TL;DR: Nexis says AI agents and other non-human identities now need the same governance discipline as workforce accounts, as its roadmap adds an Evidence Collector for verifiable documentation, governable dynamic access policies, NICO AI Co-Pilot, and recertification reviews that reviewers actually finish. The core shift is that identity governance is expanding from periodic human review to continuous proof, policy, and oversight for machine actors.
Editorial analysis by NHI Mgmt Group, based on content published by Nexis: “Agents, Evidence, and Dynamic Policies: New and Upcoming NEXIS Features”.
At a glance
What this is: Nexis outlines upcoming identity governance features for AI agents and other non-human identities, centring on evidence collection, dynamic access policies, and recertification workflows.
Why it matters: IAM and IGA teams need to plan for governance models that extend beyond people, because machine and agent identities bring different review, evidence, and policy enforcement requirements.
👉 Read Nexis's outlook on AI agents, evidence, and dynamic identity governance
Context
Identity governance is moving beyond workforce accounts into AI agents and other non-human identities, which means review, approval, and documentation workflows can no longer assume a person is the subject of control. The article frames this as a practical governance problem, not a future concept, and positions agent access review as an immediate operational question for IAM and IGA teams.
The underlying gap is familiar to identity teams: periodic recertification was built for stable human access patterns, while AI systems can accumulate access, act through dynamic policies, and generate evidence differently. That makes proof, policy enforcement, and reviewer workflow design part of the same governance conversation.
Key questions
Q: How should security teams recertify AI agent access differently from human access?
A: Use a separate review flow that tracks the agent's business purpose, runtime scope, and evidence trail rather than relying on manager-centric workforce review. The key is to judge whether the machine identity still has a defensible task boundary, not whether a person remembers approving it.
Q: Why does evidence matter so much in non-human identity governance?
A: Evidence turns access decisions into something reviewers and auditors can verify later. For non-human identities, that matters because access can be dynamic, task-scoped, and harder to reconstruct from ordinary user-centric records.
Q: What breaks when AI agent access is reviewed only after the fact?
A: After-the-fact review leaves a gap between action and containment. If an agent can already reach a dataset, API, or SaaS system, the damage may be done before a human sees the alert. Runtime checks reduce that gap by stopping unauthorized actions before they execute.
Q: How should organisations decide when dynamic access policies are appropriate for AI agents?
A: Use dynamic policy when access needs to follow task scope, runtime context, or changing risk signals, but keep the policy simple enough that governance can still explain and verify each decision. If the rule set cannot be audited, it is too dynamic to govern safely.
Background and context
Why AI agent access review breaks human recertification models
Human recertification assumes a stable account holder, a clear manager, and access that can be assessed on a calendar cycle. AI agents do not fit that pattern cleanly when their permissions are granted to support task execution, their behaviour changes with context, and the review subject is a machine identity rather than an employee. That changes the control objective from asking whether a person still needs access to asking whether the agent's access scope, evidence, and policy boundary still match its current function. Governance has to follow the identity subject, not the familiar workflow.
Practical implication: Treat agent recertification as a distinct governance process, not a copy of workforce access review.
Evidence collection for NHI governance and auditability
Evidence in identity governance is not just logging. It is the artefact trail that proves who had access, why it was granted, what policy governed it, and what changed over time. For AI agents and other NHIs, that evidence must be easier to verify because access can be more dynamic and less visible to business owners. A dedicated evidence layer matters when reviewers need to confirm not only entitlement but also the rationale behind agent behaviour and the controls that shaped it. Without that, governance becomes an assertion instead of proof.
Practical implication: Build evidence capture into governance workflows so reviews can be completed against verifiable artefacts, not screenshots and assumptions.
Dynamic access policies for autonomous and semi-autonomous access
Dynamic access policy means access conditions can change with context, task, or risk signal instead of staying fixed after provisioning. In human IAM, that idea already appears in conditional access and just-in-time patterns. For AI agents and other NHIs, the policy question becomes sharper because the actor may need access only for a narrow runtime window, and the entitlement may need to change as the task changes. That makes policy logic and governance review inseparable. The challenge is less about granting more access and more about defining when the current access state is still defensible.
Practical implication: Design policies so runtime conditions, task scope, and review evidence are governed together.
NHI Mgmt Group analysis
AI agent governance is now an identity discipline, not a feature add-on. The article shows that recertification, evidence, and dynamic policy are converging into one control surface for machine actors. That matters because identity teams cannot govern AI agents by only extending human workflows and hoping the same review logic will hold. Practitioner conclusion: agents need identity governance designed around their runtime behaviour, not a human proxy.
