TL;DR: C1.ai says Gartner has named Identity Visibility and Intelligence Platforms as a new category built around rapid IAM data integration, unified identity views, and advanced analytics, while identity sprawl, non-human identities, and AI agents keep outpacing legacy tools. Complete visibility is becoming the baseline for action, because without it identity security remains guesswork.
At a glance
What this is: This is a vendor analysis of Gartner’s new IVIP category, arguing that unified identity visibility and analytics are needed because identity sprawl, non-human identities, and agentic AI are overwhelming siloed IAM data.
Why it matters: It matters because IAM, NHI, and emerging AI governance teams need to understand whether their current controls can produce a single trusted view of identities, relationships, and access before they can automate or secure anything effectively.
By the numbers:
- IVIP is still in the emerging stage, with less than 5% market penetration today.
- Gartner predicts it will take more than 10 years to reach full maturity.
👉 Read C1.ai's analysis of Gartner's IVIP category and identity visibility
Context
Identity visibility is the ability to see identities, entitlements, relationships, configuration, and posture in one place. In this post, C1.ai argues that the problem is no longer whether organisations have identity data, but whether they can unify it fast enough to make decisions.
The governance gap is familiar across IAM, NHI, and early agentic AI programmes: data sits in silos, integrations lag, and teams cannot reliably connect who or what has access with how that access changes over time. Gartner’s IVIP category is presented here as a response to that visibility deficit, not as a replacement for identity governance.
That matters because once identity count, entitlement complexity, and machine-driven activity rise faster than review and correlation processes, control quality becomes a data problem before it becomes a policy problem.
Key questions
Q: How should security teams respond when identity data is fragmented across too many systems?
A: Treat fragmentation as an operating risk, not just a tooling inconvenience. The first step is to identify where identity, entitlement, posture, and activity data are split, then decide which control decisions depend on each source. If reviewers or automation cannot see the full identity picture, governance will remain partial and slow.
Q: Why do non-human identities complicate traditional IAM programmes?
A: Non-human identities complicate IAM because they often outnumber human identities, hold broad permissions, and operate outside normal joiner-mover-leaver processes. They are harder to inventory, harder to recertify, and easier to leave behind after a project or vendor relationship ends. That makes ownership and revocation the decisive governance issues.
Q: How do you know if identity visibility is actually good enough for governance?
A: You know it is working when reviewers and control systems can consistently see current entitlements, identity relationships, recent activity, and configuration without manual reconciliation. If those data points still require ad hoc stitching between tools, visibility is partial and the organisation is still making decisions on incomplete context.
Q: What is the difference between visibility and protection in identity governance?
A: Visibility tells you which identities exist, what they can access, and where risk is concentrated. Protection goes further by using that visibility to enforce policy, restrict access, and create auditable control actions. In practice, visibility is the prerequisite for response, while protection is the operational outcome that reduces exposure across the enterprise.
Technical breakdown
What IVIP adds to fragmented IAM data
Identity Visibility and Intelligence Platforms sit above disconnected identity sources and normalise the data into a single analytical layer. In practical terms, they ingest identity, entitlement, activity, configuration, and posture signals, then correlate them across systems so teams can ask cross-domain questions without stitching reports together manually. The intelligence layer is the point: analytics turn raw visibility into prioritisation, anomaly detection, and automated action. That changes the operating model from periodic reporting to continuously refreshed identity context.
Practical implication: treat IVIP as a correlation and decision layer, not just another dashboard.
Why non-human identities expose the limits of legacy IAM
Service accounts, API keys, certificates, and workload identities behave differently from people because they are created, reused, and left active at machine speed. Legacy IAM often assumes human-readable ownership, review cadences, and application-by-application administration, which breaks when identities multiply across cloud services and automation pipelines. The core issue is not only scale, but lifecycle opacity: teams lose sight of what exists, what is still needed, and what each identity can reach. That is where unified visibility becomes a control requirement rather than a reporting nice-to-have.
Practical implication: inventory NHI classes separately and test whether each one is visible in the same control plane.
How agentic AI changes the identity problem
Agentic AI pushes identity beyond static access assignment because agents can operate across tools, data sources, and tasks at runtime. Even when their access is mediated through existing credentials or approved workflows, their activity pattern creates a moving target for governance: what was authorised, what was used, and what should be reviewed are no longer trivially aligned. That means the most valuable control is not merely authentication at the edge, but continuous identity intelligence that can track relationships, tool use, and posture as the environment changes.
Practical implication: design review and monitoring around runtime behaviour, not only around initial credential issuance.
Threat narrative
Attacker objective: The objective is to exploit unmanaged identity complexity to maintain hidden access and reduce the organisation’s ability to detect or constrain it.
- Entry occurs through identity sprawl, where new SaaS applications, service accounts, and AI-driven workflows are added faster than the control plane can reconcile them.
- Escalation follows when fragmented IAM data prevents teams from seeing which identities are overexposed, reused, or still active after their original purpose has passed.
- Impact is the loss of trustworthy identity context, which makes access reviews, automation, and incident response slower and less reliable.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity visibility is becoming the gating control for modern identity governance. Without a unified view of identities, entitlements, relationships, and posture, every downstream control starts from partial data. That is true for human IAM, but it becomes more acute when service accounts and AI-driven workflows expand the number of identities that must be observed. The practitioner conclusion is straightforward: visibility is no longer a reporting layer, it is the prerequisite for control.
