By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: SafePaaSPublished September 2, 2026

TL;DR: AI agents, service accounts and workloads are colliding with legacy IGA models built mainly for users and roles, while SafePaaS was named a Representative Vendor in Gartner’s 2026 Market Guide for Identity Governance and Administration. The real issue is not recognition itself, but that access governance now has to follow identities into runtime activity, ownership and business context.


At a glance

What this is: This is a SafePaaS announcement about Gartner recognition that also highlights a broader IGA gap: legacy identity platforms still struggle to govern humans, NHIs and AI agents together.

Why it matters: It matters because IAM teams now have to govern access decisions, ownership and transaction risk across identity types that behave very differently at runtime.

By the numbers:

👉 Read SafePaaS's announcement on Gartner recognition and AI-aware IGA


Context

Identity governance is no longer just about provisioning users into roles. Modern enterprises now run on a mix of employees, contractors, service accounts, workloads and AI agents, which means the control problem has shifted from simple account administration to continuous identity governance across multiple actor types.

Legacy IGA platforms were built to certify access, map roles and manage periodic reviews for human users. That model breaks down when the subject is a workload credential or an AI agent whose access, ownership and action history need to be understood in business context, not just as an entitlement record.

SafePaaS is using Gartner recognition to frame that gap, but the underlying issue is broader than one vendor. Identity teams need governance models that can connect entitlements to transactions, owners and risk signals without assuming every identity behaves like a person.


Key questions

Q: How should teams govern service accounts and AI agents in the same IGA programme?

A: Use a single governance model for ownership, review, and offboarding, but apply it to different identity lifecycles. Service accounts need clear technical owners and expiry rules, while AI agents also need controls for delegated scope and runtime behaviour. The goal is one inventory and one policy spine, not separate shadow processes.

Q: Why do legacy IGA tools struggle with non-human identities?

A: They were designed to certify roles and approvals for human users, not to interpret continuous machine activity, ownership or downstream business transactions. That leaves a gap between access being granted and access being understood in operational context.

Q: What signals show that identity governance is still too user-centric?

A: If your programme can certify access but cannot explain which workload, API, or agent executed a transaction, the model is still user-centric. A modern governance stack should connect identity, entitlement and runtime evidence.

Q: Should organisations prioritise continuous governance over quarterly access reviews?

A: For high-risk non-human identities and AI agents, yes. Quarterly reviews still matter for accountability, but they are too slow to catch access misuse that emerges during runtime, especially in cloud and SaaS environments.


Technical breakdown

Why legacy IGA struggles with AI agent and NHI governance

Traditional IGA centres on identities as records: who has what role, which entitlement was approved, and when access should be recertified. That works reasonably well for humans and periodic reviews, but it is weaker for NHIs and AI agents because those identities often operate continuously, across systems, and with business actions that matter more than static entitlements. Once access is granted, the governance question becomes what the identity actually did, not just whether the role exists. Business-context governance links identity activity to transactions, ownership and risk, which is the direction the market is moving toward.

Practical implication: Practitioners should test whether their current IGA stack can trace entitlements into runtime actions and business events, not just certify access on a schedule.

Federated identity architecture across human and non-human identities

A federated identity architecture connects multiple identity sources and entitlement stores into a single governance view. In practice, that is useful when human users sit alongside service accounts, workloads and AI agents, because the same enterprise needs visibility across clouds, SaaS and on-premises systems. The challenge is not federation alone. The challenge is whether the governance layer can normalise identity types that have different lifecycles, ownership models and risk profiles without flattening them into a single user-centric abstraction. If it cannot, important access paths remain invisible or unmanaged.

Practical implication: Security teams should validate whether federation gives them actionable identity context across all sources, or only a broader inventory of fragmented accounts.

Continuous governance versus periodic certification

Periodic access review was designed for a slower identity environment where entitlements changed less often and reviewers could assess them in batches. Continuous governance extends that model by tying identity control to ongoing activity, monitoring and business rules. For AI agents and NHIs, this matters because risk often appears after access is granted, when an identity begins interacting with data, workflows or downstream systems in ways a certification process would never catch. Continuous governance therefore shifts the control point from approval history to runtime behaviour and transaction context.

Practical implication: Teams should move high-risk identities into monitoring and transaction-aware controls instead of relying only on quarterly recertification.


NHI Mgmt Group analysis

Legacy IGA is increasingly a human-centric control plane in a mixed-actor environment. The core governance assumption behind older IGA models is that identities can be reviewed and controlled primarily as users and roles. That assumption weakens when service accounts, workloads and AI agents become first-class access holders with distinct lifecycles and different evidence trails. The implication is that identity governance now has to be designed around actor type, not just around entitlement records.

Business-context governance is becoming the real differentiator in identity programmes. The article’s strongest signal is not vendor recognition but the shift from static access approval to transaction-aware control. When access decisions are linked to business events, teams can evaluate whether an identity is acting within expected boundaries instead of merely checking whether it was provisioned correctly. That is where IGA stops being an administrative function and starts functioning as risk governance.

