TL;DR: Identity programmes can process millions of accounts and still leave critical applications, entitlements and non-human identities outside effective governance, according to SafePaaS. The real measure of scale is time to governance coverage across business boundaries, because administration that outpaces policy is not control.
At a glance
What this is: This is an analysis of why identity scale is really about governance coverage, not account volume, and why that distinction matters for human and non-human identities.
Why it matters: It matters because IAM, IGA, PAM and compliance teams need to know whether they are governing material access across applications, entities and AI agents, not just storing identities in a platform.
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
👉 Read SafePaaS's analysis of identity scale and governance coverage
Context
Identity scale is not the same thing as identity coverage. A platform can hold millions of accounts, yet still fail to govern the privileges, data access and business context that actually matter across ERP, SaaS, legacy and acquired systems.
For IAM and IGA teams, the hard problem is extending consistent policy across different legal entities, operating units and identity types, including service accounts, bots and AI agents. If governance arrives late or only partially, the organisation has capacity without control.
That is why time to governance coverage is a better measure than raw identity volume. It tells practitioners whether their programme can absorb business change, acquisitions and new workloads without leaving blind spots behind.
Key questions
Q: How should security teams measure identity scale in complex enterprises?
A: They should measure how much material access is governed, not how many identities a platform stores. The better indicators are entitlement-level visibility, cross-entity policy coverage, time to onboard new systems and whether human and non-human identities are both inside the same review model.
Q: Why do non-human identities make identity governance harder to measure?
A: Non-human identities multiply faster than human accounts, often across teams and platforms that do not share a single source of accountability. That fragmentation makes it harder to prove ownership, lifecycle state, and access justification. The more distributed the estate becomes, the more likely leaders are to see activity metrics without a reliable picture of risk.
Q: What breaks when governance only covers the systems already connected to IGA?
A: The programme appears complete while critical applications, entitlements and acquired systems remain outside policy. That creates a blind spot where access can be granted, changed or overlooked without audit-ready evidence or consistent approval logic.
Q: Who is accountable when acquired systems stay outside identity governance?
A: IAM, IGA and compliance owners are accountable for the gap until the acquired estate is brought under policy and evidence controls. If governance lags behind business change, the organisation inherits access risk, control exceptions and audit exposure at the same time.
Technical breakdown
Why identity volume does not equal governance coverage
Identity volume is a storage problem, but governance coverage is a decision problem. An IGA platform may know that an identity exists, yet still not expose the underlying entitlements, SoD conflicts, data access or cross-application relationships that determine risk. At scale, the challenge shifts from counting identities to proving that material access is visible, policy-evaluated and reviewable across the estate. This is why a single-entity rollout often looks successful while a multi-entity enterprise exposes gaps. Practical implication: measure governed access by application, entitlement depth and business context, not by account count.
Practical implication: measure governed access by application, entitlement depth and business context, not by account count.
Why federated governance matters in multi-ERP and multi-entity estates
Federated governance is the layer that lets organisations apply policy across heterogeneous systems without forcing every application into one monolithic model. It preserves local systems while normalising access review, risk evaluation and evidence collection at the control plane. That matters when legal entities, ledgers and regions require different access judgments for the same role name. Without that contextual layer, teams end up centralising dashboards while policy remains fragmented underneath. Practical implication: define governance at the policy layer and let existing systems feed it, rather than rebuilding each application around a single identity model.
Practical implication: define governance at the policy layer and let existing systems feed it, rather than rebuilding each application around a single identity model.
How non-human identities change the scale equation
Non-human identities expand scale in two ways: they multiply faster than people, and they often change faster than human lifecycle processes can track. Service accounts, API credentials, bots and AI agents can all reach sensitive business processes, but many programmes still govern them as exceptions rather than as core identity subjects. That creates an access gap between what the platform stores and what the organisation can actually defend. The real risk is not just more identities, but more unmanaged privileges moving at machine speed. Practical implication: bring non-human identities into the same governance model as human identities, then adjust ownership, review and lifecycle handling by actor type.
Practical implication: bring non-human identities into the same governance model as human identities, then adjust ownership, review and lifecycle handling by actor type.
NHI Mgmt Group analysis
Identity scale without governance coverage is a false success metric. A platform that can ingest more users, more systems or more entitlements is only scaling administration if it cannot evaluate effective access across the business. The decisive question is whether material access is governed at the entitlement level across humans and non-humans. Practitioners should treat raw identity counts as secondary to governed coverage.
Time to governance coverage is the metric that exposes real control maturity. In a stable estate, periodic reviews may look sufficient. In an acquisitive, multi-cloud or AI-heavy environment, the gap between business change and policy coverage is where risk accumulates. That gap is especially dangerous because it is usually invisible to dashboard reporting. Practitioners should benchmark how fast new systems enter scope, not just how many identities the platform stores.
