TL;DR: By 2028, 70% of CISOs will use an identity visibility and intelligence platform to reduce IAM attack surface, according to Veza’s citation of Gartner research. The shift reflects a programme reality: visibility, observability, and remediation now define whether human, machine, and AI identities can be governed at scale.
At a glance
What this is: This is a vendor-cited analysis of Gartner’s view that identity visibility and intelligence platforms will become central to shrinking IAM attack surface across human, machine, and AI identities.
Why it matters: It matters because IAM teams cannot govern access they cannot see, and visibility gaps now cut across NHI, autonomous systems, and human identity programmes alike.
By the numbers:
- By 2028, 70% of Chief Information Security Officers will utilize an identity visibility and intelligence platform to shrink their IAM attack surface.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- Only 5.7% of organisations have full visibility into their service accounts.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
👉 Read Veza's analysis of Gartner's identity visibility and intelligence platform view
Context
Identity visibility is the ability to map who or what has access to which systems, data, and actions, then understand whether that access is excessive, stale, or risky. In IAM programmes, the problem is rarely a lack of policy language; it is a lack of enough trusted visibility to prove where identity risk sits across users, service accounts, tokens, and AI-connected workflows.
That gap is widening because identity estates now span human users, non-human identities, and emerging autonomous systems. When access is distributed across cloud, SaaS, and machine-to-machine paths, traditional IAM reporting often sees accounts but not effective privilege, relationship context, or remediation priority. That is why identity visibility and intelligence has become a governance problem, not just an inventory problem.
Key questions
Q: How should security teams reduce the attack surface of identity systems?
A: Security teams should reduce identity attack surface by removing standing privilege, closing unnecessary trust paths, tightening authentication controls, and continuously monitoring directory changes. The priority is not just hardening servers. It is shrinking the number of identity actions an attacker can convert into authority, persistence, or lateral movement.
Q: Why do identity visibility gaps make privilege reduction so difficult?
A: Because entitlement lists do not show how access is inherited, chained, or exercised in practice. Without observability, teams cannot tell which access paths are dormant and which are operationally dangerous. That forces over-review of low-risk accounts while leaving the most exposed identities under-governed.
Q: What breaks when organisations treat identity reporting as the same thing as control?
A: Reporting tells you what exists, but control requires knowing what can be reached and what can be changed. When teams confuse the two, they miss inherited access, orphaned relationships, and stale permissions that continue to expand blast radius. Visibility must feed remediation, or it has limited security value.
Q: What should IAM teams prioritise first in a modern identity strategy?
A: They should prioritise a unified identity foundation, then automate the highest-risk lifecycle events. If identity data remains fragmented across HR, directory, cloud, and SaaS systems, every downstream control will be inconsistent. Once the foundation is in place, offboarding, temporary access expiry, and entitlement discovery become much easier to govern.
Technical breakdown
Why identity visibility matters for IAM attack surface
Identity visibility platforms combine entitlement data, authentication context, and resource relationships to show effective access rather than just assigned access. That matters because attack surface is created by the combination of standing privilege, unused credentials, inherited permissions, and opaque third-party paths. For CISOs, the value is not the dashboard itself. It is the ability to identify which identities can actually reach sensitive assets, how that access was granted, and where remediation should start.
Practical implication: build identity inventories around effective access paths, not just directory records.
How observability changes identity governance decisions
Observability adds runtime context to identity data, showing how identities behave after authentication or issuance. In practice, that means separating low-risk accounts from credentials that are repeatedly used across sensitive workloads, cloud services, or delegated applications. It also helps distinguish policy from reality, which is where many IAM programmes fail. If an entitlement exists but is never exercised, or if a machine credential is reused across environments, remediation should follow observed behaviour, not assumptions.
Practical implication: prioritise access review and remediation based on real use, not static entitlement lists.
Remediation for human, machine, and AI identities
Remediation closes the loop by changing or removing access after visibility and observability identify the risk. For human identities, that often means narrowing roles or removing stale access. For non-human identities, it means rotating secrets, removing standing privilege, and validating ownership. For AI-connected identities, remediation also needs to account for tool access, delegated permissions, and session-level scope. The control objective is the same across actor types, but the execution mechanics differ materially.
Practical implication: align remediation playbooks to the actor type, especially where secrets and delegated access are involved.
Threat narrative
Attacker objective: The attacker objective is to turn weak identity visibility into broad, difficult-to-detect access across human and non-human accounts.
- Entry occurs when exposed credentials, overbroad entitlements, or delegated access paths give attackers a foothold into identity infrastructure.
- Escalation follows when standing privilege, reused tokens, or weak governance lets the attacker move from one account or workload to broader access.
- Impact is credential compromise, account takeover, session compromise, or unauthorised access to sensitive systems and data.
Breaches seen in the wild
- Salesloft OAuth token breach — hackers stole OAuth tokens to access Salesforce data via Salesloft.
