By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: P0 SecurityPublished June 9, 2025

TL;DR: Fragmented controls, patchworked tooling, and evolving risk across human and non-human access are shaping cloud identity as a 6-phase maturity model, with special attention to ephemeral workloads and AI agents, according to P0 Security. The useful lesson is that access strategy now has to be benchmarked as a spectrum, not a checklist, because governance failures show up differently by actor type.


At a glance

What this is: This is a cloud identity maturity field guide that maps a 6-phase model for human and non-human access and finds that modern production access is fragmented rather than linear.

Why it matters: It matters because IAM, IGA, PAM, and NHI teams need a common maturity language to prioritise controls across service accounts, workloads, and emerging AI agent access paths.

By the numbers:

👉 Read P0 Security's field guide on cloud identity maturity and access strategy


Context

Cloud identity maturity describes how far an organisation has moved from ad hoc access controls toward governed, reviewable, and least-privilege access across human users, service accounts, workloads, and AI-enabled systems. In this article, the core problem is not a missing control label, but the fact that production access is being managed through fragments of identity tooling that do not line up with how modern cloud systems actually run.

The guide treats identity maturity as a spectrum rather than a checklist because ephemeral workloads, multi-cloud dependencies, and emerging AI agent access patterns create different risks at different phases. That framing is useful for IAM and NHI programmes because it exposes where policy, visibility, and lifecycle governance are out of sync with operational reality.

For security teams, the practical issue is benchmarkability. If a team cannot describe where human access ends, where workload access begins, and how privileged non-human access is reviewed, then maturity claims are mostly narrative rather than measurable.


Key questions

Q: How should security teams measure identity security maturity across human and machine identities?

A: Security teams should measure maturity across governance, tooling, operating model, and talent, then test whether those controls cover both human and machine identities. A strong programme can describe ownership, review cadence, policy enforcement, and exception handling for each identity class. If those elements are inconsistent, the organisation has partial coverage rather than mature identity security.

Q: Why do ephemeral workloads complicate traditional IAM and access review processes?

A: Because the identity may exist for minutes or hours, while access review cycles operate on days or weeks. That means the key control point shifts from retrospective certification to runtime issuance, scope limitation, and immediate revocation. If the credential outlives the workload, the governance model is already behind.

Q: What do teams get wrong about cloud identity security?

A: Teams often assume that strong application security controls automatically neutralise the risk created by shared infrastructure. In reality, identity credentials are especially sensitive because once they are exposed, the attacker may not need to break the application at all. Security design has to account for the tenancy model, not only the user-facing controls.

Q: How can security teams know if cloud identity governance is actually working?

A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review. If teams still spend days reconstructing access state, governance is not operating continuously. Effective programmes can show current MFA coverage, role scope, and credential age on demand.


Technical breakdown

Why cloud identity maturity breaks in fragmented access environments

Cloud identity maturity fails when access is treated as a collection of separate workflows instead of one governed identity fabric. Human SSO, workload credentials, API keys, certificates, and agent access often sit in different tools, with different owners and different review cadences. That creates control gaps in visibility, rotation, offboarding, and privilege enforcement. A maturity model is useful only if it can compare these control states on the same scale and expose where access is still informal, persistent, or unreviewed.

Practical implication: map every production identity type to a single maturity baseline and expose where governance stops at tool boundaries.

What ephemeral workloads change in access governance

Ephemeral workloads shorten the useful lifetime of access, but they do not eliminate the governance problem. Instead, they shift it to credential issuance, runtime scope, and revocation timing. Traditional access models assume stable assets and longer-lived identities, which means they struggle when workloads appear and disappear faster than manual review cycles. In cloud environments, this is where least privilege becomes a runtime property, not just a provisioning decision.

Practical implication: align credential lifetime, scope, and revocation logic to workload duration rather than to static account ownership.

Why AI agents intensify identity maturity gaps

AI agents add a new access pattern because they can request tools, chain actions, and interact with data sources at runtime, which makes identity governance more dynamic than classic service-account management. Even when the agent is not fully autonomous, its access path can still expand faster than human review processes can track. That is why agent identity should be measured against the same maturity expectations as other non-human identities, with added scrutiny for delegated tool use and permission drift.

Practical implication: treat AI agent access as governed non-human identity, then test whether reviews, logs, and approvals still work at runtime.


Threat narrative

Attacker objective: The attacker objective is to convert identity fragmentation into durable access that expands operational blast radius and weakens detection.

  1. Entry occurs through fragmented cloud identity controls that leave service accounts, workload credentials, and agent access distributed across different systems.
  2. Escalation happens when persistent access, unclear ownership, or stale entitlements allow non-human identities to accumulate more privilege than intended.
  3. Impact follows as over-broad access, weak revocation, and poor visibility increase the chance of unauthorised actions, blast-radius expansion, and recovery delays.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Cloud identity maturity is now a cross-actor governance problem, not a human IAM problem with extra machine accounts attached. The field guide is useful because it frames access as a spectrum that spans users, service accounts, workloads, and AI-enabled systems. That matters for IAM leaders because lifecycle, review, and privilege controls only hold if the same governance language applies across all actor types.

