By NHI Mgmt Group Editorial TeamBased on Aembit: “Aembit Named to Fast Company’s Seventh-Annual List of the 100 Best Workplaces for Innovators” (September 9, 2025)

TL;DR: Enterprises need dynamic, policy-driven control for workload identities, AI agents, and other non-human identities rather than static, long-lived access, according to Aembit, and Fast Company named the company to its 2025 Best Workplaces for Innovators list as it argues that ephemeral access and zero standing privilege are becoming baseline governance assumptions, not advanced features.


At a glance

What this is: This is a vendor recognition piece that frames workload identity and non-human access as a governance problem shaped by static credentials, ephemeral access, and zero standing privilege.

Why it matters: It matters because IAM, PAM, and NHI teams now have to govern machine and agent access as a live policy issue, not a one-time provisioning exercise.


Context

Workload identity is the access layer for applications, services, and AI agents that act without a human sitting at the keyboard. The problem is not simply scale. It is that static credentials and long-lived privilege create governance assumptions that no longer hold when identities are ephemeral and task-scoped.

Aembit’s recognition from Fast Company is the trigger, but the underlying issue is broader: organisations are treating non-human access as if it can be managed with the same persistence model used for human accounts. That breaks down when agentic systems and service workloads need access that is policy-driven, short-lived, and continuously governed.

This is a typical sign of where the market is heading. The discussion is moving from whether non-human identities need controls to which controls must become baseline for workload identity, AI agents, and other machine actors.


Key questions

Q: How should security teams govern AI and workload identities at runtime?

A: Security teams should govern runtime identities by combining least privilege, continuous telemetry, and approval-gated containment. The goal is not just to issue credentials safely, but to detect when those credentials are being used in ways that increase blast radius. Runtime governance should include scoped permissions, event correlation, and clear escalation thresholds.

Q: Why do static secrets create more risk for non-human identities than for human users?

A: Static secrets are copied easily, persist across environments and often outlive the workload that first used them. For service accounts, pipelines and agents, that persistence turns a single compromise into repeated access, especially when leaked credentials remain valid for long periods.

Q: What breaks when workload identity still depends on standing privilege?

A: Standing privilege breaks the assumption that access can be safely left in place between tasks. For workloads and agents, the access window is often shorter than the review cycle, so risk persists even when governance records look complete. The failure is structural: the control records who has access, but the environment keeps more access than it needs.

Q: What should IAM teams evaluate after a major shift toward ephemeral non-human access?

A: IAM teams should evaluate whether their current lifecycle, approval, and audit processes can handle short-lived machine access without falling back to persistent exceptions. The key question is whether policy can be enforced at issuance time and revoked automatically at task completion. If not, the programme is still relying on human-paced control for machine-paced behaviour.


Technical breakdown

Why static credentials fail for workload identity

Static credentials assume the identity’s access needs are stable enough to provision once and review later. Workload identity behaves differently. Applications, services, and AI agents often need access only for a specific task, environment, or execution window, which makes long-lived secrets a poor fit. The technical problem is not just secret storage. It is the mismatch between credential lifetime and operational intent. Once a secret can be reused outside its intended context, the trust boundary expands beyond the workload that was supposed to hold it.

Practical implication: Treat long-lived secrets as a design debt in workload identity architecture, not as a default control pattern.

How policy-driven access changes non-human identity governance

Policy-driven access replaces fixed entitlement assumptions with runtime evaluation. Instead of granting durable access because a workload might need it, the system evaluates who or what is asking, what it is trying to reach, and under what conditions access should exist. That matters for NHI governance because the access decision becomes part of execution, not just onboarding. This is especially relevant for AI agents, where tool access can change by task and context. The governance model shifts from managing accounts to governing authorisation events.

Practical implication: Anchor NHI controls at issuance and request time so access is evaluated against context rather than inherited indefinitely.

Zero standing privilege for machine and agent access

Zero standing privilege removes persistent access from the default state. For workload identities, that means no always-on access path sitting idle between jobs, deployments, or agent actions. The control is important because standing privilege creates unnecessary blast radius when service accounts, tokens, or agent permissions are compromised or overused. Ephemeral access reduces exposure, but it only works when identity governance can reliably provision, constrain, and revoke access without human delay. The technical challenge is orchestration, not just permissioning.

Practical implication: Use ephemeral access patterns where the workload can tolerate them, and reserve standing privilege only for tightly justified exceptions.


