TL;DR: Identity security is no longer just about giving the right access at the right time, according to Saviynt's perspective, because attackers now exploit identity across humans, machines, and agentic AI while enterprises still organise controls around productivity-first IAM models. The governance gap is widening as machine identity, zero trust, and threat-aware decisioning become inseparable.
At a glance
What this is: Saviynt argues that identity security is moving from a productivity-led IAM model toward threat-aware governance across human, machine, and agentic identities.
Why it matters: This matters because IAM teams now have to govern access for service accounts, machine identities, and AI agents with the same rigor they apply to human users, without losing business enablement.
By the numbers:
- NHIs now outnumber human identities by 144:1 in enterprise environments, a 44% increase year-over-year driven by AI agents, CI/CD automation, and third-party integrations.
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
👉 Read Saviynt's analysis of identity security, machine identity, and agentic AI
Context
Identity security starts with the assumption that access can be granted safely and reviewed later. That assumption weakens when organisations must govern humans, service accounts, machine identities, and AI agents in the same operating environment, because the old productivity-first IAM model does not fully account for threat behaviour, standing privilege, or rapid identity sprawl. The result is a governance gap, not just a tooling gap.
This article frames a market shift as much as a technical one. The vendor argues that zero trust, PAM, ITDR, IGA, and machine identity now need to be treated as connected control domains, because identity is where attack patterns converge and where digital trust is either preserved or lost.
For teams building out NHI programmes, the practical question is no longer whether identity matters. It is which identities are governed well enough to withstand adversary pressure, and which are still being managed as if they were stable, human-paced accounts. That distinction is becoming central to both security architecture and compliance discipline.
Key questions
Q: What breaks when organisations manage machine identities like user accounts?
A: The programme loses visibility, ownership, and lifecycle control. Machine identities do not follow human onboarding, MFA, or password-reset patterns, so user-first processes miss the real control points. That leads to orphaned credentials, weak attribution, and a larger attack surface than the access review process is able to detect.
Q: Why do excessive NHI privileges increase breach impact?
A: Because attackers rarely need root access if an NHI already has more permission than its workload requires. Excessive privilege turns a single compromised key, token, or service account into lateral movement, data access, or infrastructure control. The risk grows further when those identities are externally exposed or not rotated on schedule.
Q: How do teams know whether identity detection is actually reducing risk?
A: Look for fewer unresolved high-risk sessions, faster containment of suspicious privilege use, and better analyst prioritisation. A strong programme changes how quickly the team can identify, contain, and explain identity misuse. If alerts rise but response quality does not improve, the control is producing noise rather than reduction in risk.
Q: How should security teams choose between Zero Trust and Defense in Depth for identity governance?
A: Use Zero Trust when the main risk is stale trust, lateral movement, or identity-driven access across cloud and SaaS systems. Defense in Depth still helps with containment, but it should not be the primary governance model if identities change frequently. The deciding factor is whether your controls continuously verify identity state or only stack barriers around it.
Technical breakdown
Why productivity-led IAM struggles against threat-aware identity governance
Traditional IAM was built to help the right subject get the right access for the right reason at the right time. That model works for enablement, but it leaves a gap when identity itself becomes an attack surface. Threat-aware governance adds the question of whether an identity is behaving like a threat, not just whether it was provisioned correctly. For machine identities and AI-adjacent access paths, that means the control problem shifts from only authorisation to continuous context, behaviour, and lifecycle enforcement.
Practical implication: Practitioners should evaluate where their IAM stack still assumes stable, human-paced access patterns and where that assumption no longer holds.
Machine identity, NHI, and the problem of hidden access paths
Non-human identities include service accounts, API keys, tokens, certificates, and other machine-bound access mechanisms. They often live outside the visibility disciplines that were developed for human users, which is why over-privilege and poor offboarding are persistent issues. Once these identities are embedded in applications, pipelines, and integrations, they can persist long after the business process that created them has changed. The control challenge is not just discovery, but ownership, rotation, revocation, and evidence of ongoing necessity.
Practical implication: Teams should map where machine identities exist across code, CI/CD, and third-party integrations before trying to tighten their governance model.
Agentic AI changes the identity question from access management to runtime trust
An AI agent is not merely another workload if it can independently choose actions, tools, and timing without human approval. That creates a different governance problem from classic automation, because the access path can shift during execution rather than at provisioning time. Identity controls designed around fixed entitlement reviews may fail when the identity can initiate, chain, and adapt actions at runtime. In that case, least privilege must be understood as a dynamic operating condition, not just an assigned role.
Practical implication: Security leaders should separate ordinary automation from autonomous runtime behaviour before deciding which governance and control framework applies.
Threat narrative
Attacker objective: The attacker wants to turn trusted identity paths into broad access that bypasses perimeter controls and creates leverage across systems and data.
- Entry occurs when attackers exploit identity trust, whether through exposed secrets, compromised service accounts, or manipulated access paths tied to human and non-human identities.
- Escalation follows when standing privilege, excessive entitlements, or poorly governed machine identities let the attacker move from one trusted identity to broader access.
- Impact lands in data exposure, service disruption, or ransomware-style operational damage because identity sits at the centre of authentication, authorisation, and business continuity.
Breaches seen in the wild
- Dropbox Sign breach — compromised Dropbox Sign service account exposed API keys and OAuth tokens.