Fragmented tooling is the real maturity gap, not the absence of another point product. When identity controls are split between human IAM, cloud policy, secrets handling, and runtime access checks, no single team can explain the full access path. The practical conclusion is that maturity programmes should measure coverage across actor type and control stage, not by how many tools are deployed.

Ephemeral workloads expose a lifecycle assumption that was built for stable identities. Joiner-mover-leaver, recertification, and access review processes were designed around access that persists long enough to be observed. That assumption weakens when the identity exists only briefly, so the governance problem shifts to runtime issuance, not retrospective cleanup. Practitioners should treat short-lived access as a lifecycle class of its own.

AI agents make the maturity curve harder to flatten because access intent can change mid-session. Even when an agent is bounded, the runtime combination of tools, data, and sequence can outpace static entitlement models. The implication is that organisations need a maturity model that can distinguish ordinary workload access from delegated decision-making, or they will misclassify risk and under-govern the agent layer.

Identity blast radius: the real maturity metric is how far one compromised or over-permitted identity can move before governance interrupts it. This guide points in that direction by showing that maturity is not just about control presence, but about control reach across fragmented cloud estates. For practitioners, the useful question is whether access is still expanding faster than review, rotation, and offboarding can contain it.

From our research:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
  • For a broader governance lens, the Ultimate Guide to NHIs explains why visibility, rotation, and offboarding must be treated as one lifecycle.

What this signals

Cloud identity programmes are moving from control inventory toward control coherence. The practical test is no longer whether a team has IAM, PAM, or secrets tooling, but whether those controls form a usable lifecycle for every identity class, including AI-enabled access paths.

Identity blast radius: when access paths span human users, workloads, and agents, the decisive question becomes how far one credential can travel before governance interrupts it. That shifts the programme from static policy design to measurable containment.

Teams that still measure maturity by platform coverage will miss the real gap, which is inconsistency between identity type, access lifetime, and revocation speed. The better benchmark is whether access remains explainable after the workload or session has already ended.


For practitioners

  • Build a single identity maturity baseline Score human, workload, service account, and agent access against the same phases so teams can compare visibility, review, and privilege state consistently.
  • Trace production access end to end Document where credentials are issued, where they are stored, how they are scoped, and who can revoke them across cloud and SaaS environments.
  • Separate ephemeral from persistent access Treat short-lived workload access as a distinct governance class and verify that revocation, logging, and owner assignment still function when the identity disappears quickly.
  • Map AI agent access to non-human controls Require runtime logs, permission boundaries, and approval points for agent-driven actions that touch tools, data, or privileged workflows, and review them with NHI oversight.
  • Use lifecycle reviews to expose fragmentation Run access reviews against real cloud identity paths rather than account lists, then remove any entitlement that cannot be tied to an owner, purpose, or expiry.

Key takeaways

  • Cloud identity maturity is failing where fragmented tools prevent teams from governing access as one lifecycle across humans, workloads, and agents.
  • The clearest evidence of the gap is weak visibility into service accounts and other non-human identities, which makes review and containment incomplete.
  • Practitioners should measure maturity by revocation speed, lifecycle coherence, and control reach, not by the number of tools deployed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The guide concerns NHI governance maturity and visibility gaps.
NIST CSF 2.0PR.AC-1Access provisioning and governance are central to the maturity model.
NIST Zero Trust (SP 800-207)3.1Zero trust assumptions are stressed by fragmented human and non-human access.

Map cloud identity phases to PR.AC-1 and verify that access is tied to governed identity state.


Key terms

  • Cloud Identity Maturity: Cloud identity maturity is the degree to which an organisation can govern access across human and non-human identities with consistent visibility, lifecycle control, and privilege management. It is measured by how well policies survive real operational conditions such as ephemeral workloads, distributed tooling, and delegated access paths.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Ephemeral Workload Identity: Ephemeral workload identity is a short-lived credential issued to a container, service, or agent for a specific task window. It reduces exposure by avoiding durable secrets on disk or in environment variables, which limits what an attacker can steal if runtime code is compromised.
  • Visibility Fragmentation: Visibility fragmentation is the condition where security telemetry exists, but only inside separate provider consoles or tools. In multi-cloud estates, it prevents teams from correlating one provider’s event with another’s and leaves lateral movement or drift hidden in plain sight.

What's in the full article

P0 Security's full field guide covers the operational maturity framework this post intentionally leaves at the strategy level:

  • Phase-by-phase maturity guidance for human and non-human access programmes
  • Patterns and traps that help teams benchmark where their cloud identity controls actually sit
  • Practical framing for prioritising access improvements across ephemeral workloads and AI agents
  • A structured model for communicating identity risk to CISOs and platform owners

👉 P0 Security's full guide provides the maturity model, patterns, and traps in more operational detail.

Deepen your knowledge

NHI governance, machine identity security, and workload identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org