By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: C1.aiPublished March 20, 2025

TL;DR: Identity programmes fail first at visibility, then at least privilege, and finally at runtime governance, with NHIs now outnumbering humans 20:1 and agentic AI set to intensify the problem, according to C1.ai. The real issue is that static access models cannot govern identities that proliferate faster than review, rotation, and offboarding cycles can keep pace.


At a glance

What this is: This is a C1.ai analysis of why modern identity security breaks down across users, non-human identities, and emerging agentic AI, with the key finding that visibility, least privilege, and runtime governance must mature together.

Why it matters: It matters because IAM, IGA, and PAM teams are being forced to govern more identities with less certainty, and the same lifecycle gaps now span humans, service accounts, and AI-driven access patterns.

By the numbers:

👉 Read C1.ai’s blog on solving modern identity governance gaps


Context

Identity security breaks down when organisations cannot see what identities exist, what they can access, and whether that access still makes sense. In practice, that means users, groups, service accounts, API tokens, certificates, and soon AI agents accumulate privileges faster than governance teams can review them.

The article’s crawl, walk, run model is really a maturity model for identity governance: first inventory, then baseline controls, then contextual automation. That progression is relevant to NHI, human IAM, and emerging agentic AI governance because each stage depends on the same core question: who or what has access, and under what authority?

C1.ai frames agentic AI as the next pressure test for identity programmes because it extends identity management beyond scheduled human workflows. That is not unusual anymore; it is becoming the normal failure mode for organisations that still rely on static access models.


Key questions

Q: How should security teams implement maturity-based identity governance for NHIs?

A: Start by defining maturity stages for visibility, lifecycle control, privilege management, and audit readiness. Then assign measurable controls to each stage, such as complete inventory coverage, automated offboarding, and review intervals for elevated access. The goal is not a static policy set but a repeatable operating model that reduces standing risk as identity volume grows.

Q: Why do least privilege programmes break down in real environments?

A: They usually break because access is copied, inherited, or left in place after a role change. Group sprawl and stale entitlements hide the real privilege state, so the programme looks controlled on paper while actual access keeps expanding in practice.

Q: What should organisations do before they automate access decisions?

A: They should make sure the underlying identity data is accurate, complete, and owned. Automation only improves governance when the access catalog, role model, and entitlement records are already trustworthy; otherwise it accelerates bad decisions instead of fixing them.

Q: What problem does ownership attribution solve for service accounts and API keys?

A: It closes the gap between exposure detection and accountable remediation. Many organisations can find the secret, but not the human who introduced it, maintains it, or can safely replace it. Ownership attribution gives security teams a practical way to assign action without relying on informal knowledge that disappears during staff changes.


Technical breakdown

Why identity inventory is the first control plane problem

Identity inventory is the starting point because governance cannot operate on unknown entities. In mature environments, inventory must cover human users, groups, service accounts, API tokens, certificates, and cloud roles in one record of truth. Without that baseline, access reviews become partial, least privilege becomes aspirational, and decommissioning is guesswork. The technical failure is not just missing assets but missing relationships between identities, entitlements, and business ownership. That is why identity governance platforms and NHI visibility controls are now inseparable from core IAM architecture.

Practical implication: build a complete identity catalog before expanding access review or automation programmes.

Why least privilege fails in group-based access models

Least privilege breaks when access is inherited through oversized groups, copied roles, or stale entitlements that no one revalidates. The problem is structural: organisations use groups as a shortcut to speed onboarding, but that same shortcut hides true privilege, slows offboarding, and makes entitlement drift hard to detect. In NHI environments the same pattern appears in service account sprawl and shared credentials, while in human IAM it shows up as role cloning and legacy access persistence. Once group logic becomes the control mechanism, policy intent and actual access diverge.

Practical implication: move from group dependency to role and attribute governance with recurring entitlement rationalisation.

How runtime governance changes access from static to contextual

Runtime governance shifts identity control from provisioning-time assumptions to active, policy-driven decisions. Just-in-time access, dynamic role adjustment, and automated separation-of-duties checks reduce standing privilege, but they only work when the governance layer can evaluate context continuously. That matters for both NHI and agentic AI because machine-paced access can change faster than human approval loops can react. The important architectural point is that runtime governance is not a replacement for inventory or baseline controls; it depends on them and extends them into the moment of access.

Practical implication: reserve runtime controls for high-risk access paths after visibility and entitlement baselines are already in place.


NHI Mgmt Group analysis

Identity visibility debt is the first governance failure. The article correctly starts with the reality that organisations cannot secure identities they cannot enumerate. That is the core identity visibility debt problem: unknown users, unknown NHIs, and unknown privilege relationships create blind spots that compound over time. In practice, this is why IAM, IGA, and NHI governance must share a single inventory baseline rather than separate tooling views.

