TL;DR: Enterprises often know who has access but cannot explain why, because approval history, policy versioning, exceptions, and business context are scattered across multiple systems, according to Oleria Security. Identity context graphs turn that trail into queryable governance data, which changes access review, incident response, and audit evidence.
At a glance
What this is: This is an analysis of identity context graphs and the finding that most enterprises can identify access entitlements but not the decision context behind them.
Why it matters: It matters because IAM, IGA, PAM, and NHI programmes fail when they cannot explain why access exists, who approved it, and whether the approval is still valid.
By the numbers:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
👉 Read Oleria Security's analysis of the identity context graph and access governance
Context
Identity context graphs address a basic governance gap: most enterprises can list access rights, but they cannot explain the decision trail behind those rights. In practice, that means approvals, policy versions, exceptions, and business justifications live in separate systems and are difficult to reconstruct when auditors, incident responders, or access reviewers need them.
For IAM and IGA teams, the issue is not just visibility but provenance. If a contractor, service account, or AI agent has access, practitioners need to know why it was granted, which policy allowed it, who approved it, and whether that approval still stands. That is the core identity governance problem the article is describing.
The same pattern applies across human identity, NHI, and emerging agentic access. The governance model breaks when decision context is trapped in tickets, chat messages, and expired policy documents instead of being attached to the identity itself.
Key questions
Q: How should security teams preserve the reason behind access grants?
A: They should store approvals, policy versions, exceptions, and business justifications as part of the identity record, not in separate workflow systems. That lets reviewers and responders trace an entitlement back to the decision that created it. Without that lineage, access can be visible but not explainable, which weakens audit, incident response, and recertification.
Q: Why do access reviews fail when entitlement data is incomplete?
A: Access reviews fail because certification only validates what is in the system of record. If ownership, application scope, or account mappings are stale, reviewers approve or revoke against a distorted picture. The result is process activity without real governance. Good certification programmes start with accurate entitlement data and clear accountability, not with more review cycles.
Q: What breaks when identity decisions are scattered across tickets and chat?
A: The governance trail becomes too fragmented to reconstruct reliably. Auditors cannot verify the rationale behind access, responders cannot quickly explain privilege paths, and reviewers cannot tell whether an exception was still valid. Fragmented evidence turns identity governance into manual forensics, which does not scale.
Q: Who is accountable when an access exception outlives its approver?
A: The owning identity governance process is accountable, because it failed to preserve the approval trail in a durable way. When approver authority changes, leaves, or expires, the organisation still needs a verifiable record of who granted the exception and under which policy. That record is what makes accountability testable.
Technical breakdown
Identity context graphs and access provenance
An identity context graph models identities, resources, policies, approvals, exceptions, and business rules as connected objects rather than disconnected records. The technical value is provenance: every entitlement can be traced back through the approval chain, policy version, and business justification that created it. That gives IGA and audit teams a way to traverse access history instead of reconstructing it manually from multiple systems. In practice, this is a graph problem, not a spreadsheet problem, because the relationship between nodes matters as much as the nodes themselves.
Practical implication: Practitioners should treat access provenance as a governed data model and not just a reporting output.
Why access reviews fail without decision context
Traditional access reviews usually present entitlements without the reasoning that produced them. Reviewers can see what access exists, but not whether it came from an exception, an inherited role, or a policy that has since been superseded. That makes certification weak because the reviewer is forced to guess at intent. A context graph changes the review unit from static entitlement to decision lineage, which is closer to how access is actually granted in enterprise environments.
Practical implication: Teams should redesign recertification workflows so reviewers see approvals, exceptions, and policy lineage together.
Why agentic access increases the value of context graphs
The article links context graphs to enterprise AI copilot and agentic access because autonomous systems can request and use access at machine speed. When identities include AI agents, the volume of decisions rises and the audit window narrows. A context graph becomes the memory layer that preserves why access was granted before the system changes again. Without that memory, identity governance becomes reactive and incomplete, especially when access is created, modified, or consumed faster than humans can review it.
Practical implication: Security teams should plan for machine-speed access decisions by preserving decision lineage at the moment of grant.
Threat narrative
Attacker objective: The attacker or insider seeks durable access that cannot be quickly challenged because the governance trail is too fragmented to verify.
- Entry occurs when access is granted through a role, exception, or approval chain that is spread across multiple systems and not centrally explainable.
- Escalation occurs when inherited entitlements, deprecated policy versions, or stale approver authority preserve access beyond the original business intent.
- Impact occurs when auditors, incident responders, or reviewers cannot reconstruct why access exists, slowing containment and allowing risky entitlements to persist.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Decision context is the missing identity control plane: Most identity programmes still optimise for entitlement visibility, not for the provenance of access decisions. That leaves a structural gap when auditors or responders need to answer why access exists, who approved it, and whether the approval is still valid. The practical conclusion is that governance data has to be attached to access as first-class evidence, not reconstructed later.
