documentation. It is a control that assumes human readability where machine access is often context-light and distributed across cloud, SaaS, and CI/CD systems.

Practical implication: rebuild certification scopes around machine ownership, expiry, and use state instead of human org charts.

How scoped NHI campaigns reduce review noise

The article’s campaign model reflects a practical truth about NHI governance: not every credential should enter review at once. Targeted filters for orphaned, idle, non-expiring, exposed, former-employee-linked, high-risk, and over-permissioned credentials let teams separate obvious remediation from deeper investigation. That matters because machine estates are usually too large and too messy for spreadsheet-style mass review. Narrowing the scope improves actionability, but only if the organisation has reliable signals for activity, privilege, and ownership. Without those signals, certification becomes a queue rather than a control.

Practical implication: define review cohorts by machine risk signals so teams can dispose of obvious candidates before escalating exceptions.

What auditability changes in NHI governance

A certification process is only as useful as the evidence it leaves behind. For NHIs, the value of a review campaign is not just that an administrator looked at a list. It is that the organisation can prove who reviewed which credential, what action was taken, and when the decision closed. That creates a defensible audit trail across cloud, SaaS, and CI/CD environments where non-human access is otherwise fragmented. It also turns access review from a reactive search exercise into a repeatable governance process that can survive scale and turnover.

Practical implication: require exportable evidence for every NHI review decision and keep it tied to the credential lifecycle.


  • Cisco Active Directory credentials leak 2025: Kraken leaked Cisco Active Directory hashes, including service and krbtgt accounts; Cisco says they came from its 2022 breach, not a new one.
  • Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Human-style certification is the wrong control model for machine identities: access review programmes were designed around people, not service accounts, API keys, and workload tokens. The article exposes a governance gap that appears when reviewers are asked to certify access that has no clear human owner, no HR record, and no natural business narrative. Practitioners should treat that as a control-design problem, not a process exception.

Formal review must move closer to issuance and ownership for NHIs: if a credential can sit active for years, annual or quarterly certification arrives too late to change exposure. The right unit of governance is the credential lifecycle, not the meeting cadence. That means the organisation has to know who can attest ownership, who can retire access, and which signals make a credential eligible for review in the first place.

Orphaned and non-expiring credentials are a distinct governance class: these are not merely risky credentials, they are credentials that sit outside normal accountability loops. When a token has no owner or no expiry, the review process becomes a discovery problem before it becomes a certification problem. That is why NHI governance has to separate identity inventory from attestation and treat missing accountability as the control failure.

Access certification for NHIs should be judged by closure quality, not review volume: a campaign that produces lots of approvals without revocations or reassignments has not reduced risk. The better measure is whether the programme can convert noisy machine access into bounded, reviewable, and revocable assets. That is the standard identity leaders should apply before calling NHI review mature.

From our research library:

What this signals

Access review has to become a credential-lifecycle control, not a calendar event: the article shows why machine identities cannot be governed by the same review rhythm used for people. When a token can outlive the developer who created it, the control point shifts to ownership, expiry, and closure evidence.

Non-expiring access is the clearest sign that review and offboarding are disconnected: if a credential has no expiry, the organisation is already relying on informal memory rather than governance. That is where NHI programmes should focus first, because the lack of a termination point is what makes review so weak.

Service accounts, machine tokens, and API keys need separate attestation rules: treating all NHIs as one bucket hides the fact that each identity type has different ownership and operational context. The programme implication is to build review logic around identity class, not around a single generic access certification workflow.


For practitioners

  • Define NHI certification scopes by risk signal Build campaigns around orphaned, idle, exposed, non-expiring, former-employee-linked, high-risk, and over-permissioned credentials so reviewers see a bounded set.
  • Assign explicit ownership before review begins Require every service account, machine token, and API key in scope to have a named attester or fallback owner before it enters certification.
  • Separate easy remediation from owner review Disable idle credentials, reassign obvious ownership, and capture provider-console instructions before escalating unresolved items to developers.
  • Export review evidence for every campaign Keep a complete log of who reviewed which NHI, what action was taken, and when the decision closed so audits can trace lifecycle accountability.

Key takeaways

  • Machine identity access reviews fail when organisations reuse human certification processes without redesigning ownership and expiry assumptions.
  • The governance gap is visible in orphaned, idle, exposed, and non-expiring credentials that can remain active long after their business context has faded.
  • Teams that want defensible NHI governance need scoped campaigns, explicit ownership, and exportable evidence for every review decision.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingInactive or former-owned credentials need lifecycle closure, which is central to this access review article.
NHI-05 — Overprivileged NHIThe article explicitly includes over-permissioned service accounts as a review target.
NHI-07 — Long-Lived SecretsNon-expiring keys and long-lived tokens are named as a review category in the source.
Recommendation — Apply NHI-01 to close orphaned and stale machine credentials through explicit offboarding and ownership reassignment. Use NHI-05 to scope review campaigns around excessive privileges and revoke unused access rights. Target NHI-07 by identifying credentials with no expiry and forcing lifecycle review before continued use.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementMachine tokens and API keys are authenticators whose lifecycle must be controlled and reviewed.
Recommendation — Apply IA-5 to govern issuance, review, rotation, and revocation of machine authenticators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about entitlement review and revocation for non-human access.
Recommendation — Use PR.AA-05 to verify NHI permissions, confirm owners, and remove unnecessary entitlements.
CIS Controls v8CIS-5 — Account ManagementThe article addresses lifecycle control of machine accounts and credential holders.
Recommendation — Apply CIS-5 to inventory, review, and retire non-human accounts with unclear ownership.

Key terms

  • Non-Human Identity Credentials: Credentials used by applications, services, APIs, and system accounts rather than people. They include API keys, service account passwords, and related secrets that authenticate automated workloads. Because these credentials often run without direct user oversight, they need explicit lifecycle controls, rotation, inventory, and monitoring.
  • Orphaned Credential: A secret, token, or service account password that remains active and valid after the NHI it was issued to has been decommissioned, or after the person or system responsible for it has left the organisation.
  • Long-Lived Secret: A long-lived secret is a credential, token, API key, or certificate that remains valid for an extended period without frequent renewal. In NHI environments, it creates durable exposure because one leaked secret can keep granting access long after the original use case has changed.
  • Access Certification Campaign: An access certification campaign is the structured workflow used to collect reviewer decisions across applications and identities. It turns access review into a managed process with assignments, reminders, decisions, remediation, and audit evidence, which is essential when estates include both human and non-human identities.

Deepen your knowledge

NHI governance, machine identity security, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 28, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org