TL;DR: NHIs outnumber human users 45:1 in large enterprises, and Saviynt argues that human-centric IGA breaks down when AI agents and non-human identities operate continuously across business applications, cloud, and SaaS. The core issue is not just scale, but the collapse of joiner-mover-leaver assumptions when identities can appear, change, and disappear within minutes or hours.
At a glance
What this is: This is an analysis of why traditional identity governance fails when non-human and AI identities operate inside business applications at machine speed.
Why it matters: It matters because IAM, IGA, PAM, and application owners now need continuous governance for service accounts, AI agents, and human users under one model instead of separate, stale review processes.
By the numbers:
- NHIs outnumber human users 45:1 in large enterprises, and the gap is widening.
- Only 5.7% of organisations have full visibility into their service accounts.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
👉 Read Saviynt's analysis of governing NHI and AI identities inside business applications
Context
Non-human identity governance has become a business-application problem, not just an infrastructure problem. When service accounts, bots, and AI agents can act inside ERP, CRM, ITSM, and HR platforms, the old assumption that access changes track human employment events no longer holds. That creates a governance gap for NHI and AI identities that most IGA programmes were never designed to close.
Saviynt's article argues that these identities can operate continuously, inherit excess access, and keep privileges long after a task ends. The practical result is cross-application access accumulation, shadow AI discovery problems, and a growing audit gap between what the business thinks is governed and what is actually active.
For practitioners, the issue is not whether NHIs and AI agents belong in identity governance, but whether the governance model treats them as first-class identities. Continuous visibility, ownership, and revocation discipline become essential, and the Ultimate Guide to NHIs provides a useful lifecycle reference point for that shift.
Key questions
Q: How should security teams govern AI agents and NHIs differently?
A: Security teams should govern NHIs as predictable machine identities and AI agents as runtime actors that can alter behaviour after authentication. That means static entitlements, inventory, and rotation remain central for NHIs, while agents need behaviour monitoring, delegation tracing, and ownership controls that account for tool choice and execution timing.
Q: Why do NHIs make access review harder than human identity review?
A: NHIs often exist in more places than a human account and can be created or copied without a clear lifecycle record. Access review becomes harder because reviewers need context about purpose, owner, privilege scope, and where the credential is embedded. Without that context, the review is administrative rather than governance-driven.
Q: What breaks when identity governance is built only for human users?
A: Access review, joiner-mover-leaver processes, and periodic certification break down when the identity is a service account or autonomous agent. Those controls assume a visible human lifecycle and a stable review window. Machine identities and agents can outlive those assumptions, leaving access active after the programme believes it has been governed.
Q: Who should be accountable for AI identity governance?
A: Accountability should sit with the team that owns the workflow and the team that owns identity controls, because AI access crosses both domains. Security, platform, and application owners each hold part of the lifecycle, but one business owner must remain responsible for the access decision and its removal.
Technical breakdown
Why human-centric IGA fails for NHI and AI identities
Traditional IGA assumes stable human roles, visible employment events, and review windows that align with joiner-mover-leaver processes. NHIs and AI agents do not behave that way. They can be created automatically, delegated to other processes, or retired by software logic without a clear human owner. Once those identities are active inside business applications, quarterly or annual reviews are too slow to capture real exposure. The technical failure is not just volume, but the mismatch between review cadence and identity lifespan.
Practical implication: move from periodic attestation to continuous inventory and event-driven governance for every non-human and AI identity.
Cross-application privilege accumulation in SaaS and enterprise apps
When an identity touches SAP, Oracle, Salesforce, ServiceNow, and related services, access does not stay isolated. Permissions compound across platforms, creating effective privilege that is larger than any one application’s local role model. That makes segregation of duties analysis harder, because a benign entitlement in one system can become risky when combined with another. AI agents increase that problem because they can request or inherit access as they move between workflows, leaving a residual privilege trail that standard access reviews miss.
Practical implication: analyse entitlements as a cross-application graph, not as separate app-by-app approvals.
Continuous monitoring for shadow AI and autonomous workflow changes
Shadow AI appears when AI capability grows inside business applications without formal onboarding, ownership, or inventory. In practice, this means the identity estate expands faster than governance records, and approval workflows become informationally incomplete. Business processes may create or modify identities within minutes or hours, which makes stale certification data almost inevitable. The control problem is not only detection, but timely linkage between identity, task, owner, and business context so that excess access can be removed before it becomes embedded.
Practical implication: pair discovery with ownership assignment and automated remediation triggers for unknown or newly delegated identities.
NHI Mgmt Group analysis
Human-centric governance is the wrong operating model for NHI and AI identities. Joiner-mover-leaver controls were designed for people with employment records, managers, and predictable lifecycle events. That assumption fails when identities are created by workflow logic, delegated across systems, or retired without human action. The implication is that identity governance must stop treating non-human and AI actors as exceptions and begin treating them as primary governed subjects.
