By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ExaforcePublished March 17, 2026

TL;DR: Customer environments processed 79 billion events and 1.29 million alerts in 2025, with 97% of alerts requiring no analyst investigation and 98% later judged benign or false positives, while NHI density reached 14.5:1 and AWS made up 67% of telemetry on average, according to Exaforce. The operating lesson is that cloud-scale SOCs now depend on identity context, not just more log volume.


At a glance

What this is: This review argues that modern SOCs are being overwhelmed by cloud telemetry, NHI sprawl, and third-party risk, and that agentic automation is increasingly used to absorb the noise.

Why it matters: For IAM and SOC practitioners, the identity signal is now part of operational triage, because non-human identities and cloud access paths shape what gets investigated, escalated, and contained.

By the numbers:

👉 Read Exaforce's year-in-review analysis of agentic SOC operations and NHI pressure


Context

Modern SOCs are dealing with a governance problem, not just a tooling problem. Cloud telemetry is high-volume, non-human identities multiply faster than human users, and third-party dependencies now sit inside routine operations rather than on the edge of them. In that environment, identity context determines whether an alert is intelligible or just another item in a queue.

The primary identity lesson in this review is that non-human identities are now a first-class SOC signal. When cloud events, service accounts, and third-party access all contribute to the same incident path, detection and investigation cannot stay organised around human user records alone. That starting position is now typical for cloud-heavy enterprises, not an edge case.


Key questions

Q: What breaks in SOC triage when non-human identities are not modelled separately?

A: Alert context becomes too shallow to distinguish a person, a service account, or a delegated workflow, so analysts investigate the wrong actor or miss the real access path. That raises false confidence in triage and weakens containment decisions, especially in cloud environments where automated identities dominate day-to-day activity.

Q: Why do non-human identities complicate incident response more than user accounts?

A: Non-human identities are often embedded in tools, collectors, pipelines, and third-party services, so the affected access path is distributed rather than centralized. That means one compromise can require coordinated action across multiple owners and systems. The operational burden is finding every place the credential is stored and used.

Q: How do SOC teams know whether automation is reducing risk or just hiding work?

A: They should measure whether investigation time, case quality, and containment accuracy improve together. If triage gets faster but analysts still chase missing context, the platform is only relocating labour. Real improvement shows up when duplication drops, evidence stays traceable, and the right cases rise first.

Q: What should organisations do when third-party access is part of routine operations?

A: Treat supplier credentials, integrations, and delegated access as in-scope security objects with ownership, review, and revocation rules. The practical test is whether you can identify who granted the access, what it is for, and how quickly it can be removed when the relationship changes.


Technical breakdown

Why cloud telemetry overwhelms traditional SIEM workflows

Cloud environments generate high-cardinality, short-lived, and distributed activity that does not fit neatly into older ingest-and-retain SOC models. A SIEM can store the data, but storage alone does not create investigation-ready context. The real issue is that cloud logs often arrive detached from business meaning, so analysts spend time reconstructing what a service, role, or workload was supposed to do. That becomes worse when telemetry is dominated by a single cloud provider and when identity changes faster than detection logic can be tuned.

Practical implication: correlation logic must be built around cloud identity context, not just raw event volume.

How non-human identity sprawl changes alert triage

Non-human identities include service accounts, API keys, tokens, certificates, bots, and workload credentials. In cloud operations, they often outnumber human identities and are used in automated paths that conventional access reviews do not see in time. That means an alert may actually be about delegated access, a workload credential, or an integration path rather than a named employee. SOC teams that do not model NHI relationships end up missing the real actor, the real privilege boundary, or the real blast radius.

Practical implication: build identity graphs that map alerts back to workload and service-account ownership.

Why agentic SOCs are moving from triage to lifecycle response

Agentic SOCs aim to connect detection, triage, investigation, and response as one workflow because the handoff between those stages is now a bottleneck. The point is not simply to automate first-line review. It is to preserve context from the first signal through containment so that analysts can focus on the smaller set of alerts that require judgment. In practice, that means models and automation must explain why an alert was dismissed or escalated, especially when identity misuse, third-party behavior, or cloud access paths are involved.

Practical implication: require decision traceability before using automation to suppress or close alerts.


Threat narrative

Attacker objective: The attacker seeks to turn legitimate cloud and identity paths into trusted access that can bypass noisy detection and accelerate impact.

  1. Entry begins in cloud environments where attackers target exposed access paths, third-party integrations, or identity-linked footholds that already exist in daily operations.
  2. Escalation follows when compromised non-human identities or delegated credentials provide access that looks legitimate to detection tooling.
  3. Impact occurs when the attacker uses that trusted access to move faster than manual triage can respond, increasing the chance of data theft, disruption, or ransomware deployment.

NHI Mgmt Group analysis

Cloud telemetry has outgrown legacy SOC assumptions. Security teams still behave as if most useful evidence can be centrally ingested, correlated, and reviewed at human speed. In cloud-heavy estates, that assumption fails because the data is too voluminous and the resources are too ephemeral. Practitioners need operating models that treat telemetry reduction and context preservation as core control objectives, not reporting conveniences.

