By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Oleria SecurityPublished September 20, 2026

TL;DR: Gartner’s new Identity Visibility and Intelligence Platform category formalises a layer for aggregating identity, entitlement, and activity data across fragmented environments, with Oleria listed as a Representative Provider, according to Oleria Security. The practical shift is that continuous visibility and action on human, non-human, and AI identities is becoming a governance requirement, not an optional IAM add-on.


At a glance

What this is: Gartner’s IVIP category names a new identity layer focused on unifying fragmented identity data and turning it into actionable visibility, intelligence, and control.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes now need a way to govern humans, non-human identities, and AI identities from one operational view.

By the numbers:

👉 Read Oleria Security's analysis of Gartner's IVIP category and identity visibility


Context

Identity visibility is the ability to see who or what has access, why that access exists, and whether it is still acceptable. In fragmented estates, that question spans human users, service accounts, API keys, tokens, certificates, and AI agents, which is why traditional IGA and PAM stacks often leave blind spots. Gartner’s IVIP category is a sign that buyers are now looking for a control layer above those tools.

The governance gap is not just missing data, but disconnected data that cannot be interpreted or acted on quickly enough. For NHI-heavy programmes, the same problem shows up in sprawl, excessive privilege, stale credentials, and weak offboarding. That is why the Ultimate Guide to NHIs remains relevant as a baseline reference, while the new category points to a broader operational layer.


Key questions

Q: How should identity teams handle fragmented identity data across IGA, PAM, and cloud systems?

A: Treat fragmentation as a governance defect, not just a reporting inconvenience. Identity teams should normalise human, NHI, and AI identity data into a single operating view, then connect that view to activity and enforcement. Without that, access reviews become incomplete and revocation remains reactive.

Q: Why do entitlements alone fail as a measure of identity risk?

A: Because entitlements show theoretical access, while activity shows exploitable access. In mature environments, the riskiest privileges are often the ones that sit unused until abuse occurs. A useful control model must compare grant state with observed usage before making risk decisions.

Q: What are the signs that an identity programme is still workforce-only?

A: A workforce-only programme usually cannot explain where service accounts live, which AI identities are active, or which cloud entitlements are disconnected from governance workflows. If identity reviews depend on spreadsheets or manual reconciliation, the programme is not seeing the full identity graph.

Q: How should security teams evaluate IVIP-style capabilities in existing tools?

A: Ask whether the platform can see all identity types, use activity rather than entitlements alone, and execute control changes without another integration project. Those three checks separate a reporting layer from a working control layer.


Technical breakdown

Why fragmented identity data defeats traditional IGA

Traditional IGA was built around managed joiner-mover-leaver workflows and periodic certification, not around a live identity graph that includes all machine identities, cloud entitlements, and AI-driven access paths. When identity data sits across IGA, PAM, cloud consoles, and ad hoc spreadsheets, the organisation cannot reliably answer who has access, why, and whether it is still justified. Visibility is not a dashboard problem. It is a data normalisation problem followed by a control problem. IVIP exists because identity decisions increasingly depend on real activity, not just assigned entitlement.

Practical implication: Practitioners should treat fragmented identity sources as a control gap and prioritise normalisation before adding more point tools.

Why activity data matters more than entitlement data alone

Entitlements show what access exists on paper, but activity data shows what access is actually being used. That distinction matters because many of the highest-risk privileges are never exercised until they are abused, which means entitlement-only reviews can overstate governance maturity. In NHI and AI-enabled estates, the difference is even sharper because access can be issued to identities that humans do not actively manage day to day. A platform that cannot compare use versus grant cannot reliably support least privilege or risk scoring.

Practical implication: Use activity telemetry to separate theoretical access from exploitable access before recertification or revocation decisions.

Why action is the real category test

Visibility without action usually turns into another reporting layer, not a security control. Gartner’s IVIP framing matters because it places revocation, least privilege enforcement, and response into the same operating loop as discovery and analysis. That is especially relevant when the identity population includes non-human identities and AI agents, where delay creates larger blast radius than it does in human-only IAM. The real question is whether the platform can change access state quickly enough to matter in the same operational cycle.

Practical implication: Validate whether the platform can revoke, constrain, or step up access without forcing a separate integration project.


NHI Mgmt Group analysis

IVIP is a category name for a control problem, not a product race. The market has accumulated too many identity point solutions that each answer a narrow question but none answer the programme question. That leaves governance teams with fragmented evidence and weak enforcement across humans, NHIs, and AI identities. The category matters because it re-centres identity on operational control rather than tool count.

Identity visibility debt is now a governance liability. Organisations that cannot see service accounts, API keys, and AI-access paths in one place are carrying hidden risk that access reviews cannot fully surface. The problem is not merely incomplete inventory; it is that disconnected systems create false confidence in certification and least-privilege programmes. Practitioners should read that as a signal that visibility gaps are now board-relevant control gaps.

Actual activity has become the deciding signal for identity risk. In mixed estates, entitlement-based models overestimate acceptable access because they ignore what is being used, chained, or delegated at runtime. That makes activity-based intelligence a necessary supplement to IGA, PAM, and NHI governance. The practical conclusion is that identity programme maturity now depends on use-based evidence, not paperwork.

