By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: VezaPublished August 13, 2026

TL;DR: Identity programmes need a shared maturity model spanning humans, non-human identities and AI agents, because most enterprises still operate in Partial maturity with fragmented visibility, manual reviews and disconnected workflows, according to Veza. The gap is that identity creation is outpacing governance, so least privilege, remediation and offboarding now depend on a unified access graph and continuous control.


At a glance

What this is: This is Veza’s identity security maturity model, which maps five capability pillars across human, non-human and AI agent identities and finds most enterprises still live in fragmented, partial maturity.

Why it matters: It matters because IAM, IGA, PAM and SecOps teams need one common language for visibility, remediation and lifecycle governance across NHIs, autonomous systems and human access.

By the numbers:

👉 Read Veza's identity security maturity model for human, NHI and AI agent governance


Context

Identity security maturity is the ability to see, prioritise and control access across the full identity estate, not just humans. Veza’s model argues that the problem is not a lack of point tools, but a lack of shared structure for understanding where an identity programme stands and what to fix next, especially as non-human identities and AI agents expand the attack surface.

That gap shows up in the way organisations still split identity work between security operations, IGA, application owners and platform teams. A maturity model only becomes useful when it can describe access graphs, workflows, lifecycle controls and remediation in a way that board members, auditors and engineers can all recognise. For broader NHI context, see the [Ultimate Guide to NHIs](https://nhimg.org/the-ultimate-guide-to-non-human-identities).

The important takeaway is that identity debt compounds faster than manual governance can absorb it. As new SaaS apps, service accounts, automation pipelines and AI systems appear, the question stops being whether an organisation has tools and becomes whether it has a repeatable operating model for least privilege and offboarding.


Key questions

Q: How should security teams implement maturity-based identity governance for NHIs?

A: Start by defining maturity stages for visibility, lifecycle control, privilege management, and audit readiness. Then assign measurable controls to each stage, such as complete inventory coverage, automated offboarding, and review intervals for elevated access. The goal is not a static policy set but a repeatable operating model that reduces standing risk as identity volume grows.

Q: Why do NHIs create problems for simplified identity governance?

A: NHIs often outnumber human identities, change less visibly, and carry access that is hard to describe in a simple catalog. Simplified governance can process requests, but it often struggles to model ownership, inheritance, and revocation. That leaves hidden privilege in the environment long after the ticket is closed.

Q: What breaks when access reviews are the primary identity control?

A: The control breaks because access can change, be abused, and disappear between review cycles. Review-based governance produces documentation, but not continuous enforcement. In practice, that means investigators can find clean records even when the environment had excessive access at the exact moment the incident occurred.

Q: How do organisations know whether identity visibility is actually improving?

A: Look for faster answers to access questions, fewer unresolved toxic combinations, better ownership coverage, and a smaller gap between what separate tools report and what the enterprise access model shows. If remediation still depends on manual reconciliation, visibility has not yet become operational intelligence.


Technical breakdown

Why an access graph changes identity governance

An access graph is a unified model of who or what has access to which resources across cloud, SaaS, on-prem and custom systems. It matters because identity risk is not visible in isolation. Over-privileged access, orphaned entitlements and dormant accounts only become governable when access relationships are mapped into one data layer that can be queried, prioritised and acted on.

Practical implication: build a trusted access graph before trying to automate reviews or remediation.

How monitoring and orchestration enforce least privilege

Least privilege is not achieved by policy statements. It is maintained by monitoring for drift, correlating high-risk access patterns and orchestrating removal actions when access is no longer justified. In Veza’s model, this is where detection turns into operational change, whether that means deprovisioning, updating ownership or launching a review across connected systems.

Practical implication: connect detection to removal actions, not just dashboards and alerts.

Why workflows matter for joiner, mover and leaver processes

Workflows embed access governance into business operations. They make provisioning, deprovisioning, access requests and certification repeatable rather than ad hoc. The article is clear that manual tickets, spreadsheets and email threads are where identity risk accumulates, especially when non-human identities and AI agents are added late instead of being included from the start.

Practical implication: extend JML, access review and JIT workflows to non-human identities from day one.


NHI Mgmt Group analysis

Identity maturity cannot be measured by tooling count alone. The article correctly treats maturity as a capability model, not a product inventory. Organisations often have scripts, reviews and scattered controls, yet still lack a shared operating model for visibility, prioritisation and remediation. That is why identity programmes stall in Partial maturity even when teams believe they are modernised.

