TL;DR: Mergers and acquisitions create a high-risk identity integration problem because service accounts, API keys, tokens, and certificates are often inherited across mismatched environments with unclear ownership, inconsistent scoping, and hidden secrets, according to Oasis Security. The security issue is not just sprawl, but the collapse of governance assumptions that make merged identity estates auditable and controllable.
At a glance
What this is: This is a guide to managing non-human identities during mergers and acquisitions, with the key finding that post-merger identity sprawl creates hidden access, unclear ownership, and governance drift.
Why it matters: It matters because IAM, IGA, PAM, and cloud teams have to baseline inherited NHIs quickly or the merged environment will carry forward unowned privileges and audit blind spots.
Context
Mergers and acquisitions create a governance gap because two or more identity estates are combined before their ownership models, credential lifecycles, and access rules are aligned. In practice, that means non-human identities can cross from one environment into another without a reliable baseline for naming, scoping, or accountability.
In this context, an NHI is any service account, service principal, token, API key, or certificate that enables system-to-system access. When those identities are inherited from different organisations, the merged environment can look unified on paper while still operating with incompatible trust assumptions beneath the surface.
That makes M&A a lifecycle problem as much as an integration problem. The starting position described here is typical: most organisations have some discovery capability, but far fewer have a repeatable way to normalise NHIs across legacy on-prem, cloud, and SaaS estates after a deal closes.
Key questions
Q: What breaks when non-human identities are merged without a baseline?
A: Ownership, scoping, and lifecycle controls break first. The merged organisation inherits identities from different technical worlds, so service accounts and secrets keep working even when nobody can say who owns them, how long they should live, or which policy actually governs them. That creates unmanaged access paths and audit gaps.
Q: Why do orphaned service accounts create so much risk after an acquisition?
A: Orphaned service accounts are dangerous because they often keep working after the original owner has left or the original environment has changed. In a merger, that persistence turns old access into live access, especially when the account still reaches production systems, cloud resources, or connected SaaS platforms.
Q: How do teams know if NHI governance is actually working?
A: Look for complete inventory coverage, clear ownership, enforced rotation, and reliable decommissioning. If new credentials appear faster than they are classified, or if stale secrets stay valid after workload changes, the programme is not governing machine identities effectively.
Q: Should organisations unify policy or federate identity systems during M&A?
A: That depends on maturity, regulatory pressure, and operational complexity. Federation can preserve separation while linking trust, but it does not remove the need for shared NHI governance. If the organisation cannot enforce the same lifecycle rules in both estates, unification without policy alignment only hides the risk.
Technical breakdown
Why merged identity estates create NHI governance drift
M&A does not simply add more identities. It combines different control models, each with its own assumptions about who owns access, how credentials expire, and which system enforces policy. When one side relies on broad default roles and the other on short-lived, tightly scoped credentials, the merged estate inherits conflicting definitions of least privilege. That mismatch creates configuration drift, because a single governance baseline no longer exists across the combined environment. The practical problem is not just volume. It is that the same credential type can mean different levels of risk depending on where it was issued and how it is maintained.
Practical implication: baseline ownership, scope, and expiry rules before treating inherited NHIs as a single governed population.
How secrets sprawl and orphaned access appear after integration
Secrets sprawl happens when credentials are embedded in repositories, CI/CD workflows, infrastructure-as-code, SaaS connectors, and legacy scripts, then carried into the merged organisation without inventory. Orphaned NHIs are identities that still hold privilege after the system or owner they supported is gone. In an M&A context, both problems are amplified by rapid lift-and-shift work and partial visibility across teams. The technical failure is not merely that secrets exist. It is that their lifecycle is detached from the business relationship that originally justified them, which makes revocation, rotation, and attestation inconsistent.
Practical implication: inventory embedded credentials and treat every inherited identity as suspect until its owner, purpose, and expiry are verified.
What a unified NHI governance baseline actually changes
A unified baseline is the point where merged identity control stops being ad hoc. It standardises naming conventions, credential rotation schedules, least-privilege policy, and lifecycle management from creation through decommissioning. The article’s recommendation to adopt the stricter standard matters because post-merger compromise often exploits the weakest inherited practice rather than the most mature one. This is especially relevant when identities span cloud, on-prem, and SaaS environments, because enforcement is usually decentralised even when policy is centralised. Without that baseline, security teams cannot reliably compare exposure or prove control consistency.
Practical implication: define one enforceable policy floor for all inherited NHIs before integration work expands the attack surface.
Threat narrative
Attacker objective: The objective is to exploit inherited non-human access paths that the merged organisation cannot yet see, govern, or revoke consistently.
- Entry occurs when merger integration exposes previously separate NHI estates, including service accounts, API keys, tokens, certificates, and hard-coded secrets that were not inventoried before access was granted.
- Credential access follows through inherited secrets sprawl, stale credentials, and undocumented accounts embedded in repositories, scripts, and SaaS connectors.
- Escalation happens when over-permissive roles, inconsistent scoping, and unclear ownership let those identities retain access across the combined environment.
- Impact is unauditable machine-to-machine access in the merged organisation, with compliance drift, hidden privileges, and a larger post-integration attack surface.
