By NHI Mgmt Group Editorial TeamBased on Veza: “Taming the M&A Chaos: How Veza Addresses Identity Security Risks During Mergers, Acquisitions, and Divestitures” (February 12, 2026)

TL;DR: Mergers, acquisitions, and divestitures create identity sprawl across human accounts, service accounts, secrets, and AI agents, leaving visibility gaps that legacy IGA and cloud identity tools cannot close, according to Veza. The core issue is not just integration speed but the loss of trustworthy permission-level control across both combined and separated environments.


At a glance

What this is: This is an analysis of why M&A and divestiture work creates identity sprawl across human and non-human identities, with hidden permissions, ownership gaps and review blind spots as the central finding.

Why it matters: It matters because IAM and NHI programmes have to prove who can access what while identities are being combined or carved apart, and M&A is where weak lifecycle control becomes a compliance and security problem.


Context

Mergers, acquisitions and divestitures stress identity governance because the new estate is rarely built from one consistent model. Multiple directories, identity providers, SaaS stacks, CI/CD systems and secrets managers arrive with different definitions of user, role and access, so the combined environment quickly loses a trustworthy source of truth.

The core problem is not simply integration speed. It is that permission-level visibility, ownership and lifecycle control break down when organisations have to combine or separate access while business operations, audit demands and regulatory scrutiny continue at the same time. That makes M&A a direct test of identity governance maturity across human IAM, NHI and AI agent oversight.


Key questions

Q: What breaks when identity governance is not aligned during M&A?

A: The first break is usually visibility, followed by inconsistent provisioning and delayed revocation. When two identity estates are merged without a shared model, duplicate accounts, misclassified roles, and stale privileges persist. That creates operational friction and makes it much harder to prove who should have access to what across the combined environment.

Q: Why do non-human identities make M&A risk harder to control?

A: Non-human identities are harder to govern because they often have persistent permissions, limited ownership and no obvious business custodian. During M&A, that means service accounts, API keys and automation identities can carry hidden access into the new environment or across a divestiture boundary without being reviewed properly.

Q: How should teams prove access is separated during a divestiture?

A: Teams should prove separation by testing who can still reach the systems, data and automation that belong to the other side of the transaction. The useful evidence is not a broad certification summary but a targeted boundary check that shows inherited access has been removed and remaining operations still function.

Q: What should IAM teams prioritise after a merger closes?

A: They should prioritise permission truth, ownership assignment and risk-based review of the identities most likely to preserve hidden access. That means focusing on effective permissions, orphaned accounts and non-human identities before consolidating directories or standardising roles.


Technical breakdown

Why fragmented identity stores break permission truth

In M&A, each company brings its own identity stack and its own semantics for users, groups, roles and entitlements. A directory can show that an account exists, but not always the effective permissions inherited through nested groups, SaaS sharing layers or cloud role chains. When those structures are merged, legacy IGA often struggles to normalise what access actually means in plain language. That is why permission truth becomes unstable during integration: the control plane is split across systems that do not agree on the same identity model.

Practical implication: Practitioners need a permission-level inventory before they can certify access or separate entities with confidence.

How non-human identities and AI agents multiply inherited access risk

M&A does not just add more users. It also imports service accounts, API keys, bots, automation identities and AI agents that often have broad, persistent access and no clear owner. Those identities are harder to review because they are not managed like employee accounts, yet they can touch production systems, secrets and cloud roles at scale. The risk is not merely volume. It is inherited machine access that outlives the business context that created it, especially when ownership is unclear and review cycles are human-paced.

Practical implication: Teams need to map ownership and effective permissions for every non-human and agent identity before consolidation or carve-out work begins.

Why divestiture requires access separation, not just offboarding

Divestiture is the inverse of integration. Instead of absorbing identities, organisations must prove that access has been removed cleanly and that the remaining business still functions. That requires validating which identities, roles and service accounts cross the new boundary, then confirming that access no longer spans the separated entities. Manual scripts and broad access reviews are poor fits because they miss edge cases, especially where inherited group membership or shared automation still reaches both sides of the transaction.

Practical implication: Security and IAM teams should treat divestiture as a boundary-validation exercise, not a routine deprovisioning task.


Threat narrative

Attacker objective: The objective is to retain or exploit access that should have been removed, hidden or revalidated during the transaction.

  1. Entry occurs when two identity estates are combined or separated and inherited accounts, groups and service identities are carried forward without full reconciliation.
  2. Credential and permission exposure follows when dormant, orphaned or overprivileged identities remain active across directories, SaaS apps and cloud roles.
  3. Escalation happens as nested groups, shared automation and unclear ownership preserve access that no one can confidently attest or revoke.
  4. Impact is audit failure, segregation-of-duties violations, residual access after divestiture and expanded attack surface across both organisations.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity sprawl is the real M&A control failure, not integration delay. When identity estates are merged or carved apart, the loss of permission-level truth is what creates security and compliance exposure. Legacy IGA can struggle with nested inheritance and role translation, so the programme cannot prove who really has access to what. The practitioner takeaway is that M&A should be governed as a control-verification event, not just a systems project.

