By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: ConductorOnePublished July 30, 2026

TL;DR: As machine identities now outnumber humans 109 to 1, ConductorOne says its new agentic security and intelligence layer detects ownership gaps, misclassifications, shadow accounts, and missing anomaly detection across service accounts, workloads, integrations, and AI agents. The deeper issue is that identity review cycles assume risk can be observed and remediated slowly, while these identities appear, act, and disappear at machine speed.


At a glance

What this is: This is a product announcement about ConductorOne's new agentic security and intelligence capabilities, with a key finding that machine identities, including AI agents, now vastly outnumber human identities and create review blind spots.

Why it matters: It matters because IAM, IGA, and PAM teams need control paths that can detect and route remediation for non-human identities faster than manual ownership reviews, especially as AI agents and service accounts multiply.

By the numbers:

👉 Read ConductorOne's post on agentic security and intelligence for identity risk


Context

Machine identity risk is expanding faster than traditional identity governance can absorb. In environments where service accounts, workloads, integrations, and AI agents are created continuously, the main failure is not only visibility. It is the lag between identity creation, ownership assignment, access review, and remediation, especially when the primary subject is a non-human identity rather than a person.

ConductorOne's framing is useful because it separates detection from remediation. The operational problem for IAM and IGA teams is that machine identities often arrive with ambiguous ownership, poor classification, and inconsistent connector telemetry, which makes manual triage brittle. That is why the governance model has to cover NHI lifecycle, entitlement context, and audit routing together rather than as separate workflows.

This is not an edge case. It is the normal direction of travel for organisations that are scaling AI agents and other NHIs faster than their governance operating model can keep up.


Key questions

Q: Why do service accounts and AI agents need different controls from human users?

A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.

Q: Why do machine identities create problems for traditional IAM reviews?

A: Machine identities often operate through credentials and delegated permissions that persist beyond a human session, so review cycles can miss active risk. If ownership, purpose, and expiry are unclear, the identity may continue to access systems long after the original need has ended.

Q: What do teams get wrong about managing non-human identities?

A: They often treat NHIs as one-off credentials instead of governed identities with owners, lifecycles, and review requirements. That leads to stale access, orphaned secrets, and overprivileged service accounts. Effective governance requires discovery, assignment of accountability, and a revocation process that is as disciplined as human offboarding.

Q: Who should be accountable when an AI agent or service account causes access drift?

A: The accountable party should be the human or team that authorised the identity and owns the business process behind it. The agent cannot own its own lifecycle in a governance sense. Accountability must stay with a human owner who can approve, revoke, or re-scope access when usage changes.


How it works in practice

Why machine identity ownership gaps break governance

Machine identities fail governance when the system cannot reliably answer who owns them, what they are, and whether they should still exist. An orphaned service account, a misclassified account, or a shadow identity can retain access indefinitely because no human workflow closes the loop. In practice, the problem is not discovery alone. It is identity context, classification fidelity, and lifecycle state tied together across connected systems so that risk can be reasoned about before it spreads into entitlement sprawl.

Practical implication: teams need a reliable ownership and classification control point for every NHI before access reviews can mean anything.

How routing changes the value of identity findings

A finding without routing is just another alert. The architectural shift here is to connect identity detection to the same approval, tagging, and audit path used for access governance, so a flagged NHI can move from identification to remediation without manual re-entry. That matters because remediation is often the slowest step in machine identity governance, especially when the action is to assign ownership, right-size access, or revoke an account that should never have been active.

Practical implication: integrate finding triage with request, approval, and audit workflows instead of letting NHI risk sit in a separate queue.

Why connector telemetry becomes part of identity risk

Identity intelligence is only as strong as the telemetry behind it. If anomaly detection is disabled on a connector, or if imported findings are not normalised into the same governance queue, the organisation loses consistency in how it measures and acts on NHI risk. This is especially important in hybrid environments where AI agents may rely on service accounts, APIs, and external tools, because the access graph becomes the evidence layer for impact analysis.

Practical implication: validate connector coverage and telemetry quality as part of NHI control design, not as an afterthought.


