By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: AbovePublished May 20, 2026

TL;DR: Insider risk definitions built around employees and contractors no longer match the 2026 identity surface, according to Above’s analysis. AI agents, OAuth-connected apps, and lingering third-party access now sit inside the same harm model, which means program scope, ownership, and review processes must expand beyond Workday-era assumptions.


At a glance

What this is: This article argues that the classic insider definition built around named people is now too narrow because AI agents, OAuth apps, and other non-human identities can hold authorized access and create harm.

Why it matters: IAM, IGA, and insider risk teams need a broader identity model because governance, monitoring, and offboarding fail when the programme only tracks human users and overlooks non-human actors.

👉 Read Above's analysis of why the insider definition no longer fits 2026


Context

Insider risk programmes usually start with a person-centric assumption: if the subject is not a named employee or contractor, it is outside the control model. That assumption now breaks down because AI agents, OAuth-connected applications, service accounts, and long-lived third-party access can all hold authorised access, act inside the environment, and create harm. The primary issue is no longer just who can log in, but which identities the programme is actually governing.

The article’s core point is that the 2018-era definition of insider was built for a narrower identity surface than most enterprises now operate. As organisations add autonomous tooling, delegated app access, and external integrations, the governance model must widen or it will keep missing exposure that is already inside the trust boundary. For identity teams, this is as much an IAM and lifecycle problem as it is an insider threat problem.


Key questions

Q: What breaks when an insider programme only tracks employees and contractors?

A: It misses the identities that now create real exposure outside HR records, especially service accounts, OAuth apps, and AI agents. Those identities can hold authorised access, persist after the original use case changes, and create harm without ever appearing in a traditional insider roster. The result is blind spots in monitoring, review, and offboarding.

Q: Why do OAuth-connected third-party apps create identity risk?

A: OAuth-connected apps extend trust beyond the organisation’s own perimeter into a vendor’s security posture. If the integrator is compromised, attackers can inherit downstream access through valid tokens without attacking the customer directly. The risk grows when grants are broad, refresh-capable, or left in place without ownership review.

Q: How should security teams govern AI-powered insider threats?

A: Treat AI-powered insider threat as an identity governance problem first. Track human users, machine identities, and AI-assisted workflows together, then apply ownership, approval, and logging to each access path. Deepfakes and model access only become dangerous when the organisation cannot verify who acted, what credentials were used, and whether the action stayed within scope.

Q: Should organisations expand insider risk ownership beyond security?

A: Yes. If insider risk now includes human identities, delegated apps, service accounts, and agents, then no single team owns the whole problem. Security may coordinate the policy, but IAM, application owners, HR, legal, and business leaders all own pieces of the lifecycle and the approvals that make the access real.


Technical breakdown

Why person-centric insider definitions miss non-human identities

Traditional insider programmes were designed around employees, contractors, and other people in formal HR systems. That works when the primary risk is human misconduct or error, but it fails when the organisation has service accounts, OAuth apps, and AI-driven workflows that can also hold authorised access. The mechanism problem is not detection alone. It is that the data model, ownership model, and review model are all built around a human roster, so non-human identities never enter the control system in the first place. Practical implication: map the insider scope to identity type, not just employment status.

Practical implication: expand the insider control universe to include non-human identities with authorised access, not just users in HR.

How authorised app-to-app access becomes insider exposure

OAuth-connected apps are a delegated identity pattern, not just a convenience feature. A user or admin grants scoped access, then the application continues to operate with that scope until someone revokes it. That means access can outlive the business purpose that created it, and the trust relationship often sits outside standard joiner-mover-leaver processes. In practice, many organisations know the app approval moment but not the full lifecycle of the resulting identity. Practical implication: treat delegated app access as governed identity infrastructure, with ownership, review, and revocation like any other credentialed access path.

Practical implication: bring delegated app access into lifecycle governance, ownership review, and revocation workflows.

Why service accounts and AI agents change the insider threat boundary

Service accounts and AI agents complicate insider thinking because they can act with authorised access without a person continuously driving each action. A human may provision the access, but the risk unfolds through system behaviour, not just human intent. That changes what must be monitored: the programme needs to understand scope, usage patterns, and business ownership for identities that can operate at machine speed or in response to prompts. Practical implication: align identity governance and insider risk monitoring so machine identities are reviewed as operational actors, not orphaned technical accounts.

Practical implication: monitor machine identities as active operational actors, with clear owners and behavioural baselines.


Threat narrative

Attacker objective: The objective is to exploit authorised but poorly governed access paths that sit outside the organisation’s human-centric insider controls.

  1. Entry occurs through an authorised non-human identity such as an OAuth app, service account, or agent with access broader than the programme recognises.
  2. Escalation happens when that identity’s scope persists beyond its original business purpose or is used in a way the insider programme never models.
  3. Impact follows when the identity can move data, expose systems, or operate in ways that would have been treated as insider harm if a person had done the same.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Insider risk is now an identity-classification problem, not just a behaviour problem. The working definition of insider determines what the programme sees, measures, and governs. If the definition stops at employees and contractors, every non-human identity with authorised access remains outside the risk model even when it can cause equivalent or greater harm. The practitioner conclusion is simple: insider scope has to follow identity type, not org chart assumptions.