Evidence is becoming a first-class control in NHI governance. A verifiable documentation layer matters because approvals without durable proof do not scale to machine identities that act continuously or change context quickly. This is a governance problem as much as an audit problem, since weak evidence makes every downstream review less credible. Practitioner conclusion: if evidence cannot be reconstructed cleanly, the entitlement was never truly governable.
Dynamic policy is the right direction, but only if governance can keep pace with it. Static access decisions are increasingly mismatched to AI agents that need bounded, task-scoped authority. The field should interpret this as a shift away from one-time provisioning certainty toward ongoing policy realism. Practitioner conclusion: the access model must be reviewed as often as the automation model changes.
Recertification for AI agents will fail if the review experience is still built for humans. The article's emphasis on reviews reviewers actually finish points to a broader governance truth: a control that cannot be completed reliably becomes symbolic rather than defensive. That is especially relevant when reviewers are asked to judge machine access they do not operationally understand. Practitioner conclusion: the workflow has to match the subject being reviewed, or governance becomes friction without assurance.
From our research library:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
- Read next: AI Agent Authorisation Guide
What this signals
Evidence-led governance is becoming the practical boundary for machine identity programmes. Teams that cannot reconstruct why an AI agent had access will struggle to defend that access in reviews, audits, or incident response. The control is shifting from approval alone to approval plus proof, which changes how IGA teams should design their operating model.
Dynamic policy only works when the governance layer can explain the decision state. For AI agents, the question is not whether access can be made flexible, but whether the resulting access path remains reviewable and attributable when the task changes. That is where many current IAM processes start to lose control fidelity.
53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey. That expectation makes agent governance a near-term operating requirement, not a speculative policy discussion.
For practitioners
- Map AI agents to a separate governance workflow Define a non-human identity review path for agents that includes ownership, business purpose, evidence, and runtime access scope. Do not route these reviews through the same assumptions used for workforce recertification.
- Require verifiable evidence for every entitlement decision Capture the policy rationale, approver context, and access scope in a form reviewers can inspect later. If the evidence cannot be reconstructed, treat the access decision as incomplete.
- Review dynamic policies as a governance control Validate whether task-scoped or context-sensitive rules still reflect actual agent behaviour after model or workflow changes. Reassess policy drift whenever the agent's operating context changes.
- Redesign recertification for machine identities Shorten review loops where agent access changes quickly, and assign reviewers who can evaluate the operational purpose of the identity rather than just the named owner.
Key takeaways
- AI agents are forcing identity governance to expand beyond workforce-centric recertification and into machine-specific review models.
- Evidence, policy, and review completion are becoming tightly linked controls for non-human identity governance.
- If governance cannot explain and verify agent access, the entitlement is not truly under control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | The article focuses on governance of AI agents and other NHIs through human review and oversight. |
| NHI-05 — Overprivileged NHI | Dynamic access policy and recertification are directly about constraining excessive machine identity access. | |
| Recommendation — Separate human oversight duties from machine identity operations so reviewers govern the agent, not the person behind it. Review agent entitlements against task scope and remove any access that exceeds current operational need. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing and reviewing access permissions for machine identities. |
| GV.OV-01 — Oversight of the Cybersecurity Risk Management Strategy | The roadmap theme is governance oversight for emerging AI identity controls and evidence processes. | |
| Recommendation — Apply entitlement controls to keep agent access authorized, scoped, and reviewable over time. Extend governance oversight to machine identity evidence, policy, and recertification outcomes. | ||
Key terms
- Evidence Collector: A governance capability that captures proof of why access existed, who approved it, and what policy governed it. In machine identity programmes, the value is not storage alone but the ability to reconstruct access decisions later for review, audit, or incident analysis.
- Dynamic Access Policy: An authorisation approach that changes access decisions based on context such as device posture, location, or session risk. Unlike static role-based rules, it can step up, limit, or deny access as conditions shift during the session.
- Machine Identity Recertification: A periodic governance review of service, workload, or agent identities to confirm that access is still justified. Unlike human recertification, the review must account for runtime behaviour, task scope, and evidence quality rather than relying on manager memory or organisational charts.
- Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials, ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.
What to expect at the briefing
Nexis's full webinar covers the operational detail this post intentionally leaves for the source:
- Live walkthrough of the Evidence Collector and how it turns governance documentation into verifiable proof
- Feature context for governable dynamic access policies and how they fit into day-to-day IAM operations
- Recertification workflow details aimed at helping reviewers complete reviews instead of abandoning them
- Roadmap context for Bring Your Own LLM and how governance choices change when the model is part of the control plane
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on October 5, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org