By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SailPointPublished September 10, 2026

TL;DR: Relying on a primary directory for enterprise-wide security leaves entitlement decisions, non-native applications, and non-human identities under-governed, according to SailPoint. The real risk is not login failure but control drift across human and machine identities, where static reviews and SSO coverage cannot enforce least privilege or separation of duties.


At a glance

What this is: This is an argument for moving identity governance beyond directory-centric control to cover entitlements, non-native applications, and non-human identities.

Why it matters: It matters because IAM teams cannot govern what they cannot see, and blind spots in entitlement oversight directly weaken least privilege, certification, and audit readiness across human and machine identities.

By the numbers:

👉 Read SailPoint's analysis of identity governance beyond ecosystem silos


Context

Primary directory control is not the same as enterprise identity governance. A directory can prove that an account authenticated, but it often cannot tell IAM teams what that account can do inside non-native applications, which is where entitlement risk usually lives. For practitioners, the gap is not theoretical. It shows up when the organisation depends on SSO coverage while core business permissions remain outside governance.

The same blind spot becomes more serious as non-human identities, service accounts, API keys, tokens, certificates, and AI agents multiply across hybrid estates. If governance remains tied to account administration inside one ecosystem, identity programmes inherit a structural visibility problem rather than a tooling problem. That is why entitlement-aware control and lifecycle governance now matter across human and machine identity together.


Key questions

Q: What breaks when identity governance stops at the primary directory?

A: Governance becomes partial because authentication is visible while effective permissions remain hidden inside non-native applications. That leaves teams unable to certify, recertify, or remove toxic access with confidence. The practical result is an identity programme that can prove who signed in, but not what authority they actually exercised.

Q: Why do manual access reviews break down in hybrid identity environments?

A: Manual reviews break down because entitlements, roles, and activity are spread across too many systems for periodic certification to keep pace. Reviewers end up working from partial data, and the delay between risk creation and review leaves excessive access in place long enough to matter.

Q: How should organisations govern non-human identities across their environment?

A: Start by inventorying every machine identity, assigning a human owner, and tying each one to a business purpose. Then apply routine access review, least privilege, and revocation for stale accounts. NHIs should be governed as accountable identities, not as background infrastructure that can be left unmanaged.

Q: Should teams prioritise entitlement control over broader SSO coverage?

A: Yes, when the business risk sits in what users can do after login rather than whether they can authenticate. SSO helps with access entry, but entitlement control governs real authority, separation of duties, and auditability. Teams should prioritise the layer that reduces the highest residual risk first.


Technical breakdown

Why account governance leaves entitlement risk outside the control plane

Account governance focuses on whether an identity can sign in, not on the permissions it exercises after authentication. In non-native systems, the entitlement layer often lives outside the directory, so the organisation sees a valid account but not the effective access path, delegated role, or toxic combination of privileges. This is where certificate-style assurance and login-centric thinking diverge from governance. The problem is especially visible in applications where transactional rights, record modification, or approval authority sit below the directory layer.

Practical implication: move governance controls from account presence to entitlement visibility and review the permissions that actually drive business actions.

Why static certification cycles create governance velocity gaps

A review cycle captures access at a point in time, but entitlement usage changes continuously as roles shift, projects evolve, and exceptions accumulate. When governance depends on periodic recertification, privilege drift can build between cycles and the organisation ends up certifying yesterday’s access against today’s risk. That creates manual cleanup, poor role recommendations, and weaker separation of duties enforcement. The technical issue is not just scale. It is the mismatch between a static governance cadence and a dynamic entitlement graph.

Practical implication: align access reviews with live entitlement usage signals so certification reflects current privilege, not stale organisational charts.

How non-human identities expand the governance boundary

Service accounts, API keys, tokens, and AI agents are non-human identities, but they behave differently from employees because they are created for functions rather than people. Native platform tools usually manage them as local objects inside one ecosystem, which leaves cross-platform ownership, offboarding, and entitlement scope fragmented. That fragmentation matters because machine identities often outnumber people and can persist longer than the business process they support. Once governance stops at the directory boundary, these identities become part of the unmanaged attack surface.

Practical implication: extend identity governance to machine identities and tie each one to an owner, purpose, and revocation path.


Threat narrative

Attacker objective: The attacker objective is to use legitimate identity footholds and unmanaged entitlements to perform actions that the directory itself cannot constrain.

  1. Entry occurs through a valid directory-authenticated account that looks healthy to native tools but carries hidden permissions in a non-native application.
  2. Escalation occurs when excessive or stale entitlements let the user perform actions beyond intended scope, including transactional or record-level operations.
  3. Impact follows as over-privileged access enables fraud, data alteration, or separation-of-duties failure across the enterprise application estate.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Directory-centric security is not enterprise identity governance. A directory proves authentication, but it does not govern the effective authority an identity holds inside non-native systems. That distinction matters because the real control failure often sits below SSO, in entitlement structures that drive transactions, data changes, and approval authority. Practitioners should treat directory coverage as a starting point, not a governance endpoint.

Entitlement visibility is the control plane that account-centric models leave behind. When teams rely on account governance, they tend to miss the permissions that actually create risk, such as role inheritance, delegated admin, and toxic combinations across applications. This is why the post-SAML world still produces audit gaps. The governance problem is not login success, but authority that cannot be observed or certified at the right layer.

