TL;DR: Identity is now the control point for users, apps, and automation, yet the article says many programmes still rely on manual provisioning, ticket-based approvals, and periodic access reviews that miss shadow SaaS and non-human identities, according to Zluri. The core issue is not tooling volume but governance model drift: identity controls designed for slower human workflows no longer match how access is created, used, and abandoned.
At a glance
What this is: This is a Zluri analysis of modern identity strategy, arguing that access governance must now cover SaaS, shadow IT, and non-human identities instead of stopping at human user provisioning.
Why it matters: It matters because IAM, IGA, and PAM teams can no longer rely on quarterly reviews and ticket-based workflows when access decisions span humans, bots, service accounts, and unmanaged SaaS entitlements.
By the numbers:
- According to Gartner, by 2026, 70% of cyberattacks against enterprises will target identities, whether through credential compromise, privilege escalation, or unmanaged access.
- According to Forrester, over 65% of enterprises still struggle to govern access across SaaS apps and non-human identities, even after years of IAM investment.
Context
Identity strategy is the control plane for access, but many programmes still assume a slower world of ticket queues, quarterly certification, and neatly owned accounts. That model fails when SaaS, shadow IT, service accounts, and automation create and change access faster than governance processes can see it. In that environment, identity gaps become security gaps, not just administrative debt.
Zluri's analysis argues that modern identity governance has to cover the full access surface, including non-human identities and unmanaged SaaS entitlements. The practical issue is not simply more accounts, but more places where ownership, usage, and revocation can drift out of sync.
The article's starting point is typical rather than exceptional for SaaS-first enterprises: identity sprawl now reflects how work actually happens, while many control programmes still reflect how IT used to operate.
Key questions
Q: What breaks when access governance stops at SSO-connected apps?
A: Coverage breaks first, then accountability. Access reviews and lifecycle controls can look complete while legacy systems, shadow IT, and niche SaaS still hold unmanaged entitlements. That leaves orphaned access, inconsistent evidence, and weak revocation assurance across the long tail of applications that most IAM programmes do not govern well.
Q: Why do manual offboarding and quarterly reviews leave access risk behind?
A: Because they assume access changes slowly enough to be certified after the fact. In SaaS-first environments, entitlements are created, delegated, and abandoned continuously, so a calendar-based review often arrives after the privilege has already drifted or the account owner has left.
Q: How can security teams know if cloud identity governance is actually working?
A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review. If teams still spend days reconstructing access state, governance is not operating continuously. Effective programmes can show current MFA coverage, role scope, and credential age on demand.
Q: How should teams govern service accounts and bots alongside human users?
A: Treat service accounts, bots, and other non-human identities as owned assets with explicit purpose, review, and retirement rules. They need the same lifecycle discipline as human identities, but with tighter inventory, stronger change tracking, and clearer accountability because they are often more persistent and less visible.
Technical breakdown
Why manual provisioning and audit-season reviews fail
Manual provisioning and ticket-based approvals assume access is created in a small number of predictable steps and then remains stable long enough for periodic review. In SaaS-heavy environments, entitlements are often created directly inside applications, inherited through group membership, or accumulated by bots and service accounts outside the main joiner-mover-leaver flow. That makes quarterly certification a lagging control: reviewers are looking at a snapshot after the access has already changed. The result is governance that is descriptive, not preventive, and that is why shadow IT and orphaned access persist even when the IAM stack looks mature.
Practical implication: Replace review-only governance with event-driven access decisions tied to role changes, usage, and ownership signals.
How SaaS entitlements and non-human identities expand the control surface
SaaS governance is not the same as SSO governance. A user can authenticate through a central identity provider and still hold risky in-app roles, elevated workspace permissions, or unmanaged direct access inside the application itself. The same applies to non-human identities such as service accounts, API keys, bots, and tokens, which often live outside HR-linked lifecycle processes and therefore escape normal offboarding. Once you separate authentication from entitlement governance, the failure mode becomes clear: the login is controlled, but the privilege is not. That is why modern identity strategy has to map ownership and rights inside the application, not just at the edge.
Practical implication: Inventory in-app roles, direct entitlements, and machine identities as first-class governance objects.
Why unified identity data is the foundation for continuous governance
A modern identity strategy depends on a unified view across HRMS, directory services, ITSM, SaaS, and cloud platforms. Without that consolidation, access decisions are made on partial context, so reviewers cannot reliably tell whether an account is active, who owns it, or whether the privilege is still justified. Continuous governance is therefore a data problem before it is a workflow problem. Unified identity data enables event-triggered reviews, auto-remediation, and lifecycle-aware policy enforcement because it gives the control plane a current picture of who or what has access and why.
Practical implication: Build a consolidated identity inventory before trying to automate certification, remediation, or offboarding.
Threat narrative
Attacker objective: Exploit governance blind spots to retain or abuse access that should have been revoked, constrained, or reviewed.