IVIP is a response to identity data fragmentation, not a substitute for governance design. Gartner’s new category reflects a market correction: organisations have accumulated more identity sources than their current operating model can reconcile. The issue is not the absence of tools, but the absence of a reliable data model that can support action across human, machine, and emerging autonomous identities. The practitioner conclusion is to evaluate whether your governance model can consume identity intelligence, not just whether it can display it.
Ephemeral identity visibility debt: identity programmes accumulate unresolved exposure when service accounts, API keys, and AI-mediated access paths cannot be seen quickly enough to be governed. That debt grows as identity count rises faster than review and correlation cycles. The practitioner conclusion is to measure how much of your identity estate remains outside continuous visibility, because that blind spot is now a first-order risk.
Agentic AI makes runtime identity intelligence more important than static access assignment. Once agents can act across tools and tasks, the question changes from who was granted access to what the system actually did with that access in motion. That means identity governance has to track relationships and posture over time, not just approve access at provisioning. The practitioner conclusion is to redesign controls for runtime observability, especially where agents can compound decisions quickly.
The market is moving toward identity intelligence as an operating assumption, not an add-on. IVIP signals that visibility, correlation, and action are converging into one governance layer. That convergence will pressure teams to collapse separate workflows for discovery, review, and remediation into a single operational loop. The practitioner conclusion is to prepare for identity control architectures that treat data quality as a security function.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 96% of security operations teams report critical blind spots, most commonly in cloud infrastructure (74%) and identity and access behaviour (67%).
- Read next: Identity Visibility and Intelligence Platforms (IVIP) Guide
What this signals
Identity visibility now sits upstream of nearly every identity control. When teams cannot see identities, entitlements, relationships, and posture in one place, recertification, anomaly detection, and remediation all slow down. That makes unified visibility a control prerequisite for programmes that span human IAM, NHI, and agentic AI.
Ephemeral identity visibility debt: the longer service accounts, API keys, and AI-mediated access paths remain outside a single control plane, the more governance debt accumulates. Teams should expect more manual reconciliation, weaker certification quality, and slower incident response until the visibility baseline is enforced.
For practitioners
- Map identity data silos Identify where identity, entitlement, posture, and activity data live separately across IAM, cloud, and SaaS systems, then document which controls depend on each source.
- Classify non-human identities separately Split service accounts, API keys, machine identities, and certificates into distinct inventories so lifecycle, ownership, and review can be measured by identity class.
- Test whether access reviews have enough context Check whether reviewers can see current entitlements, relationships, and recent activity for each identity before certification decisions are made.
- Establish a continuous identity visibility baseline Define the minimum identity data set required for operational decisions and track which systems still fall outside that baseline.
Key takeaways
- Identity visibility has shifted from a reporting preference to a prerequisite for governing complex identity estates.
- The pressure is coming from fragmented IAM data, expanding NHI populations, and early agentic AI use cases that outgrow legacy workflows.
- Teams that cannot assemble a single trusted view of identities and entitlements will struggle to automate decisions or prove control effectiveness.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Hidden entitlements across service accounts and machine identities are the core risk in this visibility problem. |
| NHI-01 — Improper Offboarding | Poor visibility leaves stale non-human accounts active after their purpose ends. | |
| Recommendation — Continuously inventory NHI entitlements and remove overexposed access paths when visibility gaps appear. Tie offboarding checks to identity visibility so stale non-human accounts are revoked promptly. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about knowing and governing access permissions accurately. |
| ID.AM-01 — Physical devices and systems are inventoried | The visibility challenge is an inventory problem across identity sources and assets. | |
| Recommendation — Use PR.AA-05 to validate entitlements against a current, trusted identity inventory. Extend inventory discipline to identity sources so control decisions are based on complete asset visibility. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | Poor identity visibility creates conditions that support credential misuse and lateral movement. |
| Recommendation — Map visibility gaps to TA0006 and TA0008 to prioritise identities most likely to support lateral movement. | ||
Key terms
- Identity Visibility and Intelligence Platform: An Identity Visibility and Intelligence Platform is a layer that correlates identity data across multiple tools into one risk picture. It does not replace existing controls. It makes them more useful by connecting events, relationships, configuration, and posture so teams can prioritise what matters.
- Identity Data Fragmentation: Identity data fragmentation is the condition where authoritative identity information is split across many systems that do not agree with one another. It weakens governance because reviews, dashboards, and audit evidence can no longer be trusted as a single source of truth.
- Identity visibility debt: The gap that appears when an organisation can list its assets but cannot reliably link them to owners, entitlements, or activity. It creates a false sense of control because inventory looks complete while access relationships remain hidden, stale, or unreviewed.
- Dynamic Ephemeral Identity: Dynamic Ephemeral Identity is a model in which credentials or authority exist only for a short operational window and are generated at runtime. It reduces the value of exposed secrets, but only if the environment can also limit what the identity is allowed to do while active.
What's in the full article
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- The exact IVIP feature set C1 associates with identity visibility, intelligence, and unified control
- The vendor's discussion of multi-agent identity management across human, machine, and AI identities
- Implementation detail on its connector model, unified data model, and graph-based relationship mapping
- The roadmap items C1 says it plans to add later in the year, including dashboards and security insights
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org