TL;DR: Enterprise identity governance must now cover human users, non-human service accounts, and autonomous AI agents, because periodic access reviews cannot keep pace with access that changes in real time, according to Oleria Security. The core issue is not just scale, but the collapse of assumptions behind legacy IGA when AI-driven identities widen the governance gap daily.
At a glance
What this is: This is a leadership transition post that uses Oleria Security’s AI-era identity governance message to argue that continuous control is replacing periodic access review models.
Why it matters: It matters because IAM, IGA, and PAM teams need governance patterns that work across humans, NHIs, and autonomous systems without assuming access stays static long enough for certification cycles.
👉 Read Oleria Security's analysis of identity governance in the age of AI
Context
Enterprise identity governance is no longer just a human access problem. As organizations add service accounts, API keys, tokens, certificates, and AI agents, the governance model has to account for identities that operate continuously and can change risk faster than a quarterly review cycle can detect.
Oleria Security’s leadership transition is a signal about where the category is heading: continuous, adaptive governance across human, non-human, and AI identities. The underlying issue is not whether access reviews exist, but whether the programme can see and control access as it changes across multiple actor types.
The keyword here is identity governance. Legacy IGA still tends to assume stable identities, scheduled certification, and human-paced decision-making, which is increasingly mismatched to NHI sprawl and autonomous runtime behaviour.
Key questions
Q: Should organisations use the same controls for humans, NHIs, and AI agents?
A: No. The control family may overlap, but the operating assumptions differ. Human identity controls focus on authentication and user context, while NHIs need lifecycle and credential governance, and AI agents require both NHI controls and runtime oversight for autonomous action. The correct model is shared governance with actor-specific enforcement.
Q: When should organisations prioritise posture management for NHIs and AI agents?
A: Prioritise it before large-scale deployment, not after incidents or budget reviews. If visibility is limited, excess privilege and stale credentials will accumulate faster than teams can remediate them. Baseline discovery and exposure mapping should come before expansion, because they reduce the size of the blind spot that attackers exploit.
Q: When should teams move from point-in-time governance to continuous access control?
A: They should move when critical access can change faster than a manual certification cycle can observe. That is common for service accounts, tokens, certificates, and AI-driven workflows. If the access decision can become outdated before the next review, the programme needs continuous evaluation, not another checklist.
Q: How should IAM teams govern human, non-human, and AI identities together?
A: Start by separating the identity types in policy, ownership, and review cadence, then define where controls can be shared and where they must remain distinct. Human users, service identities, and AI systems do not fail in the same way, so the governance model has to preserve that difference while still producing one audit trail.
Technical breakdown
Why continuous identity governance is replacing periodic certification
Continuous identity governance means evaluating access when it changes rather than waiting for a scheduled review cycle. In practice, that shifts the control point from point-in-time attestation to ongoing entitlement evaluation, risk flagging, and privilege removal. This matters because human users, NHIs, and AI-driven identities can all accumulate access faster than manual review can keep up. The architectural change is less about a single feature and more about moving governance closer to runtime so the decision reflects current state, not last quarter’s snapshot.
Practical implication: replace review-only workflows with event-driven access evaluation for critical identities and high-risk privileges.
How standing privilege behaves across NHI and AI agent identities
Standing privilege is access that remains available after the immediate task is complete. For service accounts and API credentials, that creates persistent blast radius; for AI agents, it can also create uncontrolled action scope if access is broad enough to be reused across sessions. The governance problem is not just excess privilege, but the assumption that access can safely remain resident until someone notices. Once identities act faster than human review, persistent permissions become a structural weakness rather than a convenience.
Practical implication: identify long-lived credentials and broad entitlements first, then reduce them to task-scoped access where the business process allows it.
Adaptive identity governance across human, non-human, and AI identities
Adaptive governance is a control model that adjusts to identity context rather than applying one static policy to every subject. That distinction matters because a human, a service account, and an autonomous AI agent do not move through the same lifecycle or generate the same assurance evidence. Human IAM relies on user verification and access appropriateness, NHI governance depends on credential lifecycle and ownership, and autonomous actors add runtime decision risk. A single operating model can span all three, but only if it distinguishes actor type and governance tempo.
Practical implication: classify identities by actor type before applying lifecycle, access review, and privilege controls.
Threat narrative
Attacker objective: The objective is to preserve high-value access long enough to move laterally, amplify control, or operate unseen across enterprise systems.
- Entry occurs when organizations assign broad or inherited access to identities that were never designed for continuous decision-making.
- Escalation happens when standing privilege and unattended credentials expand the effective reach of NHIs and AI agents beyond the task at hand.
- Impact follows when governance cannot see or revoke access quickly enough, leaving persistent excess privilege across systems and data.
Breaches seen in the wild
- Moltbook AI agent keys breach — Moltbook breach exposed 1.5M AI agent keys.
- Sisense breach — unauthorized GitLab access led to exfiltration of access tokens, API keys and certificates.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Continuous governance is becoming the minimum viable control model for modern identity estates. Periodic certification was built for stable human access, not for environments where NHIs and AI agents can change access state continuously. The governance question is no longer whether access can be reviewed, but whether the programme can observe and act on access before the risk becomes durable. Practitioners should treat static review cycles as incomplete for mixed identity estates.