- Entry occurs through manual provisioning, shadow SaaS adoption, or direct creation of non-human identities outside the main governance workflow.
- Credential or entitlement access persists because ownership, usage, and revocation are not tied into a unified lifecycle process.
- Escalation happens when stale access, excessive roles, or orphaned service accounts remain active after role change or offboarding.
- Impact is widened blast radius, audit failure, and increased exposure to credential compromise, privilege escalation, or unmanaged access.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity governance has become a cross-domain control problem, not a directory problem. The article is right to treat identity as the control plane for users, apps, and automation, because the real risk now sits in the joins between HR, SaaS, cloud, and non-human access. When those systems are fragmented, entitlement drift becomes inevitable and governance becomes ceremonial. Practitioners should read this as a reminder that identity strategy now has to span IAM, IGA, PAM, and SaaS governance together.
Shadow SaaS and non-human identities expose a governance blind spot that legacy IAM models cannot see. The important issue is not that these identities exist, but that they often sit outside ownership, review, and offboarding disciplines. That creates a predictable asymmetry: authentication may be centralised while privilege remains dispersed. The practitioner conclusion is straightforward, even if the operational work is hard: the governance boundary has to move from sign-in to entitlement.
Policy-driven JML is now a control requirement, not a workflow preference. Manual offboarding, ticket queues, and annual review cadences were designed for human-paced changes, not for environments where access is created by applications, workflows, and service identities at machine speed. This is the modern identity governance gap: not lack of visibility alone, but access lifecycle logic that no longer matches the environment it is supposed to govern. Teams should treat lifecycle automation as an access security control.
Access review fatigue is a symptom of mis-scoped governance. Quarterly certification still has value, but only when it sits on top of continuous inventory, ownership, and usage signals. When reviewers are asked to rubber-stamp entitlements they cannot see in context, the process measures compliance effort rather than access risk. The practitioner takeaway is that review quality depends on upstream entitlement hygiene, not on the review cycle itself.
NHI governance is now inseparable from SaaS access governance. Service accounts, API tokens, and bots are not an adjacent problem anymore; they are part of the same access economy as human users and third-party apps. The named concept here is identity sprawl by lifecycle mismatch: access is born in many places, but it is still retired as if it were created in one. That is the governance model that practitioners need to rethink.
From our research library:
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
- Read next: Identity Security Programme Guide
What this signals
Identity governance has to move upstream of the access review. The operational signal in this article is that entitlement drift begins before certification ever starts, so teams need continuous inventory and ownership data to make reviews meaningful. A lifecycle-aware programme will focus on revocation triggers, not just attestation outputs.
Non-human access should be governed as part of the same access economy as SaaS and human accounts. Service accounts, bots, and tokens only become manageable when they are assigned ownership, expiry logic, and review expectations that match their business use. That is where NHI governance and SaaS governance converge for practitioners.
For practitioners
- Map the full identity surface Create a consolidated inventory that includes employees, contractors, SaaS apps, service accounts, bots, API keys, and in-app roles so governance is not limited to SSO-visible access.
- Automate joiner-mover-leaver logic Tie onboarding, role changes, and offboarding to source-of-truth systems and use policy-driven expiry for temporary or elevated access instead of ticket-based revocation.
- Review entitlements inside SaaS apps Validate workspace admin rights, owner roles, and other in-app permissions separately from authentication status, because SSO coverage does not equal least privilege.
- Treat non-human identities as governed assets Assign ownership, usage review, and revocation criteria to bots, service accounts, and tokens so they enter the same lifecycle controls as human accounts.
- Move from periodic to event-driven reviews Trigger access reviews on role changes, inactivity, or risk signals, and prioritise the most sensitive applications and privileges instead of certifying everything on a calendar.
Key takeaways
- Identity strategies fail when they stop at authentication and ignore the entitlement and lifecycle layers where access actually drifts.
- The article's core evidence is that manual provisioning, periodic reviews, and siloed identity data no longer match how SaaS and non-human access are created and abandoned.
- Practitioners need continuous inventory, policy-driven JML, and governance for service accounts and SaaS entitlements if they want access control that reflects current operations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Delayed offboarding and orphaned access are central governance failures in the article. |
| NHI-05 — Overprivileged NHI | The article warns that bots, service accounts, and API identities accumulate excessive privileges. | |
| NHI-07 — Long-Lived Secrets | Untracked bots and service accounts often persist with secrets that never expire or get reviewed. | |
| Recommendation — Automate revocation when users or services exit so access does not outlive the business need. Right-size NHI permissions and remove standing access that exceeds the task scope. Enforce rotation and expiry for NHI secrets, tokens, and API keys on a defined schedule. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post centres on entitlement governance across SaaS and non-human access. |
| Recommendation — Apply PR.AA-05 to review, approve, and periodically revalidate access entitlements across all identity types. | ||
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
- Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org