By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: VezaPublished January 6, 2026

TL;DR: Identity has moved from administrative plumbing to the enterprise control plane, with permissions metadata, authorization paths, and micro-certifications now defining where risk lives and how AI governance must scale, according to Veza. Incremental IAM, PAM, and IGA tuning is no longer enough; the governing assumption that access can be understood through directories and periodic reviews has collapsed.


At a glance

What this is: This is a Veza perspective on why identity, permissions metadata, and authorization paths now define enterprise risk and AI governance.

Why it matters: It matters because IAM, NHI, and PAM programmes now have to govern authorization at scale rather than rely on legacy directory-centric and review-centric models.

By the numbers:

👉 Read Veza's analysis of identity as the enterprise control plane for AI governance


Context

Identity security is shifting from a back-office control function to the mechanism that determines enterprise access, trust, and operational risk. In this article, the primary NHI and agentic AI message is that authorization, not login, is the real control surface because modern business activity happens through permissions, entitlements, and access chaining across systems.

That framing matters for IAM practitioners because the old model of governing users, groups, and periodic reviews no longer matches how access is actually consumed. When AI agents and workloads act through chained permissions, the governance question becomes who or what can do what, when, and under which contextual conditions, not who authenticated at a directory boundary.

Veza’s starting point is consistent with a broader identity maturity shift: visibility is no longer enough unless it is tied to enforcement, context, and lifecycle decisions. The organisations that still treat identity as plumbing will miss the fact that identity is now the enterprise control plane.


Key questions

Q: How should security teams govern access when permissions and usage do not match?

A: Treat the mismatch as a risk signal, not a reporting issue. If an identity has access it never uses, or uses in ways that do not match the role or workflow, review the business justification, reduce standing privilege, and add monitoring for reactivation. The point is to govern actual behaviour, not preserve theoretical entitlement.

Q: Why do periodic access reviews struggle in AI-heavy environments?

A: Because risk changes faster than the review cycle. AI-driven workflows, automation, and service accounts can gain, reuse, or accumulate access continuously, while periodic reviews only capture a moment in time. That creates a gap between what was approved and what is actually being used. Continuous monitoring closes that gap better than certification alone.

Q: What do IAM teams get wrong about visibility into non-human identities?

A: They often stop at discovery. Seeing service accounts, tokens, and workload identities is useful, but visibility alone does not tell you whether the identity is over-privileged, still needed, or properly offboarded. The control objective is not just to count identities, but to prove that each one has an owner, a purpose, and an expiry path.

Q: How do PAM and IGA need to change in the agentic AI era?

A: They need a shared authorization model that treats agent access as governed entitlement, not a special-case exception. PAM should control the highest-risk paths, while IGA should certify the underlying permissions graph that makes those paths possible. Without that alignment, the controls will describe different versions of the same risk.


Technical breakdown

Permissions metadata as the control surface for authorization

Permissions metadata is the structured record of what an identity can do across applications, cloud platforms, and data systems. Unlike directory data, which mainly tells you who exists, permissions metadata exposes actual entitlement paths, inherited access, and latent exposure. That distinction matters because risk is usually expressed through authorization, not simply authentication. In practice, the modern identity problem is less about listing accounts and more about understanding how access is assembled, delegated, and accumulated across systems.

Practical implication: Practitioners need to inventory authorization data as a first-class asset and use it to drive reviews, detection, and remediation.

Micro-certifications and continuous justification

Micro-certifications are short, contextual trust assertions that validate access at the point of use rather than at long review intervals. They shift governance from periodic certification to ongoing justification, which is important in environments where permissions change quickly and exposure windows are short. This is not just a process tweak. It changes the unit of trust from an identity object to a permission decision, which is closer to how real operational risk behaves in cloud and AI-enabled environments.

Practical implication: Teams should treat access justification as a runtime control and tie it to the permissions most likely to create blast radius.

Why AI governance depends on an authorization-aware control plane

AI agents do not behave like classic human users because they operate through access chaining rather than interactive login events. That means an AI governance layer built only around identities and sign-ins will miss the paths that matter most. An authorization-aware control plane can evaluate what an agent can reach, how access was inherited, and where it can cascade into downstream actions. Without that view, governance becomes policy theatre because the decision point sits too far upstream from the actual risk.

Practical implication: Security teams should align AI governance with entitlement graphs and access paths, not just model inventories or authentication controls.


Threat narrative

Attacker objective: The objective is to turn latent access paths into unauthorized business actions, data exposure, or AI-driven policy bypass at enterprise scale.

  1. Entry occurs through excessive authorization exposure rather than direct compromise of the identity layer, because access paths already exist across systems and services.
  2. Escalation happens when permissions chaining allows the actor to move from one entitlement to another without a fresh governance decision at each step.
  3. Impact follows when over-permissioned access enables actions the business did not intend, turning hidden authorization breadth into operational and security risk.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity has become the enterprise control plane, not a support function. The article is right to reject the old assumption that identity is mainly about directories and login events. Modern risk lives in permissions metadata, authorization paths, and contextual trust decisions, which means IAM, PAM, and IGA have to operate as one control system rather than separate silos. The practitioner implication is clear: if you cannot govern authorization, you cannot claim to govern identity.

