TL;DR: Machine identities now outnumber human identities 109:1, and Linx Security cites research showing only 44% of organisations have policies to manage AI agents even as 92% say governance is critical. The governance gap is no longer theoretical: identity data, ownership, lifecycle, and least-privilege controls have to be redesigned for human, non-human, and agentic identities together.
At a glance
What this is: This analysis argues that identity governance has to move from periodic workforce reviews to continuous governance across human, non-human, and AI identities, with identity data, ownership, lifecycle, and least privilege as the foundation.
Why it matters: It matters because IAM, IGA, PAM, and identity architecture teams cannot govern today’s identity estate if service accounts, machine identities, and AI agents sit outside the same control plane as workforce identities.
By the numbers:
- Machine identities now outnumber human identities 109:1, according to Palo Alto Networks' 2026 Identity Security Landscape.
- Only 44% of respondents have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate versus 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
👉 Read Linx Security’s analysis of modern identity governance for human, NHI, and AI identities
Context
Identity governance is no longer just about workforce access reviews and joiner-mover-leaver workflows. The modern identity estate now includes service accounts, workloads, API keys, machine identities, and AI agents, many of which change outside HR systems and outside quarterly certification cycles.
That creates a basic governance problem: if identity data is fragmented, ownership is unclear, and lifecycle state is not explicit, every downstream IGA decision inherits the same blind spots. The article’s core point is that modern IGA has to start with identity context, then extend least privilege, automation, and governance coverage across all identity types.
For teams already dealing with NHI sprawl, the operational question is familiar. The controls only become credible when identities, accounts, entitlements, resources, and ownership are correlated into one governance model, not managed as disconnected inventories.
Key questions
Q: What breaks when IGA is not built on a central identity view?
A: Access review loses context when identities, roles, and entitlements are scattered across systems. Reviewers cannot reliably see who has access, why they have it, or whether it is still justified. That leads to weak certifications, delayed revocation, and poor audit evidence. A central identity view is the baseline for any governance model that needs to scale.
Q: How can teams govern machine identities and AI agents in access reviews?
A: Teams should assign ownership, define review cadence, and include machine identities and AI agents in the same certification logic as human access, but with role-appropriate approvers. If a non-human identity can act on sensitive data, it needs a lifecycle owner and a removal path just like any other privileged account.
Q: How do security teams know whether least privilege is actually working?
A: Least privilege is working when identities have narrowly scoped permissions, unused credentials are removed or quarantined, and repeated access reviews consistently shrink entitlements. A good signal is whether a compromised identity would be unable to move beyond one bounded workflow. If broad resource reach still exists, the control is not effective.
Q: Should organisations use AI for identity governance before they clean up data and policies?
A: No. AI should not be asked to decide access when identity records, entitlement labels, and policy rules are inconsistent. The better sequence is to normalise data, standardise approval criteria, and then apply AI to assist with scale, because automation amplifies the quality of the inputs it receives.
Technical breakdown
Why fragmented identity data breaks modern IGA
Modern IGA depends on correlating identities, accounts, entitlements, ownership, lifecycle state, and usage across HR, IdP, SaaS, cloud, and engineering systems. An entitlement by itself is just a record. Governance starts only when the organisation can connect that entitlement to the identity that holds it, the owner of the resource, the reason it exists, and whether it is still being used. When those sources are fragmented, certification, remediation, and policy enforcement all act on incomplete context. That is why identity graphs and authoritative source modelling matter more than another review workflow.
Practical implication: build a single identity context layer before expanding automation or certification volume.
How ownership and lifecycle models need to change for NHIs and AI agents
Traditional JML logic assumes a human lifecycle tied to employment events. NHIs and AI agents do not follow that pattern. A service account may live for the application, a workload identity may be ephemeral, an API credential may need expiry or rotation, and an AI agent may gain or lose integrations as a process evolves. That means governance has to separate administration from accountability and define ownership even when there is no manager in the HR sense. Without that, review outcomes remain informational instead of actionable.
Practical implication: assign explicit business ownership and lifecycle policy to every non-human identity, including AI agents.
Why least privilege must become a continuous state
Least privilege is not a point-in-time certification result. Access that was appropriate six months ago can become excessive as roles, projects, and applications change. Modern IGA therefore needs to detect stale, unused, excessive, or incompatible access continuously rather than waiting for a periodic review to surface it. That shift also changes SoD enforcement, because conflicting entitlements should be blocked before they are granted, not discovered months later in an audit cycle. The goal is a living access model, not a scheduled clean-up exercise.
Practical implication: prioritise continuous detection of privilege drift over periodic recertification alone.
NHI Mgmt Group analysis
Identity governance is now a multi-actor discipline, not a workforce-only process. The article’s strongest point is that IGA has to cover employees, service accounts, workloads, API keys, machine identities, and AI agents inside the same governance model. That is a structural change, not a feature update, because the old workforce-centric lifecycle no longer matches how access is created, changed, and retired. Practitioners should treat governance coverage as the control boundary, not the HR directory.