NHI Mgmt Group analysis

Machine identity governance is now a detection-and-routing problem, not just an inventory problem. The article describes a control model that flags ownership gaps, misclassification, and shadow identities, then pushes remediation through governed workflows. That reflects the reality that NHIs fail in the gaps between systems, not only in the systems themselves. Practitioners should treat detection, classification, and routing as one governance loop, not three separate tools.

109 machine identities for every human identity is a governance ratio that breaks manual review assumptions. When machine identities outpace human review by that margin, access certification becomes structurally stale before it is complete. The field needs to stop treating NHI review as an extension of human IAM cadence and start treating it as a separate operating problem with its own control rhythm. The practitioner conclusion is that review-based governance alone no longer scales.

Identity context is the named concept that now determines whether NHI findings are actionable. A finding without the identity's access graph, entitlement reach, and ownership state cannot support meaningful remediation or impact assessment. That is why the discipline is moving toward identity blast radius, where the question is not only whether an NHI exists, but how far its access can reach if it is wrong. Practitioners should prioritise context-rich governance over flat inventories.

Shadow accounts and misclassified identities expose a standing privilege assumption that governance teams still rely on. The control model assumes an identity is known, owned, and reviewable before it can do harm. In fast-moving AI and workload environments, that assumption fails because identities can be created, delegated, and used before ownership is settled. The implication is that governance teams must rethink how accountability attaches to machine identities, not just add another review step.

Routing remediation through existing governance is the only practical way to make NHI detection operational. The article's design pattern aligns with how modern identity programmes actually work: findings must land in request, approval, incident, or ITSM workflows where action can be assigned and audited. That is the difference between visibility and control. Practitioners should evaluate whether their NHI detection stack can hand off cleanly into the systems that already enforce policy.

From our research:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which explains why ownership and entitlement gaps persist.
  • For the lifecycle angle, Ultimate Guide to NHIs is the clearest starting point for rotation, offboarding, and visibility controls.

What this signals

Identity blast radius is the concept practitioners should carry forward from this launch. Once detection is coupled to an access graph, teams can stop judging NHIs as isolated objects and start evaluating how far a misclassified account can reach before remediation. That shift is especially important for programmes using the Ultimate Guide to NHIs as a lifecycle baseline.

With 79% of organisations having experienced secrets leaks, the operational lesson is that detection alone is not enough. NHI programmes need triage paths that convert findings into revocation, reassignment, or containment before access becomes persistent.

The broader signal is that IAM teams will increasingly need to unify human, machine, and agent workflows in the same governance plane. The organisations that keep NHI findings in separate dashboards will continue to discover risk after the access has already been exercised.


For practitioners


Key takeaways

  • Machine identities now create governance risk faster than manual review cycles can resolve it, which makes lifecycle controls a core security requirement.
  • Ownership gaps, misclassification, and shadow accounts are not edge cases. They are the failure modes that turn NHI scale into security exposure.
  • Detection only matters when it routes into approval, audit, and remediation workflows that can change access immediately.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on unmanaged NHI discovery, ownership gaps, and lifecycle governance.
NIST CSF 2.0PR.AC-1Identity and access management controls are directly implicated by NHI classification and remediation workflows.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous verification of identities whose ownership and access change quickly.
NIST SP 800-53 Rev 5IA-5Authenticator management applies to secrets, API keys, and other machine credentials discussed here.

Map every service account and AI agent to an owner, purpose, and retirement condition before granting durable access.


Key terms

  • Machine Identity: The digital identity of a machine, device, or workload — such as a server, container, or VM — used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Shadow account: A shadow account is an identity used for work that is not managed under normal organisational controls. It may lack approved MFA, monitoring, retention, and revocation processes. In practice, it creates a parallel trust zone where sensitive activity can occur without the same governance applied to corporate identities.

What's in the full announcement

ConductorOne's full post covers the operational detail this post intentionally leaves for the source:

  • How the agentic security queue maps identity findings to owner assignment, right-sizing, and revocation
  • How imported findings from external tools inherit the same tagging, routing, and audit trail
  • How the access graph is used to assess impact before remediation
  • How the platform verifies that an ownership gap has actually been cleared

👉 The full ConductorOne post covers the detection logic, routing flow, and audit handling in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing identity security practice, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org