- CoPhish OAuth Token Theft via Copilot Studio — CoPhish campaign exploits Microsoft Copilot Studio agents to steal OAuth tokens via AI-assisted phishing.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity security is becoming a threat detection problem, not just an access administration problem. The article's core argument is that modern identity programmes must answer whether an identity is trusted and whether it is behaving like an adversary. That moves identity governance closer to runtime control, where PAM, ITDR, and NHI management have to be treated as connected disciplines. Practitioners should stop treating identity as a back-office provisioning function and start treating it as a live security control plane.
The governance gap is largest where machine identities were inherited, not designed. Service accounts, API keys, certificates, and integration tokens often accrete through application delivery rather than through intentional identity design. That is why visibility, ownership, and offboarding remain weak even in mature environments. The implication is straightforward: if the identity was created to make a workflow possible, it is often also the identity most likely to outlive its original purpose.
Identity programmes built for human-paced review cycles do not automatically scale to autonomous behaviour. Access review, recertification, and joiner-mover-leaver processes assume that access remains stable long enough to be observed and certified. That assumption weakens when an AI agent can acquire and use access within a single session. The implication is not just more monitoring, but a rethink of whether the governance model itself matches the actor's runtime behaviour.
NHI governance is now a board-level resilience issue, not a niche machine-identity topic. The article links identity security to business continuity, regulatory pressure, and trust in digital operations. That is the right frame, because identity sprawl, privilege creep, and poor revocation discipline can now produce operational harm at scale. Security teams should present NHI as part of resilience and control assurance, not as an isolated secrets-management workstream.
Identity blast radius: The meaningful unit of analysis is no longer the account alone but the amount of downstream access, data, and operational reach it can unlock. Once organisations understand that blast radius, they can prioritise which identities matter most and where governance failures will hurt first. Practitioners should use that lens to re-rank remediation, because the highest-risk identities are often not the most visible ones.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
- For deeper breach context, see The 52 NHI breaches Report for real-world patterns of credential abuse and hidden machine access.
What this signals
Identity teams should expect their control model to be judged by runtime trust, not just provisioning discipline. As agentic AI and machine identity scale, the programme that only knows how to grant access will look incomplete. The practical shift is toward governing who or what can act, not merely who or what can sign in.
With 97% of NHIs carrying excessive privileges, the most dangerous identity issues are usually hidden in plain sight. That means inventory quality, ownership, and offboarding speed now influence security outcomes as much as authentication design. Teams that cannot see their machine identities clearly should assume their control coverage is already incomplete.
The next maturity step is to connect NHI lifecycle data to privileged access and threat response workflows. That is where identity governance stops being a record-keeping exercise and becomes a containment capability. For teams building their roadmap, the signal is simple: improve visibility first, then use it to drive least privilege, rotation, and offboarding discipline.
For practitioners
- Define identity ownership across all machine accounts Assign explicit business and technical owners to service accounts, API keys, certificates, and integration tokens so revocation and review decisions do not fall into administrative gaps.
- Separate automation from autonomous runtime behaviour Classify workflows that follow fixed rules differently from AI agents or other runtime decision-makers, then apply governance based on whether the actor can choose actions and timing independently.
- Rebuild access reviews around identity blast radius Prioritise recertification and monitoring for identities that can reach sensitive systems, move laterally, or persist across multiple delivery pipelines and third-party integrations.
- Tie PAM to machine and agent identity lifecycle Use privileged access controls for high-risk non-human and autonomous identities, especially where standing privilege, dormant credentials, or delegated access paths can be reused.
- Measure NHI visibility before expanding control scope Baseline how many service accounts and machine credentials you can actually inventory today, then use that inventory to sequence rotation, revocation, and offboarding work.
Key takeaways
- Identity security is shifting from access enablement to adversary-aware governance across humans, machines, and agents.
- Machine identities remain poorly visible in most environments, which makes privilege creep and stale access the default risk condition.
- Teams that separate autonomous behaviour from ordinary automation will make better decisions about where traditional IAM controls stop being sufficient.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Discovery and Inventory | The article centres on machine identity visibility gaps and unmanaged NHI sprawl. |
| NHI-03 — Secrets and Credential Management | The post stresses secrets, tokens, and access paths as core identity security risks. | |
| Recommendation — Inventory all service accounts and machine credentials before expanding NHI governance scope. Rotate, revoke, and scope machine credentials with strict lifecycle controls. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorisations | The article argues for tighter access governance across human and non-human identities. |
| Recommendation — Map non-human access permissions to PR.AC-4 and reduce standing privilege. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Excessive privilege is presented as a central control weakness in identity programmes. |
| Recommendation — Apply AC-6 to limit high-risk non-human identities to the minimum required access. | ||
| NIST Zero Trust (SP 800-207) | 3 — Identity and access management | Zero trust is a major theme, especially around continuous verification and trust decisions. |
| Recommendation — Align identity decisions to zero-trust principles and verify access continuously. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Threat-centric identity governance: Threat-centric identity governance is the practice of managing identities based on attacker behavior and blast-radius reduction rather than on audit artifacts alone. It focuses on visibility, least privilege, short-lived access, and rapid revocation so that identity controls reduce real-world attack opportunity, not just policy exceptions.
What's in the full article
Saviynt's full article covers the strategic context this post intentionally leaves at a higher level:
- The author's firsthand account of how identity, PKI, and machine identity markets evolved over time.
- The rationale behind the shift from productivity-first IAM to adversary-aware identity security.
- The specific market and organisational signals the author uses to argue that agentic AI is accelerating change.
- The leadership and market-convergence context behind Saviynt's broader identity strategy.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on September 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org