By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: Oleria SecurityPublished September 9, 2026

TL;DR: Continuous governance is becoming the baseline for human, non-human, and AI identities because periodic certification leaves standing privilege and access drift unchecked, according to Oleria Security’s partnership announcement with SDG. The governance model now has to treat identity as a live control surface, not a quarterly review exercise.


At a glance

What this is: This announcement frames a partnership aimed at modernizing identity governance so human, non-human, and AI identities can be governed with continuous visibility and adaptive controls.

Why it matters: It matters because IAM teams are being asked to manage service accounts, machine identities, and AI agents with the same governance discipline once reserved for people, but with far less tolerance for delay.

By the numbers:

👉 Read Oleria Security's announcement on continuous identity governance for AI-era estates


Context

Identity governance is no longer just about employee access reviews. Once service accounts, applications, machine identities, and AI agents enter the environment, the control problem shifts from periodic certification to continuous visibility, entitlement accuracy, and privilege removal across actors that do not behave like people.

The primary gap is not simply scale. It is that legacy IGA models were built around point-in-time decisions, while modern enterprises need to understand effective access as it changes. In that sense, AI era identity governance is now a continuous control problem across human IAM, NHI governance, and emerging agentic access.

This partnership is presented as a response to that gap. The relevant question for practitioners is not whether governance should modernize, but which identity populations need live oversight first and how quickly standing privilege can be reduced without breaking operations.


Key questions

Q: How should IAM teams govern human, non-human, and AI identities together?

A: Start by separating the identity types in policy, ownership, and review cadence, then define where controls can be shared and where they must remain distinct. Human users, service identities, and AI systems do not fail in the same way, so the governance model has to preserve that difference while still producing one audit trail.

Q: When does periodic access certification stop working for identity governance?

A: Periodic certification stops working when identities change faster than a review cycle can observe them. That is common in cloud, automation, and agentic environments where access is created, reused, and expanded between review windows. At that point, certification becomes historical documentation rather than a control that meaningfully limits exposure.

Q: What are the signs that a governance programme is failing for non-human identities?

A: The clearest signs are poor ownership, unexplained standing privilege, and access that survives long after the business task ends. If teams cannot say who owns an application account, when it should be revoked, or why it still exists, the programme is already behind the identity estate it is meant to control.

Q: How can organisations reduce third-party identity risk without slowing operations?

A: By making onboarding, ownership, review, and offboarding part of one lifecycle path. That approach reduces orphaned access and gives security and compliance teams a single place to verify who is still authorised. The goal is not to block collaboration, but to keep external access accountable.


How it works in practice

Continuous identity governance versus periodic certification

Periodic certification assumes access can be reviewed on a schedule and still be meaningful by the time reviewers act. Continuous governance replaces that assumption with live evaluation of access as it changes, which is especially important when identities are non-human or machine-driven and can accumulate risk far faster than a quarterly campaign can clear it. Effective access must be measured against current role, activity, and context rather than the original approval record. That is the architectural shift this article is pointing toward.

Practical implication: move high-change identity populations out of quarterly-only review cycles and into continuous entitlement monitoring.

Why standing privilege is the wrong default for machine and AI identities

Standing privilege is persistent access that remains available even when the identity is idle. For service accounts, applications, and AI agents, that creates unnecessary blast radius because the access often outlives the business task that justified it. In mixed estates, the risk is not just excess permission, but stale permission that nobody is actively observing. Continuous governance only works if privilege can be reduced to the minimum viable scope and withdrawn when the task or trust relationship changes.

Practical implication: inventory identities with persistent access and prioritise them for privilege reduction and lifecycle review.

Unified governance for human, non-human, and AI identities

A unified governance model does not mean treating every identity the same. It means applying the same lifecycle logic across different actor types while preserving the controls each one needs. Human users still need familiar access governance, but service accounts, machine identities, and AI agents also need ownership, review, and offboarding logic. The central technical challenge is keeping effective access visible across systems that span cloud, SaaS, automation, and emerging agentic workflows without breaking auditability.

Practical implication: design a single governance view that can classify, review, and retire access across all three identity classes.


NHI Mgmt Group analysis

Continuous governance is becoming the only defensible model for mixed identity estates. Periodic access reviews were designed for environments where entitlements changed slowly enough to be certified after the fact. That model breaks once service accounts, machine identities, and AI agents operate inside the same control plane as humans. The implication is not just more automation. It is a different governance stance, where access must be evaluated as a live state rather than an audit event.

