By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: VezaPublished February 12, 2026

TL;DR: Mergers, acquisitions, and divestitures create identity sprawl across human accounts, service accounts, secrets, and AI agents, leaving visibility gaps that legacy IGA and cloud identity tools cannot close, according to Veza. The core issue is not just integration speed but the loss of trustworthy permission-level control across both combined and separated environments.


At a glance

What this is: M&A activity turns identity into an access-control problem spanning users, NHIs, and AI agents, with the article arguing that fragmented systems and permission sprawl make traditional IGA insufficient.

Why it matters: IAM, IGA, PAM, and NHI teams have to treat transactions as lifecycle events with audit, deprovisioning, and ownership requirements, or risk leaving inherited access in place.

By the numbers:

👉 Read Veza's analysis of identity governance in mergers, acquisitions, and divestitures


Context

M&A identity governance starts with a simple problem statement: the organisation cannot reliably answer who has access to what when identities, directories, applications, and permissions have been inherited from multiple operating models. That gap becomes more severe when non-human identities and AI agents are embedded in pipelines, clouds, and SaaS estates that were never designed to reconcile cleanly.

Traditional IGA tools were built around roles, groups, and periodic reviews, but M&A events expose the limits of that model because effective permissions, nested inheritance, and orphaned identities matter more than directory records. In practice, identity debt accumulates faster than integration projects can resolve it, which is why transaction-driven access governance so often becomes an audit and operational risk.

For NHI programmes, the transaction problem is especially acute because service accounts, API keys, secrets, and automation identities often lack clear owners and are rarely reviewed during change events. The article's core message is that integration and separation both fail when identity visibility is incomplete.


Key questions

Q: What breaks when identity integration is delayed in a merger?

A: When identity integration is delayed, the merged organisation inherits inconsistent authentication, uneven access policy, and manual exception handling. That creates a security gap and slows user productivity because access decisions remain split across two operating models. The practical fix is to establish one authoritative identity layer early so policy harmonisation can happen before broad user onboarding.

Q: When should organisations prioritise permission-level visibility over broader IGA cleanup?

A: They should prioritise permission-level visibility as soon as a transaction is underway or anticipated, because access questions become time-critical during due diligence, integration, and divestiture. Visibility into what identities can do is the prerequisite for any cleanup, review, or deprovisioning effort. Without it, remediation work is blind and often creates outages or missed exposures.

Q: What do security teams get wrong about NHI governance in M&A programmes?

A: They often treat service accounts and API keys as secondary to human identities, even though those machine accounts can retain broad access across inherited systems. They also underestimate ownership gaps, which means orphaned credentials survive the transaction. In practice, NHI governance must be built into due diligence and separation planning, not added after human account migration is complete.

Q: Who is accountable for access separation when divestitures involve shared systems?

A: The acquiring and divesting organisations both remain accountable until access separation is provable, because shared systems create overlapping control obligations. Regulatory teams will expect evidence that privileged access, orphaned accounts, and residual entitlements were identified and removed without breaking the remaining business. The practical answer is to assign explicit ownership and validate each removal step.


Technical breakdown

Why fragmented identity stores break permission truth

Mergers and divestitures rarely join cleanly because each organisation brings different identity providers, directory structures, SaaS entitlements, and service-account models. A user, group, or role can mean something different in each system, and nested inheritance often hides the real effective permission. Permission-level visibility matters more than app-level inventory because compliance and separation decisions depend on what an identity can actually do, not what it is called in a directory.

Practical implication: build a normalised permission model before remediation, or access decisions will be based on incomplete directory data.

Why NHI ownership becomes the hidden M&A risk

Non-human identities multiply during integration because scripts, cloud roles, API keys, and automation accounts are often created faster than ownership and lifecycle controls can be assigned. These identities frequently carry broad, persistent access and may remain dormant until a transaction or system change exposes them. In an M&A context, orphaned ownership is not a side issue. It is a control failure that blocks deprovisioning, attestation, and audit evidence.

Practical implication: inventory NHI ownership as part of deal due diligence and tie each account to a named business or technical owner.

How divestiture access separation differs from routine offboarding

Divestiture is not standard leaver processing because access must be removed across shared systems without breaking the remaining business. That requires validating group inheritance, resource-level entitlements, and downstream service-account dependencies before access is cut. Micro-certifications and guardrail policies are useful here because broad access reviews are too slow and too coarse for transaction timelines.

Practical implication: use targeted certification and dependency mapping to separate access in layers instead of revoking blindly.


Threat narrative

Attacker objective: The practical objective is to exploit inherited access before identity teams can normalise, review, and remove it, enabling unauthorised access or transaction disruption.

  1. entry: The article describes how fragmented identity stores, inherited permissions, and unknown access arrive with acquisitions and divestitures, creating an exposure window before governance teams can reconcile the estate.
  2. escalation: Overprivileged users, orphaned accounts, and unmanaged NHIs retain access across merged systems, while legacy tools miss effective permissions, nested groups, and resource-level exposure.
  3. impact: The result is compliance failure, segregation-of-duties violations, stalled transactions, and a wider attack surface across both combined and separated environments.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity debt is the true M&A security liability. The article is right to frame merger and divestiture risk as more than a directory-consolidation problem. What breaks first is not the login flow but the trust that identity data is complete enough to support legal, operational, and audit decisions. When effective permissions are hidden behind nested groups, inherited roles, and system-specific semantics, the organisation cannot prove separation or continuity with confidence. Practitioners should treat identity debt as a transaction-level control risk, not an implementation inconvenience.