Least privilege collapses when access is treated as a one-time event. Copying access from one employee to another, preserving group memberships after role change, and leaving service account entitlements untouched are all symptoms of the same governance flaw. The article’s point is that privilege creep is not a minor hygiene issue but a structural consequence of provisioning models that do not revisit actual use. Practitioners should treat entitlement rationalisation as a core control, not a cleanup exercise.

Ephemeral access bias: organisations increasingly need governance models that assume access must be proven at the moment of use, not merely approved at creation. That concept matters because static access approvals do not describe whether access is still appropriate hours or months later. For NHIs and AI-driven workflows, the relevant question is no longer just who requested access, but what operational condition justifies it right now.

Agentic AI turns lifecycle governance into a shared discipline. The article’s AI discussion is not about a new category of risk so much as a new acceleration of old governance failures. If organisations already struggle to offboard users, revoke API keys, and clean up dormant entitlements, they will struggle even more when software entities can act and re-enter workflows at runtime. The implication is that human IAM, NHI governance, and emerging agent governance now belong in one programme rather than parallel ones.

Risk-aware governance is where identity programmes mature. The strongest part of the crawl, walk, run model is the move from compliance-oriented controls to contextual automation. But automation only improves security when the underlying data is accurate and the access model is already rationalised. Practitioners should read this as a sequencing warning: automate last, after inventory and privilege cleanup have made decisions trustworthy.

From our research:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
  • That combination of scale and weak lifecycle control is why 52 NHI Breaches Analysis is the next resource to use when turning governance findings into breach patterns.

What this signals

Identity visibility debt will stay the dominant programme risk until organisations stop treating service accounts, tokens, and human accounts as separate governance queues. The operational question is not whether teams can inventory identities once, but whether they can keep that inventory current as access changes faster than review cycles.

A practical maturity signal is whether entitlement rationalisation happens before automation. When groups and role copies are still the main access model, just-in-time access and contextual policies tend to paper over the same upstream problems instead of fixing them. The better sequence is catalogue, clean up, then automate.

The article’s arc mirrors what the Ultimate Guide to NHIs has been showing for some time: lifecycle governance is now the common control plane across human IAM and NHI management, and the programme that unifies them will have the clearest path to measurable risk reduction.


For practitioners

  • Build a unified identity inventory Create a single source of record for users, groups, service accounts, API tokens, certificates, and cloud roles. Tie each identity to a business owner, system owner, and renewal or offboarding rule so the inventory supports governance, not just discovery.
  • Rationalise group-based access Review high-risk groups, shared roles, and copied entitlements to identify where access is inherited rather than intentionally assigned. Remove stale memberships and replace approval-by-copy with role-based or attribute-based access decisions where possible.
  • Separate baseline controls from runtime controls Use access reviews, role definitions, and onboarding guardrails to establish the baseline, then apply just-in-time access and contextual policy checks only where the risk justifies it. Do not use runtime automation to compensate for missing inventory or unclear ownership.
  • Extend lifecycle governance to NHIs Treat service account offboarding, API key revocation, and credential rotation as formal lifecycle events with owners and deadlines. If an identity can authenticate independently, it needs a documented joiner, mover, and leaver process.

Key takeaways

  • Identity governance fails first where organisations cannot see all identities and entitlements in one control plane.
  • Least privilege erodes when access is copied, inherited, and never revalidated across role changes and machine identities.
  • Programmes should sequence inventory, entitlement cleanup, and lifecycle control before relying on runtime automation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on inventory, visibility, and governance gaps across NHIs.
NIST CSF 2.0PR.AC-4Least privilege and access governance are central to the article’s control model.
NIST Zero Trust (SP 800-207)The article’s runtime governance model aligns with continuous verification principles.
NIST SP 800-53 Rev 5AC-2Account management is directly implicated by onboarding, offboarding, and entitlement cleanup.
NIST AI RMFGOVERNAgentic AI governance is mentioned as the next lifecycle challenge.

Use PR.AC-4 to rationalise entitlements and reduce standing access across users and machine identities.


Key terms

  • Identity visibility debt: The gap that appears when an organisation can list its assets but cannot reliably link them to owners, entitlements, or activity. It creates a false sense of control because inventory looks complete while access relationships remain hidden, stale, or unreviewed.
  • Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.
  • Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.
  • Lifecycle Offboarding: Lifecycle offboarding is the process of removing an identity when it is no longer needed or no longer under the original owner’s control. In NHI programmes, it applies to service accounts and integrations as well as people, and it is essential for preventing stale access from surviving ownership changes.

What's in the full article

C1.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The article’s end-to-end crawl, walk, run maturity framing for identity governance.
  • The vendor’s specific examples of how teams should sequence visibility, baseline controls, and runtime automation.
  • The product-oriented interpretation of contextual and automated governance for modern enterprise environments.
  • The article’s commentary on how agentic AI changes onboarding and offboarding expectations.

👉 C1.ai’s full post expands the crawl, walk, run model with practical examples of modern identity control.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org