TL;DR: 69% of companies now manage more machine identities than human ones, 72% say machine identities are harder to manage, and only 38% have a real-time list of active machine identities, according to a SailPoint-sponsored Dimensional Research survey. The gap is no longer visibility alone; it is lifecycle control, auditability, and accountability.
At a glance
What this is: This is SailPoint’s analysis of machine identity management blind spots, highlighting that scale, manual handling, and weak auditability are outpacing governance.
Why it matters: IAM, IGA, PAM, and NHI teams need to treat machine identities as lifecycle-governed assets, because unmanaged service accounts and bots expand risk, audit failure, and unintended access.
By the numbers:
- 69% of companies surveyed now manage more machine identities than human ones.
- 72% of identity professionals surveyed find machine identities more difficult to manage than human identities.
- Only 38% of companies surveyed reported having a real-time list of their active machine identities.
- 60% of companies surveyed acknowledged compliance issues tied to machine identities.
Context
Machine identities are non-human accounts such as service accounts, bots, and RPAs that let systems and applications operate without direct human involvement. In this article, SailPoint argues that these identities are now numerous enough, and opaque enough, to create governance problems that many identity programmes still handle manually.
The core issue is not that machine identities exist. It is that their ownership, lifecycle, and audit state are often unclear, which makes it difficult to know what is active, what is unused, and what still has access. That is an IAM and NHI governance problem, not just an operational inconvenience.
Key questions
Q: What breaks when machine identities are tracked manually?
A: Manual tracking breaks when credential volume outpaces human oversight. Teams lose visibility into where certificates, keys, and secrets live, who owns them, and when they expire. That creates outages, audit gaps, and stale access paths that remain valid longer than intended. Central inventory and automated lifecycle control are the practical response.
A: Machine identities create risk because they often scale faster than human oversight, while certificate lifecycles, privileges, and ownership can drift over time. In regulated environments, that drift weakens accountability, makes audits harder, and increases the chance that old credentials remain valid after they should be removed or rotated. Automation is the main control that narrows that gap.
Q: How do security teams know whether machine identity governance is working?
A: They know it is working when every non-human credential has a named owner, a visible system scope, and a documented retirement path. If access reviews cannot answer when the identity was last used or why it still exists, governance is only partial. High confidence comes from evidence of cleanup, not just policy coverage.
Q: Should organisations prioritise machine identities before human access reviews?
A: They should prioritise both, but machine identities often deserve immediate attention because they are numerous, long-lived, and under-reviewed. If service accounts and keys are unmanaged, human access reviews alone will not close the largest exposure paths.
Technical breakdown
Why machine identity governance breaks at scale
Machine identities are created to support system-to-system work, but they rarely follow the same lifecycle discipline as human accounts. Service accounts, bots, and RPAs often accumulate over time, remain connected to critical workloads, and are managed through ad hoc requests or spreadsheets. That creates drift between the identity’s original purpose and its current access. Once that drift grows, auditability weakens because ownership, intended use, and current entitlement no longer line up. The article’s figures point to a common pattern: organisations can count these identities in aggregate, but cannot reliably govern them as discrete assets.
Practical implication: define machine identity ownership and lifecycle state before you try to automate remediation.
Why manual workflows create hidden risk in NHI estates
Manual handling is especially dangerous for machine identities because the control burden grows with every exception. When teams hesitate to delete an account for fear of breaking a dependency, stale identities remain active long after their purpose ends. That is how the attack surface expands quietly. The technical problem is not just that the identity exists, but that its current dependency map is incomplete, so teams keep access alive to preserve service continuity. In NHI governance terms, that is a lifecycle failure, not simply a permissions mistake.
Practical implication: map dependencies before offboarding so stale machine identities do not become permanent exceptions.
Auditability depends on real-time inventory, not periodic cleanup
A machine identity programme cannot be audited reliably if active and inactive identities are tracked through separate manual processes. Real-time inventory is the control plane for governance because it lets teams answer basic questions about scope, ownership, and current status. Without that inventory, certification, compliance review, and incident response all start from uncertain data. The article shows that many organisations still lack this baseline, which means governance decisions are being made against stale or partial records. In practice, this leaves inactive identities available for misuse and active identities invisible to review.
Practical implication: establish continuous inventory of active machine identities before relying on certification or compliance reporting.
Threat narrative
Attacker objective: The attacker objective is to exploit unused or over-retained machine identities as stable access paths that are less visible than human accounts.
- Entry occurs through unmanaged machine identities that persist beyond their intended purpose, including service accounts and bots that remain active after business need has shifted.
- Credential or access abuse follows when stale machine identities retain permissions that were never fully reviewed or revoked, creating usable paths into systems and data.
- Impact emerges through audit failure, compliance exposure, and the possibility of inappropriate access being granted to identities that no longer have a valid business owner.