Access reviews without lineage are compliance theatre: A spreadsheet of entitlements is not the same as a governed decision trail. When reviewers cannot see the policy version, exception history, or approver authority behind a grant, certification becomes a guessing exercise. The practitioner implication is that recertification should be measured by decision quality, not by review completion.
Identity context graphs are becoming necessary for NHI governance: Service accounts, API keys, tokens, and certificates are often created through fragmented processes that outlive the people and policies that approved them. That creates a governance trail problem, not just a visibility problem. The practical conclusion is that NHI programmes need a durable record of why a credential exists, not only that it exists.
Context graphs will matter even more as autonomous access expands: AI agents and other autonomous systems increase the rate of access decisions while compressing the time available for human review. That does not merely add volume. It changes the governing assumption that access can be understood and challenged after the fact. Practitioners should expect identity governance to shift toward real-time decision lineage, especially where autonomous execution is present.
Decision trail opacity is the governance failure this model exposes: The enterprise assumption that access can be explained by looking across identity, policy, and ticketing systems breaks down when the evidence is split across disconnected tools. That assumption was designed for human-paced review cycles. The implication is that identity governance must treat decision provenance as a managed asset, or it will remain unable to prove why access exists.
From our research:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs is the natural next step for teams mapping ownership, rotation, and offboarding evidence.
What this signals
Decision provenance is becoming the governance layer that separates mature identity programmes from reporting-only ones: once access must be explained rather than merely listed, teams need durable lineage across identities, policies, and approvals. That is especially true for NHI estates, where a single missing ownership link can make a service account impossible to govern at scale.
With 71% of NHIs not rotated within recommended time frames, per Ultimate Guide to NHIs, the problem is not only stale credentials. The deeper issue is that organisations often cannot prove why the credential still exists, who owns it, or whether the original business case still applies.
Identity context graph: a governance model that treats access lineage as data, not as a manual search problem. Programmes that adopt this model will be better positioned to handle AI agent access, because machine-speed decisions require machine-readable evidence of why access was granted.
For practitioners
- Map access provenance across all approval systems Identify where approvals, exceptions, policy versions, and business justifications are stored today. Then define a single lineage view that links each entitlement back to its decision record so reviewers can see why access exists, not just that it exists.
- Redesign recertification around decision lineage Replace flat entitlement review lists with evidence that shows approver authority, policy version, exception status, and time since grant. Use that richer context to classify whether access is still valid, inherited, or stale.
- Preserve governance evidence for NHI lifecycles Attach creation rationale, ownership, expiry, and offboarding state to service accounts, API keys, tokens, and certificates. That makes it possible to prove why a non-human identity still exists and whether its access has outlived the business need.
- Prepare audit trails for agentic access volume If AI agents or other autonomous systems are entering your environment, capture decision context at the moment of grant. The practical goal is to ensure machine-speed access decisions remain traceable after the workflow has moved on.
Key takeaways
- Identity programmes fail when they can show access but cannot explain the decision trail behind it.
- The strongest governance use case for context graphs is not reporting, but reconstructing approvals, exceptions, and policy lineage.
- As AI agents and NHIs scale, decision provenance becomes a prerequisite for auditability, review quality, and accountable access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Decision lineage supports governance of NHI lifecycle and privilege drift. |
| NIST CSF 2.0 | GV.OV-01 | Identity governance needs oversight of access provenance and accountability. |
| NIST Zero Trust (SP 800-207) | Section 2.1 | Zero trust requires continuous verification of access decisions and context. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is hard to enforce without decision provenance and periodic review. |
Bind entitlement decisions to verified context rather than assuming standing access is justified.
Key terms
- Security Context Graph: A Security Context Graph is a relationship model that connects users, assets, identities, and behaviour so alerts can be judged against known organisational context. It helps investigators distinguish unusual activity from expected operations by adding ownership, access, and workflow information to raw telemetry.
- Decision Provenance: Decision provenance is the ability to explain what signals, data, and reasoning context led to a system’s choice. For autonomous or agentic systems, it is critical because review teams need to know not only what happened, but why the decision was made and where human authority still applies.
- Identity Lineage: Identity lineage is the traceable relationship between a human owner and the non-human identities that person creates, authorises, or depends on. It allows security teams to connect service accounts, API keys, tokens, and AI agents back to accountable ownership for review, audit, and retirement decisions.
- Approval Authority: The person or role empowered to grant a specific access request or exception under a stated policy. If the authority changes, expires, or leaves the organisation, prior approvals may remain visible but lose governance value unless their context is preserved.
What's in the full article
Oleria Security's full post covers the operational detail this post intentionally leaves for the source:
- How the identity context graph models identities, policies, approvals, and exceptions as traversable relationships.
- The access review workflow examples that show how reviewers use decision lineage instead of flat entitlement lists.
- The incident-response use case for reconstructing who approved access, when policy changed, and whether the approver still had authority.
- The AI copilot and autonomous access implications that require machine-readable governance evidence.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org