By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Orchid SecurityPublished August 23, 2026

TL;DR: Identity governance still fails where applications, service accounts, machine identities, and AI agents sit outside the governed layer, leaving organizations with incomplete visibility into who and what can access critical systems, according to Orchid Security. The real issue is not governance depth, but governance coverage: access that cannot be seen cannot be certified or controlled.


At a glance

What this is: This is a partnership announcement framed as an IGA coverage problem, with Orchid Security arguing that unknown identities inside applications remain outside traditional governance.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes all fail when identities exist outside the systems that certify, review, and revoke access.

By the numbers:

  • You can have excellent governance over 70% of your identity estate and still have absolutely no idea what is happening in the other 30%.

👉 Read Orchid Security's analysis of hidden identities and IGA coverage gaps


Context

Identity governance breaks down when the governance layer only sees part of the estate. In practice, that means applications, accounts, credentials, and permissions can exist outside certification and lifecycle control even when the central IAM programme appears mature. The key issue is coverage, not simply policy design.

That gap now spans human identities, service accounts, workloads, machine identities, and AI agents that authenticate through application-level access paths. If those identities are not discovered and mapped back into governance, IGA cannot review, revoke, or prove control over them. The result is a blind spot that grows with application sprawl.


Key questions

Q: How should security teams govern applications that cannot connect to an IdP?

A: Treat disconnected applications as a separate governance class, not as exceptions to be ignored. Assign an owner, define the approval path, document revocation evidence, and decide whether the app needs compensating controls or should be retired. If access still depends on tickets and spreadsheets, the programme is managing process, not enforcing control.

Q: Why do service accounts and machine identities matter under NIS2?

A: Service accounts and machine identities matter because they often carry the permissions that move data, trigger reports, and feed AI workflows. If those identities are over-privileged or left out of review cycles, the organisation cannot prove that access is proportionate or necessary. Under NIS2, that creates both security exposure and audit weakness.

Q: What breaks when AI agents inherit access from users and service accounts?

A: The main failure is that inherited access can be broader than the agent’s actual task, so privilege becomes easier to reuse than to govern. Once an agent can chain tool calls across systems, the original approval no longer describes the full blast radius. Security teams need to treat inherited access as a live identity surface, not a one-time provisioning artifact.

Q: Who is accountable when a shared application identity is abused?

A: Accountability should sit with the business owner of the entitlement, the application owner who granted it, and the IAM or governance team that certified it. Shared application identities fail when everyone assumes someone else will revoke them, so clear ownership and removal responsibility are essential.


Technical breakdown

Why application-layer discovery is the governance bottleneck

IGA systems govern what they can model. Application-layer discovery fills the gap between the central identity plane and the accounts, roles, permissions, and authentication methods embedded inside individual applications. Without that discovery step, governance tools inherit only partial truth, which means certifications and access reviews are based on incomplete inventories. The problem is not that the IGA engine is weak, but that it is asked to govern identities it never saw at onboarding time.

Practical implication: treat application discovery as a prerequisite for access governance, not as a downstream enrichment step.

Why hidden service accounts and machine identities create blind trust

Service accounts, API credentials, privileged local accounts, and machine identities often live outside the IdP and outside normal review cadences. They are still identities, but they are frequently created, reused, and inherited inside application teams without consistent governance metadata. That creates blind trust: the organisation assumes access is controlled because a system exists, when in fact the identity objects inside that system may never have been registered, classified, or recertified.

Practical implication: inventory non-human identities at the application layer and tie each one to an owner, purpose, and lifecycle state.

How AI agents widen the identity boundary

AI agents do not just consume access, they can carry credentials, inherit permissions, and interact with applications through access paths that were never modeled for governance. That makes them an NHI governance problem first and an AI problem second. When agent activity is mediated through service accounts, API keys, or delegated application access, the control issue is whether those identities are visible, attributable, and revocable in the same way as other non-human accounts.

Practical implication: extend IGA and NHI control points to any application path that can be used by an AI agent, directly or indirectly.


NHI Mgmt Group analysis

IGA coverage is now the limiting factor, not governance sophistication. Many programmes are optimized for certifications, access requests, and policy enforcement after identities are already in scope. That works only when the estate is accurately discovered and connected. The harder problem is the unknown 30% of identities, systems, and access paths that never enter the governance universe. Practitioners should treat coverage as the first control objective.