AI agent visibility changes the governance question from permission to accountability. If an organisation cannot see where AI agents operate, what they can access, who owns them or what actions they are taking, then access governance is incomplete by design. The same gap applies to NHIs that accumulate access faster than humans can review them. Practitioners should treat ownership and runtime accountability as core control data, not metadata.

Continuous governance is now the minimum viable response to mixed identity estates. Periodic reviews alone do not keep pace with cloud, SaaS and on-premises entitlements that can change without human intervention. The market is moving toward governance that is continuous, federated and business-aware because that is the only way to reduce blind spots across human and non-human identities. The practical conclusion is that recertification must be paired with runtime control and evidence correlation.

Named concept: identity-intelligence governance. The article points to a control model that links identity, entitlement, ownership and transaction context in one governance view. That concept matters because it moves IGA from compliance administration to operational decision support. Practitioners should measure whether their programme can answer not just who has access, but what that identity is doing and why it is allowed to do it.

From our research:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to the Ultimate Guide to NHIs.
  • For related guidance, see Top 10 NHI Issues for the control failures that most often drive exposure.

What this signals

Identity-intelligence governance: the market is moving toward governance that joins identity, entitlement, ownership and transaction data in one control view. For practitioners, that means IGA success will be measured less by certification completion and more by whether the programme can explain why a given identity was allowed to act.

SafePaaS is pointing at a wider programme shift that many teams will have to make anyway. If you cannot connect runtime activity back to the identity that performed it, then access reviews become a historical record rather than a control. For teams that rely on periodic certification, this is the moment to decide which identities need continuous oversight.

The strongest signal for IAM leaders is that mixed estates are now normal, not exceptional. Human access, NHI governance and AI agent oversight increasingly need to share the same operating model, with actor-specific controls layered into a common governance fabric.


For practitioners

  • Map governance by actor type Separate humans, service accounts, workloads and AI agents in your governance model so each identity type has its own lifecycle, review and ownership path.
  • Tie entitlements to business transactions Extend IGA controls so access can be evaluated against transaction context, not just role membership or approval history.
  • Audit ownership for non-human identities Require a named owner, purpose and review trigger for every service account, workload credential and AI agent before it is allowed to persist.
  • Add continuous monitoring to recertification Use ongoing activity signals to supplement periodic access reviews, especially for identities that can create business risk after access is granted.

Key takeaways

  • Legacy IGA is no longer sufficient when service accounts, workloads and AI agents sit alongside human users in the same access environment.
  • The governance gap is not just visibility, but whether identity data can be tied to ownership, transactions and runtime behaviour.
  • Practitioners should move toward actor-specific, continuous governance so certification, monitoring and accountability work across the full identity estate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on governance gaps across non-human identities.
Use OWASP-NHI to structure reviews of ownership, visibility and lifecycle controls for NHIs.
NIST CSF 2.0PR.AC-1Identity governance and access control align directly to access management outcomes.
Map mixed-identity governance to PR.AC-1 and verify access is managed by actor type.
NIST SP 800-53 Rev 5AC-6Least privilege and entitlement governance are central to the article.
Apply AC-6 to reduce excess access and enforce business-justified entitlements across identity types.
NIST Zero Trust (SP 800-207)The article’s continuous governance model supports zero trust access decisions.
Align identity governance with zero trust by verifying access continuously instead of relying on static trust.

Align identity governance with zero trust by verifying access continuously instead of relying on static trust.


Key terms

  • Identity-intelligence governance: A governance model that connects identity, entitlement, ownership and runtime activity in one decision framework. It goes beyond account administration by using business context and transaction evidence to judge whether access is appropriate and accountable.
  • Federated Identity: Federated identity lets one organisation trust an external identity provider so a user can access another service without creating a separate account. It simplifies access, but it also expands the trust relationship that must be monitored. Weak federation settings can turn a single compromise into cross-domain access.
  • Continuous governance: An identity governance model that checks and enforces policy as activity happens rather than on a schedule. It is designed to catch drift, misuse, and orphaned access while the identity is still active, which matters when risk unfolds in minutes instead of review cycles.
  • Actor-specific governance: Actor-specific governance is the practice of applying different control logic to human identities, non-human identities, and autonomous identities. The same programme can still be unified operationally, but access, lifecycle, and review requirements must remain distinct to avoid false consistency.

What's in the full article

SafePaaS's full announcement covers the operational detail this post intentionally leaves for the source:

  • The specific Gartner Market Guide context behind the Representative Vendor designation and the wording SafePaaS published around it.
  • The platform claims about federated identity architecture across cloud, SaaS and on-premises environments, including how it says identities and entitlements are connected.
  • The business-context governance approach SafePaaS describes for linking access to compliance, transaction monitoring and risk evaluation.
  • The vendor’s own explanation of onboarding human and non-human identities into legacy IGA environments.

👉 SafePaaS's full post covers the governance model, platform framing and Gartner context behind the announcement.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing identity security capability, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org