Cross-application privilege accumulation is the real governance blind spot. The risk is not just a single over-privileged account inside one application, but the way access compounds across SAP, Oracle, Salesforce, ServiceNow, and cloud services. That is where SoD violations emerge and where local review processes break down. Practitioners need a governance model that reasons over combined effective access, not isolated application entitlements.
Machine-speed identity lifecycles invalidate periodic certification. When identities can be created, modified, or retired within minutes or hours, quarterly review cycles are structurally behind the risk. That is not a tooling gap alone, but a timing mismatch between identity behaviour and governance cadence. The implication is that audit readiness and access review design have to change together.
Shadow AI makes the identity estate partly invisible by design. Some NHIs are known, but many emerge organically through automation and embedded AI functions inside business applications. This is where discovery, ownership, and lifecycle control become inseparable. A governed NHI programme has to assume that some identities will appear before policy does, and that continuous monitoring is the only way to recover control.
Identity-agnostic governance is now the only coherent model. The article’s central point is that the enterprise cannot maintain separate rule sets for humans, NHIs, and AI agents and expect consistent control outcomes. The better model is one governance layer with identity-specific lifecycle handling underneath it. That is the direction practitioners should use when maturing application access governance.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- The lifecycle problem is broader than visibility, so the Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs is the natural next reference.
What this signals
Cross-application governance is becoming the control plane for identity. Once NHIs and AI agents operate inside business applications, teams need inventory, ownership, and SoD analysis across the full path of access, not just the local system. That makes the difference between knowing an identity exists and knowing what it can actually do.
With 97% of NHIs carrying excessive privileges in our research, the central programme question is no longer whether to review access, but how to make reduction continuous. Periodic certification alone will not close that gap, especially when identities are delegated and repurposed inside automation chains.
The practical next step is to connect identity governance to operational resilience controls and audit evidence. Teams that align application access governance with the NIST Cybersecurity Framework 2.0 will be better placed to prove control effectiveness across human, non-human, and AI identities.
For practitioners
- Build a single governed inventory for humans, NHIs, and AI agents Map identities to business owners, application scope, and lifecycle status across ERP, CRM, ITSM, SaaS, cloud, and workflow tools. Use the Ultimate Guide to NHIs as a lifecycle reference for provisioning, rotation, and offboarding patterns.
- Replace calendar-based review cycles with event-driven certification triggers Trigger review when an identity is created, delegated, repurposed, or linked to a new application instead of waiting for quarterly recertification. Continuous review matters because the article describes identities that can change within minutes or hours.
- Analyze effective access across applications, not entitlement by entitlement Assess SoD risk by combining access across SAP, Oracle, Salesforce, ServiceNow, and connected services. Use cross-application visibility to find combinations that create hidden privilege even when each individual grant looks reasonable.
- Assign ownership before automation scales further Do not allow AI agents or service accounts to remain without a named business owner, technical custodian, and offboarding path. When ownership is missing, certification and remediation become procedural rather than real.
- Use external reference material to validate control design Compare your current posture against the NIST Cybersecurity Framework 2.0 and the NHI lifecycle guidance in the Ultimate Guide to NHIs so your control model aligns with both identity governance and operational resilience.
Key takeaways
- Human-centric governance breaks down when NHIs and AI agents operate continuously inside business applications.
- Enterprise risk increases because access compounds across applications, while periodic reviews remain too slow to catch it.
- Practitioners need identity-agnostic governance with continuous discovery, ownership, and revocation across the full application estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | The article focuses on governance gaps and visibility for non-human identities. |
| NIST CSF 2.0 | PR.AC-4 | Cross-application access and least-privilege governance map to access control management. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central to governing NHIs and AI identities across applications. |
| NIST Zero Trust (SP 800-207) | The article aligns with continuous verification and identity-agnostic governance. |
Use zero trust principles to verify identity state continuously rather than relying on periodic review.
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Cross-Application Access Accumulation: Cross-application access accumulation happens when separate permissions in multiple systems combine into a larger effective privilege than any single entitlement suggests. In practice, it creates hidden SoD risk, broader blast radius, and governance blind spots when identities move across business applications and cloud services.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Identity-agnostic governance: Identity-agnostic governance is an approach that applies one governance model across human users, NHIs, and AI agents while still respecting their different lifecycle behaviours. It keeps ownership, certification, monitoring, and revocation consistent so access decisions do not depend on whether the actor is a person or a machine.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- How the vendor maps human, non-human, and AI identities across business applications and workflow systems
- The control patterns it describes for continuous visibility, ownership assignment, and policy enforcement
- The application-access governance framing used to explain SoD risk across SAP, Oracle, Salesforce, ServiceNow, and Workday
- The vendor's view of how continuous monitoring fits into audit readiness and automation adoption
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org