By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: ConductorOnePublished July 30, 2026

TL;DR: C1 says its new agentic security and intelligence layer inventories humans, non-human identities, and AI agents, creates findings for ownership and access issues, and routes remediation through approval workflows with audit trails, while Palo Alto Networks’ 2026 Identity Security Landscape says organisations now manage 109 machine identities for every human identity. The governance problem is not discovery alone; it is proving resolution across identity types.


At a glance

What this is: C1’s launch centers on a unified identity inventory that turns risk findings across humans, NHIs, and AI agents into governed remediation with auditability.

Why it matters: For IAM, IGA, and PAM teams, the issue is whether ownership, certification, and exception handling can keep pace as AI agents and machine identities expand faster than human governance processes.

By the numbers:

👉 Read ConductorOne’s analysis of agentic security and intelligence for identity risk


Context

Identity governance is moving from inventory to accountability. Once AI agents, service accounts, and human users are all routed through the same access fabric, the harder problem becomes proving who owns each identity, who approved each entitlement, and whether the resulting action was actually resolved.

This launch is best read as a sign that identity programmes are being asked to connect discovery, ownership, certification, and remediation across multiple actor types. That matters because the control failure is usually not a single missing tool, but the gap between finding an issue and closing it with an auditable decision path.


Key questions

Q: What do IAM teams get wrong about service accounts and AI agent permissions?

A: They often assume the user token or service account scope fully describes the agent’s risk. In practice, an agent can chain multiple operations within one session and operate with broader effective reach than the user intended. The control objective is not just identity binding, but action scoping.

Q: Why do AI agents make non-human identity governance harder?

A: AI agents make governance harder because they can request tools, act autonomously, and change behaviour across sessions while still relying on machine credentials. That increases the number of access paths security teams must supervise. The result is a stronger need for task-scoped access, explicit ownership, and continuous monitoring of what the agent can reach.

Q: What breaks when identity findings are tracked in one tool and remediated in another?

A: You lose the evidence chain. Discovery without closure leaves teams unable to prove that access was actually revoked, right-sized, or certified. That creates audit gaps, duplicated effort, and unresolved exposure, especially when identities span humans, NHIs, and AI agents.

Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?

A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.


How it works in practice

Unified identity inventory across humans, NHIs, and AI agents

A unified identity inventory is a graph of subjects, entitlements, and connected systems that lets teams see whether an account is human, machine, or agentic in practice. The technical value is not simply enumeration. It is correlation: linking ownership metadata, access paths, anomalous signals, and downstream systems so that an identity can be investigated and remediated in one record rather than scattered tickets. In mixed estates, classification errors are common, especially when service accounts impersonate users or AI agents are embedded inside platforms such as Salesforce Agentforce or AWS Bedrock AgentCore.

Practical implication: establish a single authoritative inventory for identity subjects before trying to automate remediation.

Governed remediation as the control plane for identity findings

Governed remediation means a finding is not just logged. It is routed through an approval, exception, or automation path that preserves audit evidence. That matters because access review, JIT access, and remediation often live in separate systems, which leaves teams unable to prove that a risk was actually closed. The architectural shift here is from passive detection to closed-loop response, where revocation, owner reassignment, access right-sizing, and exception certification all carry the same record of decision.

Practical implication: require every identity-risk finding to resolve through a traceable workflow, not an ad hoc ticket.

Why auditability matters when AI agents act with access

AI agents create a governance problem because they can hold credentials, operate across systems, and generate actions that look like ordinary identity use until the blast radius is already visible. An audit trail is therefore not a reporting feature. It is the evidence chain that ties an agent action back to ownership, approval, and remediation status. Without that chain, compliance teams cannot separate delegated action from unowned activity, and security teams cannot distinguish a valid autonomous workflow from a risky privilege boundary crossing.

Practical implication: require agent actions to remain attributable to a human owner, approval path, and remediation record.


NHI Mgmt Group analysis

Identity governance is shifting from entitlement management to accountability management. The launch reflects a broader market truth: finding an identity risk is no longer the hard part, but proving that the risk was resolved is still where most programmes break down. When humans, service accounts, and AI agents are all in the same estate, the control problem is whether ownership, approval, and evidence can survive across systems. Practitioners should treat accountability as the primary design goal, not a reporting afterthought.

Unowned identity risk is now a field-level governance concept, not a ticketing issue. The article’s core premise is that unowned service accounts, misclassified accounts, and agent findings need to become first-class records. That aligns with OWASP-NHI and zero-trust thinking because identity state must be explicit before access can be trusted. The practitioner conclusion is straightforward: if ownership is ambiguous, governance is already failing.

AI agents turn stale access into an active operating condition. A human can be reviewed on a cadence; an agent can inherit, use, and compound access across systems faster than traditional recertification loops can react. That does not make every agent autonomous, but it does make identity drift more operationally dangerous because remediation delay becomes exposure time. Teams should assume that agent visibility without governed closure is only partial control.