Ownership is the control that prevents governance from becoming theatre. The article is right to separate technical administration from accountability. When the person who can change permissions is not the person responsible for whether access is appropriate, review and remediation logic degrade quickly. The practical consequence is that every identity, including those without a traditional manager, needs a named owner and an explicit business purpose.
Least privilege has to be managed as a state, not validated as an event. The article correctly frames privilege drift as an ongoing condition created by role changes, project changes, and accumulated exceptions. That means periodic certifications alone cannot prove governance health. Teams need continuous signals that reveal when access has become stale, unused, or excessive, otherwise the certification process only documents drift after the fact.
Modern IGA should measure governance outcomes, not activity volume. A completed access review is not meaningful if nothing was removed, and a fast ticket closure is not meaningful if access remains live elsewhere. That principle matters across human, NHI, and AI identity programmes. The field should judge governance by reduced excessive access, faster remediation, and lower orphaned identity risk, not by the number of workflows executed.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- From our research: 71% of NHIs are not rotated within recommended time frames, according to the Ultimate Guide to NHIs.
- If you are rebuilding governance around non-human identities, the NHI Lifecycle Management Guide shows how visibility, rotation, and offboarding fit together.
What this signals
Identity governance programmes will be judged by coverage and outcomes, not review completion rates. As machine and agent identities continue to grow, boards will care less about how many certifications were run and more about whether excessive access was actually removed. Teams that still treat access reviews as the end state will struggle to prove governance value.
Ownership will become the differentiator between scalable governance and inventory sprawl. Without a named owner for service accounts, AI agents, and application-specific identities, remediation stays stuck in handoffs. That is why programmes need explicit accountability models before they try to scale automation across the identity estate.
With only 5.7% of organisations reporting full visibility into service accounts, the operational gap is already large enough to undermine continuous governance. Teams should expect the pressure to unify workforce, NHI, and AI identity controls to increase rather than fade.
For practitioners
- Correlate identity data before expanding governance automation Map identities, accounts, entitlements, ownership, and lifecycle state across HR, IdP, SaaS, cloud, and engineering sources before adding new certification or remediation workflows.
- Assign explicit owners to every non-human identity Create business ownership for service accounts, workload identities, API keys, and AI agents so access decisions and exception handling have a clear accountable party.
- Treat least privilege as a continuous control Continuously detect stale, unused, excessive, and incompatible access rather than relying only on quarterly reviews to catch privilege drift.
- Automate only deterministic governance decisions first Start with clear, repeatable cases such as terminations, expired temporary access, and obvious policy violations, then expand only after underlying identity data is reliable.
- Bring NHIs and AI agents into the same governance programme Apply the same lifecycle, ownership, and access review logic to machine identities and AI agents that you already use for workforce identities, then measure revocation and remediation outcomes.
Key takeaways
- The article’s core warning is that traditional IGA no longer matches the shape of the identity estate.
- Machine identities, service accounts, and AI agents need explicit ownership, lifecycle logic, and continuous privilege control, not workforce-only review cycles.
- Visibility into identity context is the prerequisite control, because automation built on fragmented data only accelerates bad governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory and Visibility | The article centres on identity visibility across service accounts and machine identities. |
| Recommendation — Inventory every non-human identity and connect each one to ownership, purpose, and lifecycle state. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorisations | Least-privilege governance is the article’s main control theme. |
| Recommendation — Review access permissions continuously and remove entitlement drift as soon as it appears. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The post argues that privilege should be maintained continuously, not checked periodically. |
| Recommendation — Apply least-privilege controls to all identity types and verify access remains justified over time. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article focuses on account ownership, lifecycle, and governance across identity populations. |
| Recommendation — Maintain complete account ownership records and retire accounts when their business purpose ends. | ||
| NIST Zero Trust (SP 800-207) | 3.5 — Continuous Verification of Trust | The article’s continuous governance model aligns with Zero Trust verification of access validity. |
| Recommendation — Reassess trust continuously instead of relying on one-time access approval or review. | ||
Key terms
- Identity Graph: An identity graph is a relationship map that connects identities, assets, data, and permissions so teams can see how access actually flows. In NHI programmes, it helps explain which agent is related to which owner, which system, and which policy boundary.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Least Privilege: A security principle requiring that every identity — human or non-human — is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
What's in the full article
Linx Security's full blog covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of how Linx structures identity graphs across HR, IdP, SaaS, cloud, and engineering sources.
- Examples of how the article sequences automation for terminations, expired access, and clearer policy violations.
- More detail on how Linx frames governance outcomes such as reduced excessive access and faster remediation.
- The article’s own guidance on when to expand modern IGA from workforce identities into NHIs and AI agents.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on September 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org