OAuth-connected applications are insiders because delegated access creates durable trust without durable oversight. The access grant is usually explicit, but the lifecycle is not. That mismatch creates governance drift: the organisation remembers who approved the app, but not who still owns the access, when it should be revoked, or whether the access still matches the original need. The conclusion for practitioners is that delegated app access must be treated as governed identity, not shadow convenience.

AI agents expose the limits of human-paced insider programmes. A person-centric insider model assumes there is a stable human operator behind access decisions. That assumption fails when the actor is autonomous enough to initiate actions, choose tools, and time execution without approval gates. The implication is not merely that a new control is needed; it is that the programme’s definition of accountable insider behaviour must be rewritten for machine-paced action.

Identity lifecycle governance is now the missing bridge between IAM and insider risk. Joiner-mover-leaver processes, access reviews, and offboarding were built to reduce human privilege drift, but the same discipline must now govern service accounts, apps, and agents. Without that bridge, insider risk programs stay focused on intent while the actual exposure sits in unmanaged authorised access. Practitioners should align insider governance with lifecycle controls across all identity classes.

Concept: identity blast radius. The article points to a broader notion of how far authorised access can extend before governance catches up. When humans, apps, and agents all hold access with different lifecycles, the blast radius is no longer defined by user count alone but by the breadth, persistence, and reuse of every identity in the chain. Practitioners should measure risk by reachable access, not just by named insiders.

From our research:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
  • A second finding in the same study shows that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility.
  • For broader context on where these gaps surface in real environments, see 52 NHI Breaches Analysis.

What this signals

Identity governance has to move from roster-based thinking to access-based thinking. Once AI agents and OAuth apps are treated as insiders, the control problem becomes lifecycle ownership, not just threat detection. Teams that still anchor governance in HR data will keep undercounting who can actually act inside the environment.

OAuth sprawl is now a governance signal, not just an app-approval inconvenience. As delegated access expands, the gap between approved identity and actually managed identity widens. Practitioners should expect more pressure to prove ownership, review cadence, and revocation discipline across non-human access paths.

From our research, 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, and that visibility gap is exactly where insider scope drifts out of view. This is where lifecycle governance and the Ultimate Guide to NHIs become practical, because the issue is not just access creation but access persistence and accountability.


For practitioners

  • Recast the insider definition Update the programme charter so it explicitly covers humans, service accounts, OAuth apps, and autonomous agents that hold authorised access and can cause harm. Use that definition to reset scope, reporting, and ownership.
  • Inventory non-human identities inside the insider programme Build a complete register of delegated apps, machine identities, and agent accounts that currently sit outside HR-driven data models. Tie each identity to a business owner and an offboarding path.
  • Bind access reviews to identity lifecycle events Trigger recertification and revocation reviews when an app, agent, or service account changes purpose, ownership, or integration scope. Do not wait for annual human review cadences to catch machine access drift.
  • Extend insider monitoring to machine behaviour Baseline expected access patterns for non-human identities and alert on unusual data movement, broader-than-expected scope, or stale approvals that no longer match the business use case.
  • Align governance ownership across security, IAM, and business teams Assign explicit accountability for each non-human identity class so security is not left owning behaviour without authority, and business owners are not left approving access they do not understand.

Key takeaways

  • The article’s core argument is that insider risk definitions built around named people no longer match the identity surface most enterprises now operate.
  • The biggest governance gap is not only detection but scope: non-human identities can hold authorised access and still sit outside the insider programme.
  • Expanding lifecycle ownership across humans, apps, service accounts, and agents is the control shift that makes the new definition operational.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on unmanaged non-human identities and insider scope drift.
NIST CSF 2.0PR.AC-4Access permissions and lifecycle governance are the article’s main control theme.
NIST SP 800-53 Rev 5IA-5The article highlights the persistence of authorised access and credential ownership gaps.
NIST Zero Trust (SP 800-207)The post argues for tighter verification of who or what holds access inside the boundary.

Map non-human identities into governance scope and assign ownership before access drifts outside review.


Key terms

  • Insider Risk Management: Insider Risk Management is the practice of detecting, investigating, and reducing harm caused by legitimate identities misusing access. It covers human error, malicious insiders, compromised accounts, and increasingly AI-driven actors that can move sensitive data without breaking perimeter controls.
  • Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
  • Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.

What's in the full article

Above's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article’s original breakdown of how the insider definition evolved from a human roster model into a broader identity model.
  • The full discussion of AI agents, OAuth-connected apps, and third-party relationships as part of the insider surface.
  • The author’s own working draft of a 2026 insider definition and the governance questions it raises for CISOs.
  • The article’s closing prompt set for insider charter reviews and ownership alignment.

👉 Above's full blog post expands on the identity classes, ownership gaps, and insider charter questions behind the argument.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org