- Internet Archive breach — unsecured GitLab authentication tokens exposed 31M Internet Archive accounts.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity visibility is now a governance control, not a reporting feature. Once identities span users, service accounts, tokens, and AI-connected workflows, basic directory views stop being sufficient for risk reduction. The operational question is no longer who exists in the directory, but which identities can actually reach sensitive assets and through which paths. Practitioners should treat identity visibility as part of control design, not post-hoc reporting.
Effective access is the metric that matters. Assigned entitlement counts tell you little about actual blast radius if permissions are inherited, dormant, or chained through third-party paths. The better model is to prioritise identities with standing access to high-value resources, then trace how those privileges were granted and whether they still serve a business purpose. That is the only way to make remediation defensible and repeatable.
There is a runtime governance gap between policy and use. Visibility alone does not close attack surface if organisations cannot connect what was approved to what is actually exercised. This is where access intelligence becomes material: it exposes stale access, orphaned relationships, and privilege paths that policy reviews miss. Practitioners should assume review cadence will lag identity behaviour unless runtime evidence is part of the control loop.
Human IAM, NHI governance, and AI identity oversight are converging around the same control question. The actor type changes the mechanics, but not the requirement to know what access exists, why it exists, and how quickly it can be reduced. That convergence is why IVIP-style approaches are gaining attention. Teams should prepare for one governance model with three execution paths, not three unrelated programmes.
Identity blast radius is becoming the decisive planning concept. The critical issue is not just whether an identity is privileged, but how far a compromised identity can move before it is detected and constrained. That makes visibility and remediation a lifecycle discipline, not a one-time cleanup exercise. Practitioners should use blast radius as the common language across IAM, PAM, and NHI operations.
From our research:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which leaves most machine access governance operating with partial evidence.
- Use Ultimate Guide to NHIs , Key Challenges and Risks to connect visibility gaps to privilege sprawl and remediation scope.
What this signals
Identity visibility will increasingly be judged by whether it changes decisions, not by whether it produces reports. Teams need access intelligence that shortens review cycles, prioritises blast radius, and feeds remediation directly into IAM, PAM, and NHI workflows. With NHIs outnumbering human identities by 25x to 50x in modern enterprises, the governance model has to scale around effective access rather than manual enumeration.
Identity blast radius should become a standing metric in IAM programme reporting. That metric is more useful than raw account counts because it ties visibility to what an attacker can actually reach. Practitioners should pair that with the NIST zero trust view of continuous verification and the NIST Zero Trust Architecture guidance to keep access decisions tied to current context.
Runtime access intelligence is the bridge between NHI governance and emerging AI identity oversight. As AI-connected identities gain delegated access, teams will need the same kind of lifecycle evidence they already struggle to assemble for service accounts. The lesson is simple: if an identity can act, it must also be observable, reviewable, and revocable before the action path becomes the control gap.
For practitioners
- Map effective access paths Inventory which identities can reach sensitive systems through inherited roles, delegated permissions, and third-party relationships. Use that map to rank remediation by reachable blast radius, not by account count.
- Separate standing privilege from active need Review service accounts, machine credentials, and privileged users for access that persists without a current business owner or operational requirement. Remove access that is not tied to a documented use case.
- Prioritise runtime evidence in access reviews Base review decisions on actual usage, last access, and observed sessions so that dormant accounts and rarely used entitlements can be trimmed before they become attack paths.
- Align remediation to actor type Use different playbooks for human users, non-human identities, and AI-connected identities. Rotate secrets, revoke orphaned tokens, and narrow delegated permissions where the identity subject is a machine or agent.
Key takeaways
- Identity visibility is becoming a control layer because IAM programmes cannot reduce risk for identities they cannot fully see.
- The scale problem is already established: excessive privilege and limited service account visibility make attack surface reduction a governance issue, not just an operational one.
- Practitioners should use effective access, runtime evidence, and actor-specific remediation to shrink blast radius across human, NHI, and AI identity estates.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Identity visibility and access review map directly to access permissions governance. |
| NIST Zero Trust (SP 800-207) | Zero trust depends on continuous verification of identity and access context. | |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to reducing the identity attack surface discussed here. |
Use zero trust principles to ensure identity decisions reflect current context, not static assignment.
Key terms
- Identity Visibility and Intelligence Platform: An Identity Visibility and Intelligence Platform is a layer that correlates identity data across multiple tools into one risk picture. It does not replace existing controls. It makes them more useful by connecting events, relationships, configuration, and posture so teams can prioritise what matters.
- Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Runtime Access Intelligence: Context collected while an identity is active, such as usage patterns, session behaviour, and current reachability. It helps teams distinguish dormant access from operational risk and supports faster, better-targeted remediation decisions across humans, service accounts, and AI-connected identities.
What's in the full article
Veza's full analysis covers the operational detail this post intentionally leaves for the source:
- Gartner-aligned explanation of the IVIP model and how the Access Graph is used to reduce identity attack surface.
- Practitioner-level breakdown of visibility, observability, and remediation as separate governance capabilities.
- Context on how CISOs can apply the model across human, machine, and AI identities.
- The source article's framing of why these capabilities are becoming mandatory for IAM risk reduction.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org