By NHI Mgmt Group Editorial TeamBased on Zluri: “Manifesto for a New Era: Identity Governance for an AI-First World” (June 27, 2025)

TL;DR: As AI adoption expands machine identities, orphaned entitlements, and shadow IT, traditional IGA tools built around static HR directories can no longer answer who has access to what, according to Zluri. Static certification and rigid access models are giving way to visibility-led governance that is driven by actual usage rather than assumptions.


At a glance

What this is: This is an analysis of why AI-first identity governance is forcing organisations to move beyond legacy IGA, with Zluri saying static, directory-led models can no longer keep up with machine identities, shadow IT, and usage-driven access decisions.

Why it matters: IAM, IGA, and PAM teams need to understand that governance based on fixed HR records and periodic review is losing fidelity as non-human identities and cloud applications proliferate.

By the numbers:

  • Machine identities now outnumber human identities by 20:1 in 2025, according to Zluri.
  • Over 60% of IT resources in a typical organization now exist as either unmanaged or shadow IT, according to Zluri.

Context

AI-first identity governance is about governing access from actual usage and live discovery, not from static HR directories and fixed role assumptions. In this article, Zluri argues that the old IGA model fails because identity and application estates have become too dynamic to fit legacy certification and access modelling.

The governance gap is not only the growth of machine identities. It is also the widening mismatch between what organisations think exists, what users actually do, and what access persists after tools, roles, and teams change.

For IAM and IGA leaders, the core question shifts from whether access was assigned correctly at onboarding to whether the entitlement still reflects current usage, business context, and identity type.


Key questions

Q: How should IAM teams evaluate modern IGA platforms?

A: IAM teams should evaluate IGA platforms on governance coverage, evidence quality, and how well they handle different identity types. The key test is whether the platform can support consistent decisions across human access, machine identities, and delegated workflows without creating separate control models for each one.

Q: Why do legacy access certifications fail in cloud and SaaS environments?

A: They fail because reviewers are asked to approve or revoke access without the context needed to judge business need. When last use, frequency, and peer comparisons are absent, certification becomes a compliance exercise instead of a control that tests whether access is still justified.

Q: What breaks when identity governance stops at the primary directory?

A: Governance becomes partial because authentication is visible while effective permissions remain hidden inside non-native applications. That leaves teams unable to certify, recertify, or remove toxic access with confidence. The practical result is an identity programme that can prove who signed in, but not what authority they actually exercised.

Q: How do teams know whether usage-based governance is actually working?

A: They should look for shrinking dormant access, fewer blanket approvals, and more reviews that end with evidence-based revocation or re-scoping. If certifications still approve most access without examining activity, the governance model has not moved beyond the old assumption-driven pattern.


Technical breakdown

Why static identity data breaks in AI-first IGA

Traditional IGA was built around relatively stable human directories, where identity attributes and application memberships changed slowly enough to support periodic review. That model fails when identities include service accounts, tokens, certificates, and AI agents, because the access surface expands faster than directory updates can track. If governance depends on HR records and assigned entitlements alone, it misses the operational state of the identity estate. In practice, that creates a false sense of control: the system can certify what is recorded, but not what is actually being used.

Practical implication: Treat static identity attributes as incomplete inputs and add live usage telemetry before trusting access decisions.

How shadow IT and fragmented entitlements create governance blind spots

Modern SaaS and AI tool sprawl fragments entitlements across many applications, each with its own permission model. That matters because IGA only governs what it can discover and normalise, while shadow IT and short-lived tools often sit outside those boundaries. The result is not just missing inventory, but inconsistent role semantics, duplicated privileges, and dormant access that survives beyond the application’s useful life. In an AI-first environment, discovery is no longer a one-time control. It is a continuous requirement for governance to remain credible.

Practical implication: Continuously discover applications and entitlement structures instead of relying on point-in-time inventories.

Why certification fails when reviewers lack usage context

Access certification becomes weak when managers see only a user-to-app pairing and no signal about recency, frequency, or business relevance. Zluri’s argument is that this context gap drives rubber-stamping, because reviewers are forced to choose between approving everything or risking disruption they cannot evaluate. Usage-aware certification changes the decision basis from assumption to evidence. That does not eliminate governance judgment, but it makes the review defensible by showing whether access is active, dormant, or inconsistent with peer behaviour and role intent.

Practical implication: Attach last-use and activity evidence to certification workflows so reviewers can make revocation decisions with context.