Breaches seen in the wild
- Zacks breach claim 2025: A hacker leaked 12 million Zacks accounts in 2025, claiming domain admin access in 2024; HIBP verified the data, Zacks has not confirmed.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
M&A exposes a governance assumption that no longer holds: identity ownership is assumed to remain stable long enough for normal lifecycle controls to work. That assumption fails when two organisations merge, because the same service account, secret, or workload identity can cross into a new operating model before anyone has aligned naming, scoping, or revocation authority. The implication is that merger integration must be treated as a control reset, not a data migration.
Unified policy is the real integration layer for NHIs: network connectivity and directory federation do not create governable machine identity on their own. A merged estate still remains fragmented if credential lifespan, least privilege, and decommissioning rules differ by inherited environment. Practitioners should read M&A as a test of whether the organisation can impose one baseline across cloud, SaaS, and on-prem identity domains.
Secrets sprawl is a merger problem before it is a secrets-management problem: the article shows how credentials embedded in Terraform, Helm charts, CI/CD workflows, repositories, and legacy scripts can survive the deal intact. That persistence creates a hidden population of access that standard project plans often miss. The practitioner lesson is to assume the combined environment contains more active NHIs than any initial inventory suggests.
Lifecycle governance has to start before the post-close rush: the strongest control in the article is not rotation alone, but early discovery followed by strict prioritisation of unmanaged, long-lived, or over-privileged identities. In M&A, the first stable baseline determines whether future governance is possible at all. Teams that wait for full system normalisation usually inherit the weakest practices from both sides.
Identity blast radius is the right mental model for merger risk: when two estates are stitched together, the effective blast radius is not just the number of accounts but the number of unowned credentials and inconsistent trust assumptions that survive integration. That is why post-merger NHI governance is a board-level resilience issue, not an implementation detail. Practitioners should measure the merged estate by recoverable control, not by count alone.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Read next: Identity and NHI Security Business Case Guide
What this signals
Identity convergence, not just infrastructure consolidation, is the core M&A challenge: merging directories and cloud estates is easy compared with merging the rules that govern machine access. If the organisation cannot harmonise ownership, rotation, and decommissioning, the combined environment will remain operationally connected but governance-fragmented.
Non-human identity discovery has to precede rationalisation: teams should assume their first inventory will undercount embedded secrets and orphaned accounts. The practical signal is simple: the faster the merger moves, the more likely hidden credentials will survive unless discovery is continuous rather than one-time.
The combined estate often contains far more NHIs than the human workforce, with NHIs outnumbering human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs. That ratio makes post-merger identity control a scale problem, not a niche hygiene task.
For practitioners
- Map every inherited NHI before system integration Scan cloud environments, repositories, container registries, on-prem applications, and SaaS tenants for service accounts, service principals, managed identities, PATs, certificates, and hard-coded secrets before the merger is operationalised.
- Freeze new long-lived credentials on day 0 Block the creation of new persistent credentials as soon as access is available, then use short-lived and tightly scoped credentials where the workflow can support them.
- Normalize ownership and lifecycle metadata Assign an owner, credential lifespan, privilege level, and business purpose to every discovered NHI so that orphaned or undocumented access can be prioritised for remediation.
- Adopt the stricter standard across both estates Use one unified governance baseline for naming, rotation schedules, least privilege, and decommissioning, and default to the stricter rule whenever the two organisations differ.
- Track post-merger NHI drift continuously Monitor total NHI growth, privileged roles, unrotated identities, stale accounts, and anomalous machine-to-machine traffic so the merged environment does not drift back into unmanaged access.
Key takeaways
- M&A turns non-human identity governance into a control-reset problem because merged estates inherit conflicting ownership, scoping, and lifecycle assumptions.
- The main evidence of risk is not one weak system but the accumulation of embedded secrets, orphaned accounts, and inconsistent trust rules across both organisations.
- The right response is to discover, normalise, and baseline inherited NHIs before the combined environment hardens around hidden access paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Orphaned NHIs that survive integration reflect weak offboarding across merged estates. |
| NHI-05 — Overprivileged NHI | The article highlights broad roles and inconsistent scoping after M&A. | |
| NHI-07 — Long-Lived Secrets | The article stresses freezes on new persistent credentials and the danger of stale secrets. | |
| Recommendation — Inventory inherited identities and revoke credentials that no longer map to an active system or owner. Reduce inherited privileges to the minimum scope needed before the merged estate expands further. Replace long-lived credentials with shorter-lived alternatives wherever merger workflows allow. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post is centered on harmonising authorisation across merged identity estates. |
| Recommendation — Align entitlements across both organisations so inherited NHIs follow one authorisation baseline. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account and credential inventory is central to managing merged NHIs and orphaned access. |
| Recommendation — Maintain an authoritative account inventory and remove stale or unauthorised machine accounts quickly. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Secrets Sprawl: The uncontrolled proliferation of sensitive credentials, API keys, tokens, passwords, certificates, across codebases, cloud environments, CI/CD pipelines, and configuration files. In 2024, over 50 million leaked secrets were found on the dark web.
- Identity baseline: A current inventory of identities, roles, entitlements, and effective permissions across environments. In Zero Trust, it is the starting point for deciding what should be trusted, reduced, or continuously verified, because controls cannot govern access that has not been discovered.
- Orphaned NHI: An orphaned NHI is a non-human identity that remains active without a clear owner, business purpose, or lifecycle path. These identities often survive employee departures, application changes, or missed deprovisioning steps, which makes them difficult to review and risky to leave in place.
Deepen your knowledge
NHI governance, identity lifecycle management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org