TL;DR: Identity sprawl, siloed IAM systems, and disconnected risk data leave organisations unable to see or control identity-based attack paths across human and machine identities in hybrid, multi-cloud environments, according to Axiad. The real shift is from product thinking to interoperable identity processes, where risk sharing and fabric-style integration become the operational baseline.
At a glance
What this is: This is an analysis of identity fabrics as an operating model for hybrid identity security, arguing that disconnected IAM tools, identity silos, and missing risk sharing leave organisations unable to govern identities coherently across environments.
Why it matters: It matters because IAM teams responsible for human, machine, and hybrid identity programmes need an interoperability strategy, not another point solution, if they want risk-aware control across the estate.
Context
Hybrid identity environments break when identity is managed as a set of separate products instead of a shared control plane. The article argues that identity sprawl, cloud fragmentation, and multiple IAM systems create blind spots that make risk hard to see and harder to act on.
For IAM programmes, the real issue is not whether each system authenticates users correctly, but whether the systems can share identity and risk data well enough to form one governance model. That is the operational gap identity fabrics are meant to close across human and machine identities.
Key questions
Q: How can teams reduce identity sprawl without losing operational speed?
A: Teams should automate provisioning and revocation, but only within a governance model that also includes periodic review, ownership assignment, and exception handling. Speed without lifecycle control creates more drift, not less. The balance is fast execution with evidence that access still serves a current business purpose.
Q: Why do siloed IAM systems make identity risk harder to manage?
A: Siloed IAM systems force each platform to interpret identity in isolation, which makes privilege review, risk scoring, and incident response inconsistent. A credential may look normal in one system while creating unacceptable exposure in another. When teams cannot share identity context across tools, they lose the ability to connect access, behaviour, and business impact in time to contain abuse.
Q: What signs show that an identity fabric is not actually working?
A: The clearest sign is that compromise information does not change access decisions outside the originating tool. If IAM, XDR, SIEM, and GRC teams still rely on separate views and manual handoffs, the fabric is not governing identity as one system.
Q: What should security teams do when IAM governance spans human and machine identities?
A: They should apply the same lifecycle discipline to both populations while preserving identity-specific review logic. That means ownership, offboarding, recertification, and entitlement scope must be defined consistently, even if the workflow steps differ between people and non-human identities.
Technical breakdown
Identity sprawl and siloed IAM systems
Identity sprawl is the accumulation of identities, privileges, and control points across multiple clouds, platforms, and business functions. In the article’s framing, the problem is not just volume. It is fragmentation: Microsoft IAM, cloud IAM, and PKI often operate as separate control islands, so no single system has a complete view of identity state or risk. That makes access decisions stale the moment they are made and leaves lateral movement paths hidden between systems. Identity fabrics respond by treating IAM as an interoperable process layer rather than a standalone product category.
Practical implication: map where identity data stops at system boundaries and identify which trust decisions are being made without shared risk context.
Risk data sharing as the fabric test
The article makes a clear architectural claim: a functioning identity fabric is proven by whether systems can share risk data, not by whether they sit under one vendor logo. That matters because identity risk is often discovered in one control plane but must be acted on in another, especially when human and machine identities coexist. Without shared signals, an organisation can detect compromise but fail to translate it into enforcement. The fabric model therefore depends on integration depth, semantic consistency, and the ability to pass identity state across IAM, XDR, SIEM, and SOAR layers.
Practical implication: test whether your identity stack can propagate risk context across tools before you treat it as a joined governance system.
Identity-first security and zero trust
Identity fabrics are presented as an identity-first extension of zero trust thinking. The key shift is that identity becomes the primary perimeter, so assurance is no longer limited to network location or device trust. Instead, access decisions depend on whether the identity, its privileges, and its risk context remain consistent across sessions and systems. This is especially relevant when machines, workloads, and cloud services are part of the same access ecosystem as people. In that model, the architecture must support continuous reassessment rather than static entitlement assumptions.
Practical implication: align zero trust controls with identity state changes, not just with authentication events at login.
Threat narrative
Attacker objective: The attacker aims to convert one compromised identity into broad, cross-system access by exploiting disconnected IAM controls and hidden privilege paths.
- Entry occurs through identity-based attacks such as phishing, credential stuffing, or social engineering when attackers target the weakest identity control in a fragmented environment.
- Credential reuse or over-privileged access then turns a single compromised identity into a broader foothold across disconnected systems and clouds.
- Escalation and lateral movement follow because siloed IAM platforms do not share enough risk data to constrain the attacker’s path in real time.
- Impact is expanded access to systems and assets that should have remained outside the compromised identity’s legitimate reach.