NHI Mgmt Group analysis

AI-first governance exposes a visibility debt, not just a tooling gap. The problem is not that legacy IGA lacks features in the abstract. It is that the control model was designed for slower-moving identity estates, while machine identities, shadow IT, and short-lived AI applications now change faster than static governance can absorb. The implication is that governance must be anchored in live identity and application discovery, or it will certify an outdated picture of access.

Usage-driven governance is becoming the new trust signal for identity programmes. When entitlements are inferred from directories alone, organisations end up governing assignment rather than behaviour. Zluri’s core position is that actual usage is now the more reliable indicator of whether access still has business value. That shifts IGA from periodic permission review to evidence-based entitlement validation, which is a material change in how identity assurance is established.

Legacy certification processes create compliance theatre when context is missing. If reviewers cannot see last access, frequency of use, or comparable peer behaviour, certifications collapse into approval rituals. The article’s example of high approval rates without meaningful review shows how easily formal governance can mask residual privilege. Practitioners should read that as a warning that process completion is not the same as governance effectiveness.

Identity governance for AI-first environments must treat machine identities as first-class citizens. Certificates, keys, tokens, and AI agents are no longer peripheral exceptions to human IAM. They are now a dominant part of the access estate, which means lifecycle, discovery, and certification models have to scale across both human and non-human populations. The governance programme that only works for employees is already incomplete.

Activity data is becoming the named concept behind modern entitlement control. The article effectively defines a shift from assumption-based IGA to activity-based governance, where usage evidence drives modelling, review, and revocation. That concept matters because it gives teams a concrete way to describe the control gap between assigned access and real operational need. Practitioners should use that lens to rework entitlement decisions around observed behaviour rather than inherited structure.

From our research library:

What this signals

Activity-led entitlement control: The key shift in AI-first IGA is that access decisions need to be anchored in observed behaviour, not static directory data. When applications and identities change faster than review cycles, programme design has to prioritise discovery, telemetry, and entitlement validation over periodic paperwork.

Legacy IGA programmes should expect more pressure on certification quality as shadow IT and machine identities expand the number of entitlements that never pass through traditional review assumptions.

For governance teams, the signal is clear: if access review evidence does not include usage context, the programme is preserving compliance mechanics while weakening actual control.


For practitioners

  • Build usage-led access reviews Add last-access, frequency, and peer-usage context to recertification so reviewers can decide whether access is still needed.
  • Continuously discover identities and applications Expand inventory controls beyond HR directories to include shadow IT, SaaS sprawl, and machine identities that live outside traditional records.
  • Rebuild role models from activity evidence Use observed usage patterns to refine access roles and reduce inherited entitlements that no longer match how teams actually work.
  • Prioritise dormant entitlement remediation Target accounts and privileges that have not been used recently, especially where access survived role changes or application churn.

Key takeaways

  • Legacy IGA is struggling because static identity records cannot explain access in estates dominated by machine identities, AI tools, and shadow IT.
  • The article points to a measurable governance problem, including over 60% of IT resources living as unmanaged or shadow IT and machine identities outnumbering humans by 20:1.
  • Practitioners need to shift governance from assumption-based certification to usage-led discovery, review, and role design.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on excess and stale access across machine identities and AI tools.
NHI-09 — NHI ReuseLegacy IGA assumptions break when identities and entitlements are reused across tools and roles.
Recommendation — Reduce entitlement sprawl by reviewing non-human access for unnecessary scope and stale permissions. Trace reused identities and entitlements across applications before certifying access as current.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing who or what still needs access in a changing environment.
Recommendation — Align entitlement reviews to actual authorisations and remove access that no longer maps to current need.
CIS Controls v8CIS-5 — Account ManagementThe article describes account sprawl, dormant access, and governance gaps in account oversight.
Recommendation — Centralise account oversight so dormant or orphaned access can be identified and removed quickly.

Key terms

  • Coverage-based governance: A governance model that measures success by whether all access was reviewed, certified, or documented. It supports audit readiness, but it can miss risk reduction if every entitlement receives the same treatment regardless of consequence.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Entitlement Sprawl: The gradual accumulation of too many discrete permissions, often with overlapping access and unclear ownership. It makes access review noisy and offboarding fragile. Grouping entitlements into profiles is one way to reduce that sprawl, provided the groups are designed around real work patterns.
  • Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org