Identity blast radius is the right named concept for this launch. The article shows that access is no longer only about whether an identity exists, but how far its reach extends across applications, automations, and remediation workflows. When one identity record can trigger owner reassignment, revocation, certification, and downstream automation, the blast radius is both technical and procedural. Practitioners need to measure not just access volume but the distance between discovery and accountable closure.

Cross-domain identity governance will become the baseline for mixed estates. The important shift is that the same governance pattern now has to work for workforce identities, service accounts, and AI agents. That raises the bar for IGA, PAM, and NHI teams because classification, evidence, and remediation all have to interoperate. The organisations that still run separate governance paths for each actor type will struggle to sustain auditability as AI adoption expands.

From our research:

  • 73% of vaults are misconfigured, leading to unauthorised access and exposure of sensitive data, according to the Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
  • For a deeper lifecycle angle, Top 10 NHI Issues outlines the governance failures that turn identity sprawl into persistent exposure.

What this signals

Identity blast radius is becoming the more useful control lens than simple access counts. As AI agents, service accounts, and workforce identities converge, the practical question is how far any one subject can reach before governance catches up. The programme signal is clear: if your inventory cannot show owner, purpose, and closure status in one place, your remediation model will not scale.

The next maturity step is closed-loop governance, where discovery, approval, certification, and revocation all share the same evidence path. That is why programmes should align their identity workflows with the Ultimate Guide to NHIs and, where AI agents are in scope, the OWASP Agentic AI Top 10 so the control model reflects both NHI and agentic risk.

When access risk can be reassigned, right-sized, or automated from a single finding, the limiting factor becomes not detection coverage but operational closure. Teams should watch for identities that remain open after discovery because those are the cases that expand the attack surface and erode audit confidence.


For practitioners

  • Define one identity ownership record per subject Tie every human, service account, and AI agent to a named owner, business purpose, and escalation path before allowing access to be operationalised. Treat unowned identities as governance failures, not housekeeping issues, and block remediation closure until ownership is assigned.
  • Route identity findings through a closed-loop workflow Make every finding resolve through the same approval, exception, or automation path, with an audit trail attached at closure. Integrate your IGA, PAM, and ticketing stack so revocation, right-sizing, and certification all end in one accountable record.
  • Classify agent accounts separately from human users Do not let AI agents inherit user-style governance assumptions by default. Record whether the subject is a person, service account, or agent, and require different review logic for each so that recertification and exception handling match the actor type.
  • Measure unresolved findings as exposure time Track how long identity findings remain open after discovery, especially for unowned service accounts and agent privileges. Use that metric to identify which teams, systems, or approval paths are extending the blast radius instead of closing it.

Key takeaways

  • The central governance problem is no longer finding identity risk, but proving that it was resolved with accountable evidence.
  • As AI agents and NHIs scale together, unresolved ownership and misclassification become blast-radius multipliers rather than simple administrative defects.
  • Security teams need closed-loop remediation, not fragmented workflows, if they want identity governance to survive mixed human and machine estates.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on unowned and misclassified non-human identities.
NIST Zero Trust (SP 800-207)4.0The post emphasizes continuous verification across mixed identity types.
NIST CSF 2.0PR.AC-1Identity ownership and access lifecycle control are the core governance issues here.
NIST SP 800-53 Rev 5IA-5The article touches credential-driven identity risk and remediation.

Inventory and classify every non-human identity before allowing remediation workflows to proceed.


Key terms

  • Identity Intelligence: Identity intelligence is the layer that turns raw identity data into context about risk, usage, and privilege. It helps teams distinguish harmless access from materially risky access by linking identity records, entitlement patterns, and behavioural signals, which is essential when non-human identities scale faster than manual review.
  • Closed-Loop Remediation: A governance process that does not stop at finding risk. It removes or reduces access, confirms the change in the source systems, and keeps evidence that the risky condition stayed fixed. For NHIs, this is the difference between inventory and actual risk reduction.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Unowned Identity: An account, token, service principal, or agent that lacks a clearly accountable human or team owner. Unowned identities are high-risk because access decisions, remediation, and audit responsibility all become ambiguous at the same time.

What's in the full announcement

ConductorOne's full post covers the operational detail this post intentionally leaves for the source:

  • How the identity intelligence graph maps humans, NHIs, and AI agents to connected systems and access paths
  • The remediation workflow options for owner reassignment, access right-sizing, certification, and exception handling
  • How findings can be routed into ServiceNow, Jira, PagerDuty, webhooks, and automations with audit evidence attached
  • Examples of the signal types that trigger a finding, including decoy credential use and misclassified accounts

👉 The full ConductorOne post covers the identity graph, remediation workflow, and audit trail details.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building identity security capability across your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org