Breaches seen in the wild
- Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity fabrics are a governance model, not a product category. The article is right to reject the idea that any single platform can solve hybrid identity security, because the control problem is now distributed across clouds, applications, machines, and teams. What matters is whether identity state, risk, and enforcement can move together across the estate. For practitioners, that means the programme objective is interoperability of decisions, not consolidation of logos.
The real control gap is broken risk sharing between identity systems. Identity programmes fail when authentication, entitlement, and detection data live in separate tools that cannot inform one another quickly enough. That is why identity fabrics are less about adding another layer and more about making existing layers legible to each other. The practitioner implication is straightforward: if risk cannot traverse the stack, governance cannot either.
Hybrid identity is now a human and machine governance problem. The article correctly includes machines, workloads, endpoints, and cloud resources in the same identity conversation as employees and customers. That reflects the reality that identity-based attack paths do not respect organisational charts or technology boundaries. A useful concept here is identity blast radius: the amount of damage one compromised identity can create when identities are not governed as a connected fabric. Practitioners should judge every identity control by how much it reduces that blast radius.
Identity-first security is becoming the practical form of zero trust. Zero trust only works when identity is the anchor point for policy, telemetry, and enforcement across environments. In hybrid estates, the perimeter has already shifted from network edges to identity edges, so the discipline must shift with it. The implication for teams is that access policy, risk scoring, and system integration need to be designed as one operating model.
Identity fabrics expose the limits of product-centric IAM thinking. Large enterprises already live with multiple IAM systems, and the article shows why that reality cannot be managed by point solutions alone. Fabric thinking forces a move toward composable control, where interchangeable components still share a common language of risk and access. Practitioners should expect governance to become more process-led and less tool-led as the category matures.
What this signals
Identity fabric thinking changes the unit of governance. Instead of measuring success by how many tools are deployed, teams should measure whether identity state and risk can move across the estate without manual translation. That is the difference between a collection of systems and a functioning control model.
Identity blast radius: the most useful way to think about hybrid identity risk is by how far one compromised identity can travel before controls stop it. The smaller that radius, the more likely the programme can contain credential reuse, over-privilege, and hidden cross-cloud access paths.
Programme leaders should expect convergence work to touch IAM, detection, and governance simultaneously. If identity risk remains invisible to SOC and GRC stakeholders, the organisation is still operating with fragmented identity control rather than a fabric.
For practitioners
- Inventory identity control islands Catalogue every IAM, PKI, cloud identity, XDR, SIEM, and SOAR component that makes access decisions or holds identity risk data, then note where information stops moving between them.
- Test risk data propagation Verify that compromise signals generated in one system can change access decisions in another without manual translation or delayed ticket handling.
- Unify human and machine identity oversight Bring endpoints, workloads, servers, cloud machines, and human users into one identity-risk review model so the same governance language applies across all identity types.
- Prioritise integration over replacement Sequence upgrades so that new tools must interoperate with existing identity sources before they are accepted as part of the fabric.
- Connect IAM to SOC and GRC Ensure identity risk is visible to detection and governance teams, not only to operational IAM owners, so business impact is assessed alongside access control.
Key takeaways
- Identity sprawl across hybrid estates turns identity security into a coordination problem as much as a control problem.
- The article’s central claim is that identity fabrics work only when IAM, detection, and governance tools can share risk context.
- For practitioners, the priority is to reduce identity blast radius by making identity data and enforcement interoperable across the stack.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article highlights over-privileged accounts as a key cross-system attack path. |
| NHI-09 — NHI Reuse | Credential reuse is called out as a risk when identity silos cannot share context. | |
| Recommendation — Reduce standing privilege and review over-privileged identities across cloud and on-premises systems. Eliminate credential reuse risk by correlating identity state across systems before access is granted. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing entitlements across connected identity systems. |
| Recommendation — Use PR.AA-05 to align entitlements across IAM systems and keep authorisation decisions consistent. | ||
| NIST Zero Trust (SP 800-207) | Principle 1: All data sources and computing services are considered resources — Zero Trust architecture principle | The article frames identity as the last perimeter and ties fabric design to zero trust principles. |
| Recommendation — Design identity control paths so each system verifies trust continuously rather than assuming perimeter protection. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account management is central to reducing sprawl, reuse, and excess privilege across identity silos. |
| Recommendation — Apply CIS-5 to inventory accounts, remove stale access, and standardise account oversight across the environment. | ||
Key terms
- Identity Fabric: An identity fabric is a connected control model that shares context across governance, privileged access, and access management. It is not a product category. The aim is to make identity decisions coherent across the full lifecycle so ownership, privilege, and enforcement reinforce each other.
- Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Identity Silos: Identity silos are isolated identity systems that manage access independently and do not share policy or lifecycle signals cleanly. They create fragmented governance, duplicate administration, and inconsistent audit outcomes, especially in hybrid and multi-cloud environments.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org