Non-human identity ownership becomes a transaction risk the moment a deal closes. Service accounts, API keys and automation identities often move between business units without clear accountability, which means the access they carry outlives the organisational context that created it. This is especially dangerous in merged environments where dormant or overprivileged machine access can be overlooked during human-focused review cycles. The field should treat NHI ownership mapping as a standard M&A workstream, not an optional cleanup step.

Inherited machine access is a hidden attack surface because it is rarely reviewed at deal speed. M&A creates a long tail of access that is easy to preserve and hard to explain, especially when cloud roles, CI/CD secrets and AI agent identities are involved. That is why the governance problem is not just who has access today, but who can still exercise old access paths after the transaction changes the business boundary. The practitioner conclusion is to validate ownership and effective permissions before operations inherit the risk.

Targeted micro-certification is a better fit than broad recertification during divestiture. Large certification campaigns are slow and often too coarse to prove that access has been separated cleanly across the new boundary. A narrower model focused on specific users, service accounts and roles gives the organisation evidence it can defend to auditors and deal teams. The practitioner implication is to use boundary-specific validation where the transaction timeline leaves no room for generic access review noise.

M&A is pushing the identity market toward permission graphs, not role-only governance. Transaction-driven environments need unified visibility across humans, NHIs and AI agents because role labels alone do not show effective access or inherited exposure. That shifts the category toward models that connect identity, entitlement and ownership across systems rather than chasing one directory at a time. Practitioners should re-evaluate any governance approach that cannot show permission truth across both combined and separated estates.

From our research library:

What this signals

Identity visibility has to move from directory-level reporting to permission-level proof. M&A programmes that stop at account counts or role inventories will miss inherited access paths, especially where nested groups, cloud roles and service identities overlap. The practical shift is toward a unified access graph that can show effective permissions across both the combined and separated estate.

Non-human identity governance becomes decisive the moment organisational boundaries change. Service accounts, API keys and automation identities are often the least visible part of the inherited environment, yet they can preserve access long after a deal structure changes. That makes ownership, lifecycle status and privilege scope the first questions to answer, not the last.

Boundary validation should replace broad comfort metrics during divestiture. If an organisation cannot show that access from one entity no longer reaches the other, it has not completed the separation work. The governance signal to watch is whether access review moves from enterprise-wide checkbox activity to transaction-specific proof of least privilege and segregation of duties.


For practitioners

  • Map effective permissions before integration Inventory the acquired or divested environment at permission level, not just by directory, group or role, so you can see what access actually exists before it is merged or removed.
  • Assign ownership to all non-human identities Identify service accounts, API keys, bots, cloud roles and AI agents, then attach a named owner and business purpose before they are carried into the new operating model.
  • Validate access boundaries during divestiture Use boundary-specific reviews to prove that identities from one entity cannot still reach systems, data or automation in the separated entity.
  • Replace broad recertification with targeted micro-certifications Focus certification effort on the identities and entitlements that determine whether the deal can close cleanly, rather than running slow enterprise-wide review campaigns.

Key takeaways

  • M&A creates identity sprawl that hides effective access, which is why directory-level visibility is not enough for either integration or separation.
  • The highest-risk gap is unmanaged non-human and AI agent access, because inherited service accounts and automation can survive the transaction with no clear owner.
  • The control that changes the outcome is permission-level proof of who can still access what, backed by boundary-specific validation and targeted certification.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIM&A often imports inherited service accounts and automation with unclear ownership.
NHI-05 — Overprivileged NHIThe article centres on broad, persistent permissions carried through acquisition and divestiture.
NHI-01 — Improper OffboardingDivestiture requires removing access cleanly from the carved-out entity and its identities.
Recommendation — Inventory inherited NHI access and assign accountable owners before integrating estates. Right-size non-human privileges to the minimum effective access needed during transaction work. Validate that offboarded identities no longer retain access across the separated boundary.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on proving who can access what across merged and separated environments.
Recommendation — Map entitlements and effective permissions before approving integration or separation decisions.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementPersistent access in NHIs and AI agents creates paths for credential abuse and spread.
Recommendation — Correlate inherited credentials with lateral movement paths and revoke excess access.

Key terms

  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
  • Permission Level: A permission level defines how much action a role can take on a record or task, such as View, Create, Edit, or Full. Higher levels expand operational power and can introduce control risk if applied too broadly. Careful level selection is essential to keep access aligned with actual job responsibilities.
  • Non-Human Identity Ownership: Non-Human Identity Ownership is the assignment of clear accountability for every machine identity used by software, services, or AI systems. It defines who creates, approves, rotates, monitors, and retires credentials such as keys, tokens, certificates, and service accounts, so each identity has a responsible human or team throughout its lifecycle.
  • Micro-Certification Campaign: A micro-certification campaign is a recurring access review used to validate whether permissions still match current business need. It is a lightweight governance control that checks access in smaller, more frequent cycles, helping teams catch excessive or stale privileges before they become persistent risk.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org