TL;DR: API-related breaches affected 57% of organisations over the past two years, and 73% of those reported three or more incidents, according to Apono. The pattern shows that governance built for human accounts is too slow and too static for cloud-native NHIs, where standing permissions and weak lifecycle control expand the attack surface.
At a glance
What this is: This analysis argues that identity and access governance designed around human users is not keeping pace with cloud-native NHI sprawl, where ephemeral services, tokens, and agents outnumber manual review cycles.
Why it matters: IAM and IGA teams need to treat non-human identities as first-class governed subjects because standing permissions, slow certification cycles, and fragmented visibility create avoidable attack surface across cloud programmes.
By the numbers:
- 57% of organisations experienced at least one API-related breach over the past two years, according to Apono.
- 73% of those organisations saw three or more incidents, according to Apono.
- Machine identities outnumber humans by over 80 to 1 in cloud-native environments, according to Apono.
Context
Identity and access governance is the discipline that decides whether access should exist, not just whether authentication works. In cloud-native environments, that question becomes harder because short-lived services, containers, tokens, and automation agents appear and disappear faster than many governance processes can review them.
The problem is not a lack of controls, but a control model built around stable human accounts. When NHIs carry long-lived credentials and broad entitlements, quarterly reviews and ticket-based approvals leave too much standing access in place for too long.
The article also ties the governance gap to compliance pressure, because auditors increasingly expect evidence that access is reviewed, scoped, and traceable across both human and non-human identities. That makes NHI oversight a governance requirement, not a specialised add-on.
Key questions
Q: What breaks when cloud-native access governance is built around human review cycles?
A: Periodic review breaks because many cloud-native identities are created and used faster than the governance cycle can certify them. When containers, tokens, or automation agents live for minutes, access review becomes retrospective paperwork instead of control. The result is standing privilege that remains active after its operational need has ended.
Q: Why do non-human identities make privileged access governance harder?
A: NHIs scale faster than human accounts and are often created for automation, integrations, and AI agents, which makes them easy to forget and hard to review. If they sit outside the main governance model, they can keep broad privileges long after the original use case changed. That creates hidden access risk.
Q: How do security teams know if cloud-native IGA is actually working?
A: Cloud-native IGA is working when every access grant has an owner, an expiry, a scope, and an audit trail that can be reconciled across clouds. If reviewers still need to stitch together console exports to answer who can reach sensitive systems, governance is not yet effective enough for ephemeral access.
Q: What should organisations do about NHI access after a cloud breach pattern emerges?
A: Organisations should immediately map which service accounts, tokens, and automation identities could have been used to reach the affected systems, then revoke any standing access that has no clear operational need. The priority is containment through credential scope reduction, because delayed offboarding leaves machine access reusable after the incident is discovered.
Technical breakdown
Why cloud-native identity churn breaks periodic access review
Cloud-native workloads often create credentials at runtime for containers, pods, serverless functions, and agents. Those identities may exist for minutes or hours, while access review cycles often run monthly or quarterly. IGA is designed to answer whether access is still appropriate, but if the identity vanishes before review, the control loses evidence and loses enforcement value. This is why short-lived identities create an audit blind spot even when policy looks strong on paper. Practical implication: move governance closer to issuance and expiry, not just recertification.
Practical implication: govern ephemeral access at creation time, because retrospective review misses the security window entirely.
Standing permissions, long-lived tokens, and NHI overprivilege
Non-human identities commonly authenticate with API keys, tokens, or service account credentials that persist far longer than the task they support. Overprivilege happens when those credentials inherit broad permissions or are reused across environments, which expands blast radius if one secret is exposed. The technical issue is not simply secret storage, but durable trust attached to credentials that were meant to support machine-to-machine execution. That pattern makes lateral movement easier once an attacker finds an exposed key or forgotten account. Practical implication: reduce credential lifetime and scope before an exposure becomes a full environment compromise.
Practical implication: eliminate durable NHI privilege and long-lived credentials that outlast the workload they were created for.
Why cloud-native IGA needs unified visibility across clouds
Cloud identity data is fragmented by design because AWS, Azure, GCP, and platform tooling each expose permissions differently. IGA programmes struggle when they must reconstruct who can do what from separate consoles, logs, and entitlement models. In practice, that means security teams cannot quickly prove least privilege, separate duties, or access accountability across the full estate. The governance failure is not only incomplete reporting, but inconsistent semantics across platforms. Practical implication: establish one governed view of entitlement state before auditors or attackers force the reconstruction exercise.
Practical implication: normalise entitlement data across clouds so governance decisions rest on one authoritative access picture.
Threat narrative
Attacker objective: The attacker seeks durable cloud access through non-human credentials so they can move from a single exposed identity into broader environment control and data exposure.
- Entry occurs through exposed API keys, static tokens, or overprivileged service accounts that were left outside normal human offboarding and review cycles.
- The attacker harvests credentials that were never rotated or certified, then uses them to access cloud workloads, CI/CD pipelines, or automation systems.
- Privilege is expanded through broad entitlements and reused machine access paths, allowing the attacker to move across environments or reset adjacent systems.