Identity governance must now distinguish actor type before it can distinguish risk. A human user, a service account, and an autonomous AI agent all need different evidence, different lifecycle controls, and different revocation triggers. Collapsing them into a single access model creates blind spots that become operational failures. The practical conclusion is to build governance rules that are actor-aware, not just entitlement-aware.
Standing privilege is the governing flaw that legacy IGA repeatedly underestimates. When access persists between reviews, the programme is already assuming that human oversight will arrive before abuse. That assumption fails in NHI-heavy and agentic environments because access can be used, reused, and amplified without a corresponding governance event. The implication is that teams must rework privilege models around persistence, not just assignment.
AI-driven identity expands the gap between access assignment and access accountability. The article’s central message is that enterprises are entering a period where identity governance must operate at runtime, not retrospectively. That does not mean replacing human controls everywhere; it means recognising that autonomous or semi-autonomous access behaviours invalidate the cadence on which legacy certification depends. Practitioners should regard continuous control as an operating requirement, not an enhancement.
Adaptive governance is the right category framing, but only if it is tied to revocation speed and ownership clarity. Visibility without ownership does not reduce risk, and monitoring without removal authority only documents exposure. The strongest programmes will connect identity classification, entitlement drift, and privilege removal into a single control loop. Teams should judge their programme by how quickly they can move from detection to enforced change.
From our research:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- A separate finding from the same research shows that lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations.
- For a broader control view, Ultimate Guide to NHIs - Lifecycle Processes for Managing NHIs covers the lifecycle controls that make visibility actionable.
What this signals
Identity governance programmes will increasingly be judged on revocation speed, not just review coverage. Once access spans humans, NHIs, and autonomous systems, the key question becomes how quickly a team can identify and remove access that is no longer appropriate. That pushes governance closer to operations and makes ownership clarity as important as policy design.
Standing privilege debt: the longer access persists without revalidation, the more the enterprise accumulates identity exposure that looks legitimate until it fails. This is especially visible in service accounts, tokens, and AI-assisted workflows that outlive their original business purpose. Teams that already rely on the Ultimate Guide to NHIs - Lifecycle Processes for Managing NHIs should use that lifecycle model to define removal triggers, not just provisioning steps.
Programmes aligned to NIST Cybersecurity Framework 2.0 should map continuous identity governance to protect and detect functions, then make sure governance findings trigger enforceable action rather than another queue.
For practitioners
- Classify identities by actor type first Separate humans, service accounts, and AI agents in the identity catalogue so lifecycle, review, and privilege controls can reflect the subject being governed.
- Replace static certification with event-driven review Trigger access evaluation when entitlements change, credentials rotate, or AI-driven workflows alter scope rather than waiting for quarterly or annual recertification.
- Target standing privilege before broadening scope Map where access persists beyond task completion and reduce it through task-scoped permissions, tighter ownership, and explicit revocation paths.
- Link identity governance to removal authority Ensure the team that detects anomalous access can also revoke it, disable it, or force re-approval without waiting for a separate process.
Key takeaways
- Legacy access review cycles are too slow for identity estates that now include NHIs and AI agents.
- Standing privilege is the control problem that turns visibility gaps into durable exposure across mixed identity types.
- Identity governance now has to be actor-aware, lifecycle-aware, and fast enough to remove access as quickly as it appears.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centers on lifecycle and visibility gaps in non-human identity governance. |
| NIST CSF 2.0 | PR.AC-4 | Continuous governance depends on managing access permissions as identity state changes. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to reducing standing access across humans, NHIs, and AI identities. |
| NIST Zero Trust (SP 800-207) | Section 3.1 | The article’s runtime governance theme aligns with continuous verification in Zero Trust. |
Map NHI ownership, rotation, and revocation to NHI-03 before extending governance to adjacent identity types.
Key terms
- Continuous Identity Governance: An operating model where access decisions, lifecycle changes, and risk signals are handled as an ongoing process rather than a periodic campaign. It uses authoritative events, telemetry, and policy automation to keep access aligned with current business and security conditions.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Actor Type: Actor type is the governance classification of the identity subject, such as human, non-human, or autonomous. The distinction matters because different actor types create different trust assumptions, lifecycle requirements, and access risks, even when they use similar credentials or access the same systems.
- Adaptive Governance: An identity control model that changes with the subject, the risk, and the runtime context instead of applying one static policy to every identity. In modern enterprises, adaptive governance is what allows control over access that changes too quickly for manual review to keep up.
What's in the full analysis
Oleria Security's full post covers the operational detail this post intentionally leaves for the source:
- The leadership transition context and the company’s positioning on AI-era identity governance.
- The full description of its adaptive governance model across human, non-human, and AI identities.
- The funding and enterprise adoption context behind the company’s current direction.
- The source article’s own framing of why continuous governance differs from periodic certification.
👉 Oleria Security's full post covers the leadership transition and the governance model behind it.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org