Non-human identities become the most underestimated source of post-deal exposure. Service accounts, API keys, cloud roles, automation identities, and AI agents often outlive the business context that created them. In an M&A event, that means inherited machine access can persist without a clear owner, especially when the acquiring team is focused on human account migration. The result is a governance gap that traditional IGA reviews miss because they were not built to surface ownership and effective permission at machine scale. The implication is straightforward: NHI oversight must be part of deal diligence, not a later hygiene task.

Permission-level visibility is the named concept that determines whether integration succeeds. Directory-level views are too shallow for transaction governance because they tell you who exists, not what they can do. The article's emphasis on natural-language effective permissions reflects the real requirement for M&A work: decision-makers need resource-level truth fast enough to separate, consolidate, and certify access under audit pressure. Without that view, every remediation step is guesswork. Practitioners should insist on permission-level visibility as the baseline for any integration or divestiture programme.

Divestiture governance is the harder test of identity maturity. Integration can absorb some slippage because the business wants speed, but carve-outs demand precision because the organisation must remove access without breaking the remaining entity. That makes offboarding, targeted certification, and guardrail enforcement the real maturity markers. If a programme can only manage joiners and movers but cannot prove clean separation, it is not ready for transaction work. Identity teams should measure success by the ability to withdraw access surgically and demonstrate the outcome to auditors.

AI agent identities extend the M&A problem into autonomous territory. The article correctly groups AI agents with NHIs because both can inherit access that no human explicitly revalidates. But autonomous behaviour changes the governance question: least privilege at provisioning time stops being sufficient when the actor can select actions and tools at runtime. That means transaction governance must begin to distinguish static machine access from runtime-decisioning access. Practitioners should plan for governance models that can cope with both inherited access and autonomous execution paths.

From our research:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which explains why transaction-driven access reviews so often miss inherited machine credentials.
  • That visibility gap is why the Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs matters when M&A work needs precise offboarding and ownership control.

What this signals

Permission-level visibility will become the baseline expectation for transaction governance. M&A programmes are moving beyond directory consolidation toward evidence-grade access truth, because regulators and deal teams increasingly need to see effective permissions, not just roles. With only 5.7% of organisations reporting full visibility into service accounts, the operational reality is that most teams still cannot answer the access question fast enough for a transaction timeline.

Identity lifecycle controls will matter more as divestitures accelerate. The weakest point in many programmes is not initial integration but the ability to remove access cleanly when boundaries change. That makes ownership, targeted certification, and timely deprovisioning the controls that determine whether the identity programme can handle carve-outs without creating outages or residual risk.

AI agent and NHI governance are converging inside the same control plane. The same visibility and ownership problems that affect service accounts now apply to autonomous agents that can inherit access across environments. Security teams should expect transaction workflows to include machine identity review as a standard step, not a specialist exception.


For practitioners

  • Map effective permissions before any consolidation decision Normalise directory, app, and resource-level entitlements so transaction teams can see what identities can actually do across both organisations. Prioritise nested groups, role inheritance, and shared application access before remediation starts.
  • Inventory NHI ownership during deal due diligence Create an explicit owner record for service accounts, API keys, cloud roles, automation identities, and AI agents. Flag any identity that lacks an accountable business or technical owner, because orphaned access will block deprovisioning and audit evidence.
  • Use targeted micro-certifications for divestiture separation Run narrow access certifications against the systems, roles, and accounts that will move out of scope. Focus on resource-level access and downstream dependencies so removal is precise enough to preserve remaining operations.
  • Build guardrails for inherited access drift Define alerts for identities that retain access across new organisational boundaries after a merger or carve-out. Pair those alerts with time-bound remediation workflows so inherited privileges do not remain active by default.

Key takeaways

  • M&A events expose identity debt faster than legacy IAM and IGA tools can resolve it.
  • Non-human identities and AI agents become hidden risk multipliers when ownership, visibility, and lifecycle controls are incomplete.
  • Permission-level visibility and targeted separation workflows are the controls that determine whether integration or divestiture succeeds.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on unmanaged NHI ownership, visibility, and lifecycle control during transactions.
NIST CSF 2.0PR.AC-4Transaction access separation depends on least-privilege permissions and controlled entitlements.
NIST SP 800-53 Rev 5AC-6Least-privilege enforcement is central to removing excess access during M&A events.
NIST Zero Trust (SP 800-207)Zero trust principles fit the need to continuously verify access across changing organisational boundaries.
CIS Controls v8CIS-5 , Account ManagementAccount management and removal are core to clean onboarding and offboarding in transactions.

Reassess trust assumptions at every boundary crossing and avoid relying on inherited network or directory trust.


Key terms

  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
  • Effective Permissions: Effective permissions are the access an identity can actually use after role inheritance, scope, and policy are applied. In Azure AI environments, they often matter more than the assigned role name because inherited rights can widen access to data, logs, and secret stores.
  • Micro-certification: Micro-certification is a narrow access review or approval step used to validate a specific entitlement, action, or risk signal. It reduces review scope compared with full recertification, but it still needs clear ownership and documented decision criteria to remain trustworthy.
  • NHI Ownership Attribution: The process of linking a non-human identity or exposed secret to a human or team that can take action on it. In practice, attribution combines identity, repository, cloud, and workflow signals so remediation, escalation, and audit tasks are assigned without relying on tribal knowledge.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • Permission-level visibility workflows for consolidating acquired identity stores
  • Micro-certification and guardrail patterns for divestiture separation
  • Examples of NHI and AI agent discovery across merged environments
  • Operational details on mapping effective permissions into natural-language access views

👉 Veza's full article covers identity sprawl, NHI ownership, and divestiture separation workflows in more depth.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org