- Impact follows as access to internal data, infrastructure, or production workflows is abused before governance processes detect the misuse.
Breaches seen in the wild
- Massive Docker Hub Secrets Leak: 10,000+ Docker Hub container images expose hardcoded secrets and authentication keys.
- Secrets in Docker Hub images (RWTH Aachen study): A 2023 RWTH Aachen study found secrets in 8.5% of container images, and 275,269 internet hosts still using the leaked private keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
NHI governance is becoming the core test of cloud-native IGA maturity. Human-centric certification models can still work for stable employee accounts, but they do not fit identities that are created, used, and discarded by software. Once service accounts, tokens, and automation agents dominate access, governance must cover issuance, scope, expiry, and offboarding with the same seriousness once reserved for employees.
Standing permission is the wrong default for ephemeral infrastructure. Cloud-native environments assume speed, reuse, and orchestration, while traditional governance assumes stability and review windows. That mismatch creates access that exists longer than its business need, which is why blast radius grows even when teams believe they are operating under policy.
Access review processes assume access persists long enough to be reviewed; autonomous and ephemeral actors invalidate that assumption. That assumption was designed for persistent accounts and human-paced governance cycles. It fails when machine access appears and disappears inside the same operational window, leaving no meaningful certification artifact and forcing practitioners to rethink governance at issuance time.
Cloud-native IGA must treat non-human identities as first-class privileged subjects. The article’s examples show that machine identities are not peripheral assets, but the operational layer through which workloads, pipelines, and services actually run. Practitioners should stop treating NHIs as exceptions to the IGA model and start treating them as the model’s most exposed edge.
Auditability now depends on whether governance can keep pace with runtime identity change. Compliance frameworks may still ask for evidence after the fact, but cloud-native risk is determined before the review packet exists. The practical conclusion is that governance quality is increasingly measured by real-time entitlement control, not by the quality of retrospective reporting.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- 61% of organisations still define privileged users as humans only, overlooking the role of non-human identities in privileged access, according to KPMG.
- Read next: Ultimate Guide to NHIs
What this signals
Cloud-native governance now fails at the point where runtime identity becomes too fast for recertification. The practical change for IAM and IGA teams is to stop treating review as the primary control and start treating issuance, scope, and expiry as the control surface. That shift matters most where service accounts and automation identities can act with no human waiting point in the middle.
Machine identity volume is now large enough that broad human-only governance models misread the environment. According to the Ultimate Guide to NHIs, NHIs outnumber human identities by 25x to 50x in modern enterprises. That scale makes NHI inventory, ownership, and revocation core programme concerns rather than edge-case hygiene.
Cloud-native access programmes need one authoritative entitlement model across people and machines. If teams continue to separate human IAM, PAM, and NHI oversight into disconnected workflows, they will keep finding access after the fact instead of governing it in motion. The next maturity step is to unify certification, approval, and logging around the identity subject, not the tool boundary.
For practitioners
- Audit NHI standing permissions first Inventory service accounts, tokens, and automation identities with persistent access, then flag any credential that is not tied to a clear task window or ownership chain.
- Shift reviews to issuance time Move approval and entitlement checks into the request and provisioning flow so ephemeral identities are assessed before they become active workloads.
- Separate human and machine governance records Track non-human identities in a governed inventory that records owner, workload, scope, expiry, and revocation path instead of blending them into human access registers.
- Reduce cloud permission sprawl Trim broad roles across AWS, Azure, and GCP so machine identities receive the minimum actions needed for the shortest possible time.
- Standardise audit evidence across clouds Normalise entitlement exports and approval logs into one reporting layer so reviewers can prove who could access which systems without stitching together siloed console data.
Key takeaways
- Cloud-native identity governance fails when review cycles are slower than the lifecycle of the identities being governed.
- API-related breaches and machine identity sprawl show that standing access remains a practical attack path in modern cloud environments.
- The control that changes the outcome is not more retrospective certification, but tighter issuance, expiry, and entitlement scope for non-human identities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on machine identities with excessive permissions in cloud-native environments. |
| NHI-07 — Long-Lived Secrets | Static API keys and long-lived tokens are a core governance failure described in the article. | |
| Recommendation — Reduce machine privilege scope and remove standing access from NHI accounts with broad entitlements. Shorten credential lifetime and rotate long-lived NHI secrets before they become durable backdoors. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle control is directly implicated by the article's discussion of static keys and rotation gaps. |
| Recommendation — Apply authenticator management to issue, rotate, and revoke NHI credentials on a governed schedule. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article focuses on whether access should exist and whether it is still appropriate. |
| Recommendation — Review permissions and authorizations continuously so cloud-native identities do not retain unnecessary access. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The breach patterns cited rely on exposed credentials and movement through overprivileged access paths. |
| Recommendation — Map exposed NHI credentials to credential-access and lateral-movement detections in cloud monitoring. | ||
Key terms
- Identity And Access Management: Identity and Access Management is the discipline of controlling who or what can access systems, data, and services. It covers identity lifecycle, authentication, authorization, provisioning, deprovisioning, and policy enforcement across users, devices, applications, and non-human identities, so access is granted only to approved entities under defined conditions.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org