Agentic and non-human identities are forcing identity architecture to move from periodic governance to continuous governance. That shift does not replace IGA or PAM; it exposes where those programmes were designed for slower human-paced review cycles. The implication is that identity leadership must align architecture, telemetry, and enforcement around continuous state, because stale access is no longer the only problem. The more important issue is that the population itself changes faster than annual controls can absorb.

Ultimate Guide to NHIs: the old visibility baseline no longer matches the scale of the problem. NHIs already outnumber human identities by 25x to 50x in modern enterprises, so a workforce-first identity model undercounts the real attack surface. That is why visibility, lifecycle, and revocation have to be discussed as a single governance system. Practitioners should treat IVIP as validation that identity governance now needs machine-scale instrumentation.

From our research:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which is why identity visibility is still a baseline problem, not a mature-state assumption.
  • If you are working on offboarding and rotation, read NHI Lifecycle Management Guide next to close the gap between visibility and enforcement.

What this signals

Identity visibility is becoming the control plane that sits above IGA, PAM, and NHI tooling. As estates add more service accounts, AI identities, and disconnected cloud permissions, the programme question shifts from coverage to operational coherence. Teams that still depend on manual reconciliation will find that their access reviews lag the identity graph rather than governing it.

Only 20% have formal processes for offboarding and revoking API keys, and that gap will widen as machine identities multiply. The practical consequence is that lifecycle governance must be wired to actual control actions, not just review cycles. For teams modernising IAM, the NHI Lifecycle Management Guide is the most direct reference point for that reset.


For practitioners

  • Map all identity sources into one operational graph Inventory where human, NHI, and AI identity data lives today, then define which systems supply authoritative entitlement, activity, and control-state records. The goal is to eliminate identity blind spots before adding another governance layer.
  • Separate assigned access from used access Build review workflows that compare entitlements with observed activity so access decisions are based on what is actually exercised, not just what is provisioned. This is especially important for service accounts, API keys, and delegated AI access.
  • Require continuous revocation paths Verify that your identity platform can remove or constrain access without opening a new integration project for each control action. If revocation still depends on manual handoffs, the programme is not operating at IVIP speed.
  • Re-baseline NHI visibility and offboarding Use the NHI Lifecycle Management Guide as the benchmark for where service accounts, secrets, and API keys should be visible, reviewable, and removable. Then compare current state against that baseline before expanding the stack.

Key takeaways

  • IVIP reflects a real governance gap: identity programmes need one view across humans, NHIs, and AI identities.
  • Activity-based intelligence is now essential because entitlement-only governance overstates how much access is actually at risk.
  • Practitioners should test whether their existing platforms can see, decide, and act without adding another integration layer.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Inventory and VisibilityThe article centres on seeing all NHIs and their access in one place.
Recommendation — Inventory all NHIs and map ownership, access, and lifecycle state into a single governed view.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsIVIP is about managing access permissions using authoritative identity data.
Recommendation — Align identity governance with PR.AC-4 by validating entitlements against actual authorised access.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article repeatedly ties visibility to least-privilege enforcement.
Recommendation — Use AC-6 to reduce standing access after comparing granted permissions with actual activity.
NIST Zero Trust (SP 800-207)3.4 — Continuous VerificationContinuous identity visibility fits a zero trust model that rechecks trust over time.
Recommendation — Apply continuous verification to identity decisions instead of relying on one-time certification.
CIS Controls v8CIS-5 — Account ManagementThe piece is fundamentally about account and identity governance across many systems.
Recommendation — Strengthen account management by reconciling all identity types before access reviews and revocation.

Key terms

  • Identity Visibility and Intelligence Platform: An Identity Visibility and Intelligence Platform is a layer that correlates identity data across multiple tools into one risk picture. It does not replace existing controls. It makes them more useful by connecting events, relationships, configuration, and posture so teams can prioritise what matters.
  • Identity Graph: An identity graph is a relationship map that connects identities, assets, data, and permissions so teams can see how access actually flows. In NHI programmes, it helps explain which agent is related to which owner, which system, and which policy boundary.
  • Activity-Based Intelligence: Activity-based intelligence uses observed behaviour to determine whether access is being used, abused, or merely assigned. In identity governance, this is the difference between a theoretical entitlement model and a control model that reflects real operational risk.
  • Identity visibility debt: The gap that appears when an organisation can list its assets but cannot reliably link them to owners, entitlements, or activity. It creates a false sense of control because inventory looks complete while access relationships remain hidden, stale, or unreviewed.

What's in the full article

Oleria Security's full post covers the operational detail this analysis intentionally leaves for the source:

  • Gartner category framing and the implications of being named a Representative Provider
  • The vendor's own explanation of visibility, intelligence, and action across a unified identity graph
  • The three practitioner questions it recommends for vendor evaluation
  • The article's view on how platform consolidation is changing identity tooling choices

👉 Oleria Security's full post expands on the IVIP framing, practitioner questions, and category implications for identity teams.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org