NHI sprawl is now a SOC design issue, not a niche IAM concern. When non-human identities outnumber human users, the SOC must be able to distinguish service activity, workload behaviour, and delegated access from genuine compromise. That requires identity-aware detection logic, not just broader log collection. The named concept here is NHI triage debt: the accumulation of unresolved non-human identity context that slows or distorts investigation. The longer teams defer this, the less reliable their incident decisions become.

Agentic automation changes the economics of investigation, but only if it preserves reasoning. A SOC that auto-disposes alerts without explainability may reduce workload while increasing governance risk. Human analysts still need to know why the machine suppressed, escalated, or grouped a signal. Without that traceability, automation creates a new blind spot inside the very control layer meant to reduce noise.

Third-party behaviour has become part of the attack surface. The article correctly points to a broader reality that dependency risk is now operational, not theoretical. Security programmes need to treat supplier actions, integration credentials, and delegated cloud access as reviewable security objects. That is where cloud security and identity governance intersect most sharply, and that intersection should now be explicit in SOC design.

What this signals

NHI triage debt: the more non-human identities a SOC inherits, the more investigation quality depends on identity ownership, not just alert volume. Teams that cannot link alerts to service accounts, tokens, and workload roles will continue to over-triage noise and under-react to abuse. For identity-led environments, that makes cloud incident response a governance problem as much as a detection problem.

The next programme shift is to treat delegated access and supplier credentials as first-class investigation objects. That means pairing cloud detection with identity lifecycle controls and reviewing where automation can revoke, rotate, or isolate access without waiting for a manual ticket. The right benchmark is whether the SOC can explain an alert in identity terms before the session, workflow, or integration chain completes.

As agentic automation becomes more common, security leaders should expect tighter scrutiny of how decisions are made, not just how many alerts are closed. The operational question is whether automation preserves enough context to support accountability, especially when the actor is a workload, bot, or third-party integration rather than a named person.


For practitioners

  • Map alerts to non-human identity ownership Require every cloud alert to resolve to a workload, service account, token, or integration owner before it is triaged or dismissed. If the alert cannot be tied back to an accountable identity, treat it as incomplete context rather than low priority. Use identity correlation to reduce the chance that delegated access hides the actual attack path.
  • Separate benign automation from risky delegated access Classify routine service activity, third-party integrations, and privileged automation into distinct detection buckets so SOC analysts can see when normal-looking behaviour crosses an access boundary. This reduces the chance that an attacker hiding inside an approved workflow gets auto-dismissed.
  • Require explanation before auto-disposition If an agentic SOC workflow closes or suppresses an alert, retain the model reason, identity context, and contributing events for later review. That evidence is essential when you need to challenge false negatives or prove that the automation decision was defensible.
  • Rebuild review around cloud and third-party paths Extend investigations beyond owned assets to include cloud integrations, supplier connections, and delegated credentials. The review should answer which identity had access, what system granted it, and whether that access still matched the intended business function.

Key takeaways

  • Modern SOC noise is now an identity governance issue, because non-human identities and delegated cloud access shape what investigators actually see.
  • Exaforce's customer data shows the scale of the problem, with 79 billion events, 1.29 million alerts, and 97% of alerts requiring no manual investigation.
  • Teams should redesign triage around identity context, explainable automation, and third-party access paths rather than relying on raw log volume.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-7Cloud telemetry and alert triage map directly to continuous monitoring and detection coverage.
NIST SP 800-53 Rev 5SI-4The review centres on detection, correlation, and response quality across large cloud environments.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe article's threat themes repeatedly involve identity misuse and downstream movement.
CIS Controls v8CIS-5 , Account ManagementNon-human identity sprawl and delegated access are central to the SOC governance problem described.
NIST AI RMFGOVERNAgentic SOC automation raises accountability and oversight questions for AI-assisted decisions.

Map cloud and NHI detections to credential access and lateral movement tactics to improve triage fidelity.


Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Agentic Soc: An agentic SOC is a security operations model where AI systems assist with triage, investigation, and response using tool access and execution authority. The control challenge is not just accuracy, but governance of what the machine can see, decide, and do.
  • Cloud Telemetry: Cloud telemetry is the operational data emitted by cloud services, workloads, identities, and control planes. It is high volume, highly distributed, and often short-lived, which means its value depends on how well it is normalised, correlated, and linked back to business-relevant identity context.
  • False positive closure rate: The share of alerts that are automatically identified as benign and closed with supporting evidence before reaching analyst queues. It is a useful SOC metric because it shows whether automation is reducing noise without hiding real threats.

What's in the full article

Exaforce's full review covers the operational detail this post intentionally leaves for the source:

  • Customer-by-customer outcome data showing how many alerts were auto-disposed versus escalated for human review
  • The specific false-positive patterns by source, including CWPPs, SIEMs, native cloud tools, email security, and EDR
  • Examples of the extended research areas, including supply chain and cloud identity attack paths
  • The company milestones, funding context, and product packaging details behind the year-in-review narrative

👉 Exaforce's full review includes the customer metrics, false-positive breakdowns, and research themes behind the SOC findings.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity control to real operational risk across modern security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org