NHI Mgmt Group analysis

Workload identity governance is becoming the control plane for non-human access. The article reflects a broader shift: workload identity is no longer a niche infrastructure problem, it is where access policy, operational trust, and machine-scale execution meet. When AI agents, applications, and services all need access to sensitive resources, the organisation’s identity model has to govern non-human behaviour directly. Practitioners should treat this as a core IAM design issue, not a tooling add-on.

Static access assumptions are the wrong baseline for agentic and workload-driven systems. Long-lived credentials were built for identities whose access needs could be assumed stable between reviews. That assumption weakens when access is task-scoped, ephemeral, or triggered by runtime context. The result is that old lifecycle models can preserve risk even when the implementation looks current. Teams should reassess whether their current controls measure exposure or merely record it after the fact.

Ephemeral access is now a governance assumption, not an advanced feature. The article’s central message is that zero standing privilege is moving into the mainstream of non-human identity design. That matters because the market is converging on a model where access exists only when it is needed and only for as long as the workload requires it. Practitioners should align policy, telemetry, and revocation around that expectation.

Agentic AI pushes workload identity into a cross-domain governance problem. Once autonomous or semi-autonomous systems can request tools and access data sources, workload identity stops being only about service accounts and starts intersecting with agent behaviour, trust boundaries, and accountability. The practical implication is that IAM, PAM, and security architecture teams now have to govern the same access path from multiple angles at once.

From our research library:

What this signals

Ephemeral credential trust debt: organisations that keep adding machine identities without reworking access lifecycle controls accumulate hidden exposure, because the governance model still assumes privileges live long enough to be reviewed. That is the wrong assumption for workload identity, service accounts, and agentic systems, where access should be evaluated at issuance and retired at task completion.

The practical signal for IAM and PAM teams is that workload identity has crossed from infrastructure hygiene into identity architecture. If your policy engine cannot express task scope, execution window, and revocation conditions for non-human access, you are not governing the system, only documenting it after the fact.


For practitioners

  • Map non-human access by execution context Inventory applications, services, tokens, and AI agents by the job they perform, the resources they touch, and the time window in which access is actually needed.
  • Replace standing access with task-scoped issuance Grant credentials only when a workload or agent begins a bounded task, and remove them when the task or session ends.
  • Separate workload identity from human account governance Stop assuming that human joiner-mover-leaver patterns will cleanly govern machine identities, because service accounts and agents follow different lifecycle cues.
  • Review policy exceptions for persistent machine access Document every case where a workload still needs durable access, then require an explicit ownership review and expiry condition for each exception.

Key takeaways

  • The article points to a governance shift in which workload identity and other non-human access paths need policy-driven control rather than durable credentials.
  • The core risk is not just secret sprawl, but the mismatch between machine-paced access and human-paced lifecycle controls.
  • Teams should move access decisions closer to task execution and reserve standing privilege for clearly justified exceptions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on reducing persistent machine access and limiting workload privilege.
NHI-07 — Long-Lived SecretsThe article argues against static, long-lived access for non-human identities.
NHI-10 — Human Use of NHIThe piece highlights the need to keep machine access separate from human account patterns.
Recommendation — Apply NHI-05 to replace standing access with tightly scoped workload entitlements. Use NHI-07 to phase out durable secrets where ephemeral access is feasible. Use NHI-10 to prevent human-style lifecycle assumptions from governing workload credentials.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential lifecycle management is central to workload identity governance.
Recommendation — Apply IA-5 to govern issuance, rotation, and retirement of machine authenticators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about access entitlements for non-human identities.
Recommendation — Use PR.AA-05 to review and constrain non-human entitlements by task and context.

Key terms

  • Workload Identity: The identity assigned to a software workload, such as a containerised application, serverless function, or microservice, enabling it to authenticate to other services without storing static credentials.
  • Ephemeral Access: Ephemeral access is permission that exists only for the duration of a specific task or session. For agents, it reduces the lifetime of credentials and limits blast radius if a workflow is abused or misrouted. The control is only effective when issuance, expiry, and revocation are enforced automatically.
  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
  • Policy-Based Access: Policy-based access grants or denies access by evaluating rules about context, workload state, and intended action at the moment of request. For AI systems, this is more useful than static roles alone because the same workload may need different privileges across different tasks and environments.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org