By NHI Mgmt Group Editorial TeamBased on SailPoint: “The progress of identity security — a three-year review” (December 10, 2025)

TL;DR: More than 40% of organisations remain in Horizon 1, while roughly one-third have reached the top three most secure horizons, alongside rising machine identity coverage and privileged access governance adoption, according to SailPoint’s three-year Horizons survey. The pattern shows identity security is improving, but most programmes still underuse the controls needed for modern identity sprawl.


At a glance

What this is: This three-year review of identity security maturity shows that most enterprises are still early in their journey, even as a growing minority advance into more secure horizons and expand machine identity and privileged access governance.

Why it matters: For IAM and NHI practitioners, the survey frames maturity as a programme problem, not a point product issue: identity coverage, governance depth, and operating model discipline now determine whether security scales with identity sprawl.

By the numbers:

  • More than 40% of organisations still remain in Horizon 1, according to SailPoint’s three-year Horizons survey.
  • About 8% of surveyed organisations made the jump from Horizon 2 to Horizon 3 over the prior year, according to SailPoint’s three-year Horizons survey.
  • Only about 1% broke out of Horizon 1, according to SailPoint’s three-year Horizons survey.

Context

Identity security maturity describes how well an organisation can govern identity data, access decisions, and lifecycle controls as identity types multiply across human, service, machine, and AI-driven contexts. In this review, the core problem is not whether enterprises have identity tools, but whether their operating model can scale governance faster than identity sprawl.

SailPoint’s three-year Horizons survey presents that gap as a maturity progression problem across strategy, technology and tools, operating model, and talent. The article argues that many organisations are still stuck in early stages, even as machine identities, AI-enabled workflows, and privileged access demands push identity security into broader enterprise risk management.


Key questions

Q: What does it mean when an identity security programme is still early in maturity?

A: It usually means the organisation still depends on manual processes, fragmented data, and inconsistent ownership to manage access. In practice, identity controls may exist, but they are not yet integrated enough to support scalable governance across human, third-party, and non-human identities. The gap is operational as much as technical.

Q: Why do machine identities change the way identity risk should be measured?

A: Machine identities expand the attack surface beyond human login events because service accounts, API keys, and certificates can be overprivileged, poorly inventoried, and difficult to review. That means risk measurement has to include visibility, access scope, and lifecycle control, not just user authentication and alerting.

Q: How do I tell whether identity governance is scaling or just administration?

A: Look at coverage, not account volume. If new systems, entitlements and business entities are still being governed through spreadsheets, tickets or local exceptions, administration is scaling faster than governance. A credible programme can show that material access is under consistent policy across the estate, not only inside the systems it already knows well.

Q: How can organisations decide whether to prioritise identity controls or data controls first?

A: Organisations should prioritise both, but begin with the control that closes the highest-risk exposure path. If sensitive data is broadly accessible, strengthen data classification and access restrictions first. If credential sprawl or weak authentication is the bigger issue, tighten identity governance first. In practice, the best outcomes come from sequencing both against the same risk model.


Technical breakdown

How identity horizons translate maturity into measurable capability

The Horizons model divides identity security into stages that reflect how much of the programme is still manual, partly automated, or operating at scale. At the low end, teams rely on ad hoc processes and isolated controls. As maturity rises, identity data becomes more integrated, policies become more context aware, and access decisions begin to use analytics rather than static rules. The important technical point is that maturity is not just tool adoption. It depends on whether strategy, operating model, talent, and data quality support consistent enforcement across identities.

Practical implication: assess maturity across operating model and data quality, not just product coverage.

Why machine identity coverage is now part of identity security maturity

Machine identities are no longer a side issue. The article links AI, automation, copilots, and machine learning models to a growing need to manage service accounts and other non-human identities as part of the same governance plane used for employees and contractors. That means lifecycle control, entitlement visibility, and privileged access governance must extend beyond human users. If machine identities are left outside the core identity fabric, the organisation can look mature on paper while leaving a large and fast-growing access surface ungoverned.

Practical implication: bring service accounts and other NHI into the same governance model as human identities.

What context-aware policy enforcement changes in practice

Context-aware policy enforcement uses identity data, behaviour, and environment signals to decide access more dynamically than a fixed role model can. In the article’s framing, this is where AI-powered analytics, anomaly detection, and identity pattern recognition become part of the control plane. The mechanism matters because static approval and recertification cycles cannot keep pace with rapidly changing identity relationships. Done well, context-aware policy turns identity security from a periodic review exercise into a continuously informed decisioning system.

Practical implication: pair recertification with runtime policy signals so access decisions reflect current behaviour.


Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity maturity is now a governance problem, not a tooling problem: the article shows that enterprises can buy more identity capability without materially changing how access is governed. Horizons progress only when strategy, operating model, data, and talent move together. The practitioner lesson is that maturity programmes must be judged by governance consistency across identity types, not by feature adoption alone.