Micro-certification is the right lens for replacing periodic trust with bounded access decisions. Periodic review models assume access changes slowly enough to certify after the fact. That assumption weakens in cloud, SaaS, NHI, and AI environments where permissions can be inherited, chained, and consumed quickly. The implication is that access review programmes need to move toward continuous justification and context-rich decisioning, or they will certify stale reality.

Authorization paths are the real blast radius in the agentic AI era. AI agents operate through access chaining, which makes their effective reach wider than any static role description suggests. This is where the named concept of authorization-aware control plane becomes useful: it describes a governance model that understands not just who has access, but how access can compound across systems. Practitioners should treat entitlement graphs as operational security infrastructure, not reporting material.

Traditional IAM maturity models understate the governance gap created by fragmented visibility. The article correctly points to graph architectures because relational context is what reveals exposure across systems. That is the right direction for NHI and human IAM alike, but especially for workloads and AI-driven access patterns where the interesting question is not account presence, but reachable action. The practitioner takeaway is to rebuild governance around relationships, not records.

Identity programmes now need to prove risk reduction, not administrative completeness. If identity is the control plane, then the useful question is whether the programme can explain and constrain enterprise access in operational terms. That raises the bar for IAM leads, PAM teams, and IGA owners: the value test is whether the organisation can see exposure, justify access, and intervene before access becomes impact. The implication is that identity strategy must be measured against business risk, not process volume.

From our research:

What this signals

authorization-aware control plane: identity programmes are moving toward graphs, contextual decisions, and continuously evaluated permissions rather than static directory records. For practitioners, the near-term implication is that recertification, PAM, and AI governance will need to share the same entitlement model or they will keep producing inconsistent answers about risk.

With 85% of organisations lacking full visibility into third-party vendors connected via OAuth apps, the governance problem is already wider than most access review programmes assume, according to The State of Non-Human Identity Security. Teams should expect pressure to tie visibility to action, because discovery without remediation will not satisfy boards or auditors.

Identity control will increasingly be judged by whether it can explain effective access across human, machine, and AI-driven actors. That makes lifecycle governance, authorization graphs, and runtime justification the practical boundary between mature identity programmes and reporting layers that look comprehensive but leave exposure untouched.


For practitioners

  • Build an authorization inventory, not just an account inventory Map who can do what across systems, then classify inherited, delegated, and chained permissions separately from directory objects. Use that inventory to surface where access is broadest, most opaque, or least justifiable.
  • Shift recertification toward micro-certification Apply shorter, context-bound access justification to sensitive entitlements and high-blast-radius permissions. Focus first on access paths that are reused across cloud, SaaS, and AI-enabled workflows.
  • Use graph context to find hidden exposure Model access relationships so teams can see how one permission opens another across systems. Combine that graph with review workflows so findings translate into removal, not just visibility.
  • Treat AI governance as entitlement governance Evaluate agent access through the same control plane used for workloads and privileged identities. Require every agent path to show what it can reach, how it inherited that reach, and where humans remain accountable.
  • Align PAM and IGA on the same authorization data Stop letting privileged access decisions and certification campaigns run from different datasets. Build one permission source of truth for review, enforcement, and exception handling.

Key takeaways

  • Identity is now the enterprise control plane, and the real risk sits in permissions metadata and authorization paths.
  • Legacy IAM, PAM, and IGA models are too account-centric for cloud, NHI, and AI governance, where access chains matter more than directory records.
  • Practitioners need graph-based visibility, micro-certification, and shared authorization data if they want governance to reduce risk instead of documenting it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The post centres on visibility, authorization paths, and governance gaps for non-human access.
NIST CSF 2.0PR.AC-4Access permissions management is the core governance theme in this article.
NIST Zero Trust (SP 800-207)3.1Zero Trust principles support continuous verification of contextual access decisions.
NIST SP 800-53 Rev 5AC-6Least privilege is central to the article's discussion of authorization control.

Tie identity review and enforcement to PR.AC-4 so access remains least privilege over time.


Key terms

  • Authorization-aware control plane: An identity governance model that evaluates what an identity can actually do across systems, rather than relying on directory records or sign-in events. It ties access decisions to permissions metadata, entitlement paths, and contextual enforcement so risk can be managed where it appears operationally.
  • Permission Metadata: Structured labels attached to documents or records that describe who may access them and under what conditions. In AI retrieval systems, stale or incomplete permission metadata becomes a governance failure because the search layer may treat it as the source of truth for disclosure decisions.
  • Micro-certification: Micro-certification is a narrow access review or approval step used to validate a specific entitlement, action, or risk signal. It reduces review scope compared with full recertification, but it still needs clear ownership and documented decision criteria to remain trustworthy.
  • Authentication path: An authentication path is the route an identity uses to prove itself to a system, such as interactive login, LDAP bind, Kerberos ticket use, or service-to-service access. Many enterprises secure the credential but forget to govern every path that can still accept that identity.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • How Veza frames canonical authorization data as the foundation for identity transformation
  • The operational logic behind micro-certifications and why they differ from periodic access reviews
  • Why graph architectures matter for exposing chained permissions and hidden risk paths
  • How the article links identity governance to AI governance without reducing either to login-centric controls

👉 Veza's full article expands on permissions metadata, micro-certifications, and graph-based identity governance.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org