Federated identity governance is becoming the practical operating model for complex enterprises. The article points to a control plane that can span ERP, SaaS, legacy systems and AI-related identities without replacing the whole stack. That reflects where the market is heading: governance must sit above fragmented systems and below business risk, or it cannot keep up. Practitioners should re-evaluate whether their current architecture can enforce one policy across many operational realities.
Non-human identities are the pressure test for every identity programme. Service accounts, bots, API credentials and AI agents do not just increase volume. They expose whether ownership, review and lifecycle processes were designed for the identities that actually move data and money. The governance model is incomplete if it only works when a human can be assigned every action. Practitioners should use NHI coverage to test whether their identity programme is truly enterprise-wide.
Scope expansion, not platform size, is where identity risk concentrates. Acquisitions, reorganisations and application sprawl create the real scaling problem because each one introduces a new governance boundary. If the programme cannot pull those boundaries into policy quickly, access remains partially governed long after the business changed. Practitioners should focus on how quickly new legal entities and applications become auditable, because that is where control failure becomes measurable.
From our research:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which shows how thin the operational margin still is.
- That same survey found 59.8% of organisations see value in simplifying non-human access management and introducing dynamic ephemeral credentials, which is a useful forward lens for governance design.
What this signals
Governance teams should expect scale to show up first as coverage debt, not user growth. The moment business change accelerates, programmes that rely on point-in-time reviews begin to drift behind the environment they are meant to control. A practical response is to track how quickly new applications, entitlements and identity types become auditable, then use that gap as a programme risk indicator.
Non-human identities are now a governance stress test for every identity architecture. If service accounts, bots and AI agents are not reviewed, owned and lifecycle-managed alongside human identities, the programme is incomplete by design. Practitioners should treat NHI scope as the fastest way to reveal whether a federated control plane is real or merely a reporting layer.
Time to governance coverage is the named concept that matters here. It captures how long an organisation needs to bring new material access under policy, review and evidence capture. Shortening that interval is increasingly the difference between a control programme that keeps pace with the business and one that only documents the backlog.
For practitioners
- Measure governance coverage, not identity volume Track the percentage of material applications, entitlements and identity types that are actually governed today. Use that as the scale metric instead of raw account counts, because account totals do not show whether effective access is visible or reviewable.
- Map policy by business boundary Test whether access decisions can differ across legal entities, operating units, ledgers and regions even when the role name is the same. If they cannot, the programme is flattening business context and missing material risk.
- Bring non-human identities into the same control model Include service accounts, integration users, bots, API credentials and AI agents in ownership, review and lifecycle processes. Treat them as governed identities, not exceptions that sit outside certification and evidence routines.
- Set a time-to-coverage objective for new systems Define how long it should take to bring an acquired or previously unmanaged application under policy, review and evidence capture. Then measure the current gap by system class so the backlog is visible to IAM and audit owners.
- Use continuous monitoring to close review lag Re-evaluate SoD and sensitive-access risk when roles, privileges or organisational context change, especially across connected applications. That reduces the gap between periodic certification and the moment new risk is introduced.
Key takeaways
- Identity scale becomes meaningful only when material access is governed across applications, entities and identity types.
- The strongest indicator of maturity is how quickly new systems and newly introduced access can be brought into policy and evidence coverage.
- Non-human identities expose whether an identity programme is truly enterprise-wide or still designed around human users alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centres on governance gaps across non-human identities and their lifecycle. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions management aligns with governing effective access across applications and entities. |
| NIST Zero Trust (SP 800-207) | The article reflects continuous verification across heterogeneous enterprise access paths. | |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to governing access across human and non-human identities. |
Map NHI coverage gaps to NHI-03 and extend policy, ownership and review to all material machine identities.
Key terms
- Governance Coverage Drift: Governance coverage drift is the gap between the access estate an organisation believes it controls and the access estate actually present across applications and identities. It emerges when discovery is incomplete, integrations lag, or review data does not reconcile cleanly to real entitlements.
- Time To Governance Coverage: Time to governance coverage is the interval between a new system, entitlement or identity type appearing and that access being brought under policy and review. In mature programmes, the interval is short enough that business change does not create a prolonged blind spot.
- Federated identity governance: Federated identity governance distributes control across platforms and business units while keeping policy, evidence, and accountability aligned. It is used when identities and permissions are managed in multiple systems, but the organisation still needs one risk view and one governance standard.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
What's in the full article
SafePaaS's full article covers the operational detail this post intentionally leaves for the source:
- A federated governance model for extending policy across ERP, SaaS and legacy applications without replacing existing identity tooling.
- Concrete examples of how entitlement-level reviews and context-aware SoD checks work across legal entities and operating units.
- Case study results showing how one enterprise expanded governed applications, reduced review effort and shortened fulfilment time.
- The compliance mechanics for SOX, ITGC and continuous monitoring when non-human identities can affect financial reporting and sensitive access.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org