Non-human and AI identities are now part of the core maturity baseline. A maturity model that centres only human IAM undercounts exposure because service accounts, API keys, secrets and autonomous agents now sit inside the same operational control plane. When those identities are excluded, the programme measures process quality for people while leaving machine access outside governance. The implication is that identity maturity is no longer separable by actor type.

Access graph maturity is the named concept practitioners should anchor on. The access graph is the point where identity data becomes governable at scale because it links identities, entitlements, systems and risk into one decision surface. Without it, organisations cannot reliably distinguish high-risk access from routine access, which means remediation remains subjective. Practitioners should treat graph quality as a maturity gate, not a reporting feature.

Control discipline is what separates partial from repeatable governance. The article’s five pillars show that visibility and analytics do not equal control unless they are followed by orchestration, workflows and maintenance. In practice, that means identity teams must stop treating reviews as the end state and start treating them as input to lifecycle enforcement. The discipline is operational, not cosmetic.

Identity governance and identity security are converging, but not collapsing into one function. The model usefully separates the SecOps-adjacent function from the IGA function while showing that both now depend on the same underlying access data. That convergence is where modern programmes should land: one data model, two operational lenses, and shared accountability for least privilege across human, non-human and AI identities.

From our research:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
  • A separate finding shows that only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities.
  • The next step is to compare that maturity gap with lifecycle exposure using Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs.

What this signals

Access graph maturity will become the practical dividing line between programmes that can govern NHIs and those that only document them. Once service accounts, secrets and AI agents are modelled in the same access layer, teams can stop arguing about definitions and start measuring removability, ownership and blast radius. The next governance debate will be about control quality, not inventory size.

The broader trend is that identity teams will be judged on whether they can connect discovery to remediation without creating more manual work. That means review processes, deprovisioning paths and ownership updates need to be tied to operational systems rather than left in spreadsheets or ticket queues.

The maturity question is shifting from 'do we know what exists' to 'can we reduce risk continuously'. Organisations that cannot answer that will keep expanding their identity estate faster than their control plane can absorb it, especially as machine identities and AI-driven workflows grow.


For practitioners

  • Build a unified access graph Integrate HR systems, directories, cloud platforms, SaaS apps and critical applications into a single access graph so identity risk can be queried and prioritised consistently.
  • Use risk-based prioritisation Separate dormant access, over-privileged accounts and wildcard policies by business impact and effort so remediation capacity goes to the highest-value fixes first.
  • Wire remediation into existing workflows Push findings into SOC tooling, ITSM, Joiner-Leaver-Mover processes and owner notifications so access issues turn into action instead of more reporting.
  • Extend governance to NHIs and AI agents Include service accounts, secrets and AI agents in access reviews, provisioning and deprovisioning from the start so machine access is not deferred to a later phase.
  • Measure identity maturity by control outcomes Track whether the programme can reduce over-privileged access, orphaned accounts and blast radius rather than counting the number of dashboards or tools deployed.

Key takeaways

  • Veza’s model is a maturity framework for the full identity estate, not a point solution narrative, and that matters because humans, NHIs and AI agents now share the same control problem.
  • The real maturity gap is not visibility alone but the ability to turn discovery into repeatable remediation across access, workflows and lifecycle management.
  • Identity programmes should measure whether they can reduce blast radius, orphaned access and privilege drift, because that is what separates partial governance from operational control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centres on NHI visibility, lifecycle and access governance gaps.
NIST CSF 2.0PR.AC-4Least privilege and access governance are core to the model's control pillar.
NIST SP 800-53 Rev 5AC-6Privilege restriction is the operational control behind the article's least-privilege focus.
NIST Zero Trust (SP 800-207)5.4The model's continuous verification and containment logic aligns with zero trust access assumptions.

Use OWASP NHI guidance to assess visibility, ownership and lifecycle coverage across service accounts and secrets.


Key terms

  • Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
  • Data security maturity: The degree to which data protection is repeatable, measurable, and resilient under real operating conditions. Mature programmes do not rely on heroics or constant manual intervention, and they can sustain control performance as the business scales.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • The full five-pillar maturity model with stage-by-stage examples of what Partial, Informed, Repeatable and Adaptive look like in practice.
  • The access graph implementation approach, including the data sources and identity relationships needed to make remediation actionable.
  • The distinction between identity security and identity governance operating lanes, and how teams divide responsibilities across them.
  • The concrete next-step workflow mapping Veza uses when organisations want to move from assessment to implementation.

👉 Veza's full article expands the maturity stages, operating model and access graph approach in practical detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org