Machine identity governance is becoming the maturity floor: the article’s strongest signal is that third-party and machine identities are now part of the baseline identity security conversation. That shifts the centre of gravity from human-centric IAM to a broader identity fabric where service accounts, copilots, and automated systems must be visible and governed. The implication is that IAM teams that stop at employee access are measuring the wrong control surface.

Integrated identity data is the enabling concept behind every higher horizon: without a unified data layer, organisations cannot see identity relationships, privilege patterns, or anomalous behaviour well enough to act consistently. The article’s context-rich identity graph direction is therefore not a reporting feature but a governance prerequisite. Practitioners should treat identity data quality as a control dependency, because incomplete identity context weakens every downstream decision.

Context-aware policy enforcement is where maturity becomes operational: static access models cannot keep up with identity sprawl, especially where AI and automation expand the number of actors and interactions. The real shift is from periodic certification to continuously informed decision-making. That means the next horizon is less about more reviews and more about better decision inputs, with practitioner emphasis on policy precision and signal quality.

Identity horizons expose the operating model gap most organisations still ignore: the survey’s maturity pattern shows that advancement is easiest when organisations change how identity work is staffed and executed, not just which controls are purchased. Engineering-led support, better data foundations, and cross-domain identity governance separate the organisations that scale from those that stall. The practical conclusion is that identity security maturity is won through operating discipline, not dashboard visibility.

What this signals

Identity maturity now depends on whether organisations can govern humans and machines through one operating model: the practical challenge is not simply expanding coverage, but ensuring that ownership, review, and enforcement work across every identity class. Teams that keep service accounts and automation identities outside the main IAM programme will stall at the point where identity sprawl becomes operational risk.

Integrated identity data is the control plane for the next phase of IAM: policy precision improves only when identity records, relationships, and behaviour signals are trustworthy enough to drive decisions. Practitioners should treat identity data quality as a standing programme dependency rather than a cleanup project.

Context-aware enforcement will matter more as AI and automation raise identity volume: static access rules cannot absorb the pace of change when identities proliferate across cloud, software, and machine workflows. The programmes that advance will be the ones that move from periodic review to continuously informed access governance.


For practitioners

  • Strengthen identity data foundations Unify identity records across employees, contractors, service accounts, and machine identities so policy decisions use one current source of context rather than fragmented directory views.
  • Extend privileged access governance to non-human accounts Treat service accounts, automation identities, and machine identities as governed privilege holders, with ownership, approval, and review paths equivalent to human privileged access.
  • Measure maturity across four operating dimensions Assess strategy, technology and tools, operating model, and talent together so a strong tool stack does not mask weak process or ownership discipline.
  • Use context signals to refine access decisions Feed anomaly detection, behaviour patterns, and identity relationships into policy enforcement so access reviews are informed by current usage rather than static role assumptions.
  • Plan for scale without linear staffing growth Shift repetitive identity work from manual support to engineering-led automation, especially where the identity estate includes large numbers of machine and third-party accounts.

Key takeaways

  • The article shows that many enterprises are still early in identity security maturity even as a growing minority progress into more advanced horizons.
  • Machine identities and privileged access governance are now central maturity indicators, not niche add-ons to human IAM.
  • Identity data quality and context-aware policy enforcement are the controls most likely to determine whether a programme can scale.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article links maturity to governance over machine and service accounts with expanding privilege.
NHI-08 — Environment IsolationThe survey discusses integrated identity across cloud, SaaS, APIs, and data environments.
Recommendation — Review machine and service account entitlements against NHI-05 and remove standing excess privilege. Separate identity contexts across environments so cross-domain access does not blur governance boundaries.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about maturing access governance and entitlement control at scale.
Recommendation — Apply PR.AA-05 to centralise entitlement governance across human and non-human identities.
CIS Controls v8CIS-5 — Account ManagementAccount governance and lifecycle control are central to the maturity progression described.
Recommendation — Use CIS-5 to standardise account ownership, review, and removal across all identity types.
MITRE ATT&CKTA0004; TA0006; TA0008 — Privilege Escalation; Credential Access; Lateral MovementThe article references the risk environment that machine and service account sprawl can enable.
Recommendation — Map identity sprawl to privilege and credential abuse paths to prioritise detections and controls.

Key terms

  • Identity Maturity Model: An Identity Maturity Model is a structured way to assess how well an organization manages identities, access, and related controls. It typically measures current practices against defined stages of capability, covering governance, provisioning, authentication, authorization, monitoring, and lifecycle management across human and non-human identities.
  • Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
  • Context-Aware Policy: Context-aware policy is a control model that decides access based on current conditions, not just preassigned entitlement. For AI agents and other non-human identities, this means privileges, tool use, and monitoring expectations can change as the task, environment, or risk signal changes.
  • Identity Data Layer: The identity data layer is the shared foundation that collects, normalizes, and links identity-related information across systems. It combines records about people, non-human identities, devices, entitlements, authentication events, and policy context so security and governance tools can make consistent decisions. It is the data backbone for identity visibility, control, and analytics.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org