Standing privilege is now a governance liability, not an administrative convenience. The article’s core message is that persistent access creates risk across every actor type, but the problem is sharpest for non-human identities because they often outlive the people or systems that created them. In practice, standing privilege widens blast radius and weakens accountability. Practitioners should treat it as a design failure in identity architecture, not a housekeeping issue.

Unified identity governance only works when ownership is explicit for non-human and agentic identities. Human IAM programmes usually assume a named person can be held accountable for access, but service accounts and AI agents often sit in ambiguous ownership chains. That ambiguity is where governance breaks down. The field needs identity ownership models that make lifecycle decisions auditable across business, platform, and security teams.

Continuous visibility is the named concept that now separates modern governance from legacy IGA. Visibility is no longer just reporting. It is the ability to see effective access, excess permission, and privilege drift as they emerge across heterogeneous identity populations. Without that, access reviews become retrospective paperwork instead of control enforcement. Practitioners should reframe governance maturity around live visibility and revocation speed.

From our research:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how identity failures compound once they are in the estate.
  • For broader lifecycle guidance, see NHI Lifecycle Management Guide for provisioning, rotation, and offboarding patterns that reduce persistence.

What this signals

Continuous visibility is the governance hinge for AI-era estates. Once the identity inventory includes applications, workloads, and agents, review cadence alone cannot keep up with entitlement drift. Teams should expect governance tooling, access reviews, and audit evidence to converge around real-time state rather than static certification snapshots.

The operational question is no longer whether identity governance can scale, but which identity populations need tighter lifecycle ownership first. Service accounts and automation identities usually deliver the fastest risk reduction because they combine persistence, weak attribution, and high privilege. That makes them the most practical starting point for programme redesign.

Practitioners should also expect board-level questions to shift from number of reviews completed to how much standing access has been removed. That is a healthier metric because it ties governance activity to blast-radius reduction, not just process volume.


For practitioners

  • Map all identity classes into one governance inventory Classify employees, contractors, service accounts, machine identities, and AI agents in the same inventory so ownership and review logic are consistent across the estate.
  • Prioritise standing privilege removal first Target the identities with persistent access that are hardest to monitor, especially application accounts, automation identities, and agentic workflows that keep privileges after task completion.
  • Shift high-risk access reviews to continuous evaluation Replace quarterly-only certification for fast-changing identities with continuous monitoring of effective access, entitlement drift, and revocation triggers.
  • Define lifecycle ownership for non-human identities Assign business and technical owners to every service account, workload identity, and AI agent so offboarding, rotation, and access changes can be executed without ambiguity.
  • Tie governance reporting to blast-radius reduction Measure how much exposed access has been removed, not just how many reviews were completed, so governance outcomes reflect reduced risk rather than activity volume.

Key takeaways

  • Legacy access certification is too slow for estates that now include service accounts, machine identities, and AI agents.
  • Standing privilege and weak lifecycle ownership are the main reasons identity risk persists across modern environments.
  • The winning governance model is continuous visibility, explicit ownership, and faster revocation of excess access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Secrets and Credential ManagementContinuous governance depends on controlling non-human access paths and excess privilege.
Recommendation — Inventory non-human credentials and enforce revocation when ownership or purpose changes.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsThe article centers on access permissions across human and non-human identities.
Recommendation — Apply PR.AC-4 to review and tighten access permissions across all identity classes.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeStanding privilege is the core governance failure this announcement addresses.
Recommendation — Use AC-6 to reduce excess access and remove persistent privilege from high-risk identities.
NIST Zero Trust (SP 800-207)Section 4 — Zero Trust principlesContinuous verification and adaptive control align with the article's governance model.
Recommendation — Apply Zero Trust principles to verify access continuously instead of relying on periodic certification.
CIS Controls v8CIS-5 — Account ManagementUnified governance for human and non-human accounts maps directly to account lifecycle control.
Recommendation — Use CIS Control 5 to track, review, and retire accounts that no longer have a valid owner or purpose.

Key terms

  • Continuous governance: An identity governance model that checks and enforces policy as activity happens rather than on a schedule. It is designed to catch drift, misuse, and orphaned access while the identity is still active, which matters when risk unfolds in minutes instead of review cycles.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
  • Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.

What's in the full announcement

Oleria Security's full announcement covers the operational detail this post intentionally leaves for the source:

  • How the partnership packages advisory, implementation, integration, and managed services for identity modernisation.
  • The specific ways the platform claims to automate access reviews and identity lifecycle processes across human and non-human identities.
  • The product framing around continuous, AI-driven governance and how Oleria describes removal of standing privilege.
  • The customer-facing messaging on compliance, cyber resilience, and support for AI agents and future digital initiatives.

👉 The full Oleria Security announcement covers the partnership scope, governance model, and customer-facing capabilities in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org