Breaches seen in the wild
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Machine identity blind spots are a lifecycle problem before they are a visibility problem: Organisations do not mainly fail because they cannot count machine identities. They fail because ownership, intended purpose, and revocation state drift apart over time. That creates a governance gap where identities outlive the process that justified them, and the practical conclusion is that lifecycle controls have to precede reporting.
Manual exception handling is the real control failure: The survey’s concern about breaking critical systems is familiar, but it often becomes the reason stale machine identities remain untouched. This is a governance assumption failure in NHI programmes because continuity fear overrides revocation discipline. The implication is that identity teams must treat dependency mapping as part of access governance, not as a separate operational nicety.
Auditability collapses when active identity state is not continuous: If active machine identities are only reconciled periodically, certification becomes retrospective paperwork rather than a control. That weakens compliance and makes incident response slower because no one trusts the current record. Continuous machine identity inventory: the control problem is not finding identities once, but maintaining an authoritative view across their full lifespan.
Real-time governance is becoming the baseline for machine identities: As machine identity counts rise faster than human identity estates, identity programmes need controls that assume scale, churn, and distributed ownership. This pushes NHI governance closer to operational control design than annual review cycles. Practitioners should expect machine identity management to sit alongside IGA, PAM, and cloud lifecycle governance as a standing discipline.
Machine identity sprawl exposes a weak accountability model: When 57% of survey participants report inappropriate access and 60% report compliance issues, the underlying issue is not just excess privilege but unclear accountability for who owns the entitlement and who can revoke it. That is why machine identity governance must be treated as a board-level control concern, not a tooling afterthought.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Read next: Service Account Security Guide
What this signals
Continuous machine identity inventory: governance only becomes actionable when active service accounts, bots, and RPAs are tracked as a living control set rather than a static list. Organisations that cannot reconcile identities continuously will keep discovering stale access only after something fails.
The article’s numbers reinforce a familiar pattern: machine identities now outnumber human ones by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs. That scale means IAM teams need inventory, ownership, and revocation discipline to become operational basics, not exception handling.
For programmes still centred on human-user workflows, machine identity management becomes the place where IGA, PAM, and cloud operations converge. The next maturity step is to make lifecycle state the source of truth for every non-human account, then let certification and audit consume that data rather than reconstruct it.
For practitioners
- Establish machine identity ownership Assign a named owner, business purpose, and revocation authority to every service account, bot, and RPA before it is allowed to persist in production.
- Build a real-time identity inventory Maintain a continuously updated list of active and inactive machine identities so certification and incident response start from current data rather than stale records.
- Reconcile stale identities against dependencies Review machine identities that have not been used recently, verify the systems that still depend on them, and retire the ones with no current business need.
- Move review evidence from manual logs to control data Use authoritative identity records and lifecycle events to support audit and compliance reporting instead of spreadsheets or ticket history.
- Separate continuity risk from identity retention Document the system dependency that would break if a machine identity were removed so teams can revoke access without preserving dead accounts by default.
Key takeaways
- Machine identity governance fails most often because ownership and lifecycle state drift away from the systems that depend on the account.
- SailPoint’s survey shows that 69% of companies manage more machine identities than human ones, while only 38% have a real-time list of active machine identities.
- The decisive control is not another periodic review but a continuously authoritative inventory tied to revocation authority and dependency mapping.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Stale machine identities remain active after their business purpose ends. |
| NHI-05 — Overprivileged NHI | The article highlights inappropriate access and unmanaged machine identity permissions. | |
| NHI-07 — Long-Lived Secrets | Manual workflows often leave machine identities and their credentials in place far too long. | |
| Recommendation — Track offboarding events for every machine identity and revoke access when the owning process ends. Review machine identity entitlements against actual system need and remove excess privilege. Shorten machine identity credential lifetimes and tie renewal to validated business use. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | This article is fundamentally about governing non-human access permissions and entitlement drift. |
| Recommendation — Govern machine account permissions through authoritative entitlement review and revocation controls. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article centres on weak account inventory, lifecycle, and cleanup for machine identities. |
| Recommendation — Apply account management controls to inventory, review, and disable stale machine identities. | ||
Key terms
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Identity Lifecycle Event: A business event that changes a person’s access, obligations, or record status, such as hiring, role change, or offboarding. In HR programmes, these events often drive entitlement changes and evidence requirements, so they need to be governed as part of the identity lifecycle rather than handled as isolated paperwork.
- Access Inventory: A map of which identities can reach which systems, why that access exists, and how it is reviewed or removed. For NHI governance, access inventory is more actionable than a simple asset list because it exposes standing privilege and dormant access paths.
- Auditability: Auditability is the ability to reconstruct who or what acted, what permissions were used, and what data or tools were touched. For AI and NHI governance, it is the minimum evidence needed to investigate incidents, validate controls, and prove that autonomous actions stayed within approved scope.
Deepen your knowledge
NHI governance, machine identity security, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or NHI governance programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org