Governance velocity is now as important as governance scope. Static reviews are too slow for hybrid estates where access changes faster than certification cycles. Once privilege drift accumulates between reviews, organisations end up validating stale access instead of current business use. The implication is that modern IGA must operate continuously across human and non-human identities, not as a periodic cleanup exercise.

Non-human identities expose the weakest assumption in legacy identity programmes. The assumption that identities are mostly human, lifecycle-bound, and locally managed no longer holds when service accounts, API keys, tokens, and AI agents operate across distributed platforms. This is not just an NHI problem. It is a programme-design problem that spans human IAM, machine identity, and lifecycle governance in one control model. Practitioners should reframe identity governance as enterprise authority management, not directory administration.

Identity governance must now be ecosystem-agnostic by design. The market is moving toward control planes that can span legacy systems, cloud services, and machine identities without assuming one authoritative directory will provide full visibility. That shift does not eliminate native controls. It defines their boundary. Practitioners should expect governance architecture to become more federated, more entitlement-aware, and less tolerant of blind trust in platform-native account tooling.

From our research:

What this signals

Entitlement governance has become the real test of identity programme maturity. Teams that still measure coverage by directory reach will miss the control layer where toxic access, inherited privileges, and separation-of-duties conflicts actually appear. For a broader operating model, see NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls.

Machine identities now force lifecycle thinking into every IAM roadmap. Service accounts and API keys cannot be left outside owner assignment, revocation, and review processes if the organisation wants audit-ready governance. That is why the control boundary must extend beyond authentication into entitlement and offboarding discipline, especially across cloud and shadow AI environments.

Governance velocity is the named concept that should shape programme priorities now. The issue is not just whether governance exists, but whether it can keep up with entitlement change before review cycles fall behind. Practitioners should use the Ultimate Guide to NHIs , Why NHI Security Matters Now to frame urgency and the Top 10 NHI Issues to map the operational backlog.


For practitioners

  • Separate authentication from entitlement governance Use the directory for sign-in and conditional access, but place entitlement review, role analysis, and toxic access detection in a dedicated governance layer that can inspect non-native applications.
  • Inventory non-native application permissions Build an application-by-application map of effective rights, including delegated admin, transactional privileges, and role inheritance, so reviews target what users can actually do.
  • Replace static certification with usage-aware review Trigger recertification from live entitlement usage and peer-group signals instead of relying only on quarterly or annual campaigns driven by organisational charts.
  • Extend lifecycle controls to machine identities Assign owners, purpose, and revocation paths to service accounts, API keys, tokens, and certificates so offboarding and access review cover non-human identities as well as people.

Key takeaways

  • Directory coverage alone does not equal enterprise identity governance when entitlements remain hidden inside non-native systems.
  • Static certification cycles create governance drift because access changes faster than review processes can validate it.
  • Modern IAM programmes need entitlement-aware and lifecycle-aware controls for both human and non-human identities.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Inventory and VisibilityThe article centers on blind spots across service accounts, API keys, and AI agents.
Recommendation — Inventory all non-human identities and map where entitlement visibility stops at the directory boundary.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsThe core issue is misaligned permission governance across hybrid identity estates.
Recommendation — Apply PR.AC-4 to govern access permissions by entitlement, not by authentication status alone.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article argues for least-privilege enforcement across non-native systems and identity types.
Recommendation — Use AC-6 to reduce over-privileged access in application entitlements and delegated roles.
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle and access oversight are central to the governance gap described.
Recommendation — Apply CIS Control 5 to standardise account ownership, provisioning, review, and removal across systems.
NIST Zero Trust (SP 800-207)3.4 — Access DecisionsThe post challenges static trust in directory-level authentication and fixed access assumptions.
Recommendation — Use access decision logic that validates effective privilege, not just successful login events.

Key terms

  • Entitlement Governance: Entitlement governance is the discipline of deciding who or what should have access, for how long, and under what business justification. It spans human users, non-human identities, and automated workflows, making it a core control layer for SaaS, cloud infrastructure, and lifecycle management.
  • Governance Velocity: Governance velocity is the speed at which an identity programme can detect, review, and correct access changes before risk accumulates. It measures whether governance keeps pace with operational change, especially in hybrid estates where privileges drift between review cycles and static certifications become stale.
  • Non-Native Application: A non-native application is a system whose access and entitlement model is not managed by the organisation’s primary directory or platform-native tools. These systems often hide effective permissions behind local roles, delegated admin, or application-specific controls that require separate governance visibility.
  • Ecosystem-Agnostic Governance: Ecosystem-agnostic governance means identity control that follows the identity across platforms instead of stopping at one vendor boundary. It gives security teams one governance model for humans and machines, with ownership, review, and revocation that work across cloud, legacy, and shadow environments.

What's in the full article

SailPoint's full blog covers the operational detail this post intentionally leaves for the source:

  • Specific examples of how entitlement-aware governance replaces account-centric control in non-native applications
  • Operational guidance on handling hybrid identity landscapes across legacy systems, cloud platforms, and shadow AI
  • How continuous governance can reduce manual certification work and improve separation of duties enforcement
  • The article's full positioning on ecosystem-agnostic identity control across human and non-human identities

👉 SailPoint's full post covers entitlement visibility, governance velocity, and hybrid identity blind spots in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org