Application-owned identities are the new governance gap. Local accounts, embedded credentials, and inherited access relationships often sit inside applications that central IAM teams do not fully model. That creates a structural blind spot because the identity object exists, but the governance record does not. The implication is that access assurance cannot rely on the IdP alone; application reality has to be part of the control plane.

AI agents intensify an existing NHI problem rather than creating a separate one. When agents authenticate through service accounts, API keys, or inherited user permissions, the core issue is still whether those identities are visible and governable. The NHI boundary now includes runtime actors that can exercise access in ways application owners did not plan for. Practitioners need one governance model that spans service accounts, workloads, and agent-mediated access paths.

Invisible identities create audit weakness, not just operational risk. If an account is outside the certified inventory, recertification outcomes can never prove completeness. That undermines evidence quality for IAM, IGA, and PAM programmes because the question is not whether the control ran, but whether it ran over the full identity estate. Organisations should expect auditors to challenge coverage assumptions before they challenge policy design.

From our research:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to the same study.
  • For a lifecycle lens, the NHI Lifecycle Management Guide is the clearest next resource for provisioning, rotation, and offboarding.

What this signals

Identity coverage will become the first budget line in IGA programmes. With 85% of organisations lacking full visibility into third-party vendors connected via OAuth apps, the governance problem is no longer limited to access review quality. It is becoming a discovery and inventory problem first, which means teams that cannot enumerate identities will struggle to govern them at all.

Application-layer identity mapping will matter more than central policy volume. The organisations that can connect discovered identities back to ownership, lifecycle state, and access context will have a defensible programme story. Those that rely on the IdP as the system of record will continue to miss local accounts, machine identities, and delegated access paths that sit outside normal review cycles.

The next programme shift is from controlling known identities to proving coverage over unknown ones. That is where the Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs becomes relevant, because lifecycle discipline only works once the identity estate is actually visible.


For practitioners

  • Expand discovery beyond the IdP Map identities at the application layer, including local accounts, service accounts, API credentials, privileged roles, and inherited access relationships that never flow through central governance.
  • Assign ownership to every discovered identity Require each non-human identity to have a named owner, purpose, and lifecycle state so that access reviews and offboarding are based on accountable records rather than archaeology.
  • Close the gap between discovery and recertification Feed discovered application identities into the IGA review process before certifications run, otherwise recertification only validates a partial estate.
  • Model agent-mediated access as governed access Treat any AI agent that authenticates through service accounts, tokens, or delegated permissions as part of the same non-human identity scope and subject it to the same control mapping.

Key takeaways

  • The core issue is coverage, not governance depth, because identities outside the inventory cannot be certified or revoked with confidence.
  • Hidden application accounts, service accounts, and AI agent access paths are now part of the identity estate and need lifecycle ownership.
  • IGA programmes that cannot discover and map these identities will keep validating partial truth instead of real control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centres on undiscovered non-human identities outside governance scope.
NIST CSF 2.0ID.AM-1Asset management applies directly to identity discovery and coverage gaps.
NIST SP 800-53 Rev 5AC-2Account management governs lifecycle state for discovered identities.
NIST Zero Trust (SP 800-207)Zero Trust depends on knowing and continuously verifying the identities in scope.

Validate that application identities are explicitly in the trust boundary before access is granted.


Key terms

  • Data-Layer Discovery: Data-layer discovery is the practice of finding and classifying tools by observing actual data movement rather than relying on vendor lists or self-declarations. It is especially useful for shadow IT and shadow AI because it reveals what the tool touches, who uses it, and how sensitive the exposure is.
  • Governance Coverage Drift: Governance coverage drift is the gap between the access estate an organisation believes it controls and the access estate actually present across applications and identities. It emerges when discovery is incomplete, integrations lag, or review data does not reconcile cleanly to real entitlements.
  • Shadow Identity: A shadow identity is a machine identity created outside central governance, often by developers or automation tooling. These identities are dangerous because they bypass normal provisioning and offboarding controls, making them hard to inventory, review, and revoke before attackers find them.

What's in the full article

Orchid Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • How Orchid discovers identities, permissions, and authentication methods inside applications without relying on questionnaires
  • The application-layer context that helps move unknown identities into the governed environment
  • How SailPoint customers can use the integration to expand the identity universe under IGA control
  • Why AI agents, service accounts, and machine identities make application discovery a governance requirement

👉 Orchid Security's full post covers application discovery, governance coverage, and how hidden identities move into scope.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or NHI governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org