By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: Oleria SecurityPublished August 18, 2026

TL;DR: MTX Group and Oleria are positioning continuous, adaptive governance as the answer to access sprawl across employees, service accounts, machine identities, and AI agents in regulated environments, according to Oleria Security. The real issue is not visibility alone but whether identity governance can keep pace with changing access across human, non-human, and autonomous systems.


At a glance

What this is: This partnership centres on continuous identity governance for human, non-human, and AI identities, with the key finding that point-in-time access reviews no longer match modern access change rates.

Why it matters: It matters because IAM, IGA, PAM, and NHI teams now have to govern mixed identity estates where standing privilege, lifecycle drift, and AI-driven access decisions can all create compliance and exposure gaps.

👉 Read Oleria Security's update on the MTX partnership for continuous identity governance


Context

Continuous identity governance means evaluating access as it changes, rather than waiting for periodic certification cycles to catch drift after the fact. In practice, that matters when an organisation is managing employees, contractors, service accounts, machine identities, and AI agents in the same operating model.

The governance gap here is not simply scale. It is that legacy IGA assumptions were built around access that was stable long enough to review, while modern environments generate constant entitlement change, delegated access, and standing privilege that can outpace manual oversight.


Key questions

Q: How should security teams govern access across human, NHI, and AI identities?

A: Security teams should govern all three through a shared lifecycle and policy layer, but with different operating rules for each actor type. Humans need review and approval flows, NHIs need ownership, rotation, and offboarding discipline, and AI agents need continuous control over actions, permissions, and escalation paths. The key is to keep governance consistent without forcing one workflow onto every identity class.

Q: When does standing privilege become unacceptable in modern IAM programmes?

A: Standing privilege becomes unacceptable when the identity can act faster than your review cycle, especially for workloads and AI agents that move across systems autonomously. If the access can be reused for multiple tasks without fresh context, the programme is relying on assumptions that no longer hold. That is the point at which runtime enforcement becomes necessary.

Q: What breaks when access reviews are only run on a fixed schedule?

A: Fixed-cycle reviews encourage repetition, not judgment. Reviewers see the same access over and over, approve it because it looks familiar, and miss the changes that actually matter. Risk-based reviews tied to role change, privilege growth, and inactivity are far more effective than calendar compliance.

Q: Who is accountable when a service account or AI agent keeps access after offboarding?

A: Accountability should sit with the system owner and the identity governance owner, not just the team that requested the access. If a service account or AI agent keeps access after offboarding, that usually means the lifecycle trigger, downstream revocation, or ownership mapping was incomplete. The control failure is organisational, not just technical.


How it works in practice

Why continuous governance matters for NHI and AI identities

Continuous governance is the shift from snapshot-based review to state-aware enforcement. Instead of treating access as something to certify on a schedule, the control plane evaluates identity context, entitlement change, and risk signals as they happen. That matters for non-human identities because service accounts, API tokens, machine identities, and AI agents can accumulate privilege outside the cadence of human access review. It also matters in regulated environments where audit evidence must show how access was decided, not just who was reviewed. The key architectural change is that governance becomes event-driven and context-rich, rather than periodic and manually assembled.

Practical implication: move high-risk identities from manual certification cycles to continuous entitlement monitoring and enforcement.

Standing privilege and lifecycle drift in mixed identity estates

Standing privilege is persistent access that remains available between tasks, sessions, or business changes. In mixed estates, that creates lifecycle drift when the identity’s role, owner, or purpose changes faster than governance can react. Non-human identities are especially exposed because they are often created to solve a point problem and then reused indefinitely. When access reviews are disconnected from provisioning, rotation, and offboarding, the organisation ends up with permissions that are technically valid but operationally stale. The architectural problem is not just over-permissioning. It is the absence of a lifecycle boundary that forces access to expire or re-justify itself.

Practical implication: tie access reviews to provisioning, rotation, and offboarding events rather than relying only on calendar-based recertification.

Visibility across human, service account, and AI-agent access

Visibility is the prerequisite for governance, but in identity programmes it has different meanings depending on actor type. For humans, it often means understanding business role and approval path. For non-human identities, it means mapping secrets, tokens, certificates, workloads, and third-party integrations to ownership and purpose. For AI agents, the challenge expands because the identity may act through tools and delegated permissions that change at runtime. That means a single access graph has to capture who created the identity, what it can reach, where privilege lives, and whether the access is still justified. Without that graph, enforcement becomes reactive and evidence becomes incomplete.

Practical implication: build one inventory that links identities, owners, privileges, and lifecycle state across human, NHI, and AI use cases.


NHI Mgmt Group analysis

Continuous governance is becoming the baseline control for mixed identity estates. Access that changes across employees, service accounts, machine identities, and AI agents cannot be governed effectively through quarterly or annual review cycles. The control question is no longer whether organisations can certify access, but whether they can see and enforce change fast enough to matter. That makes continuous governance a structural requirement for modern IAM, not an enhancement.

Standing privilege is the failure mode that keeps showing up underneath modernisation projects. The partnership language points directly at the problem: access persists after purpose changes, ownership shifts, or workloads are reconfigured. That is a governance gap, not just a hygiene issue, because the entitlement remains technically valid while operational accountability has already moved on. Practitioners should treat standing privilege as the default risk condition in cloud and AI-heavy environments.

Legacy IGA assumptions are being outgrown by identity diversity. Point-in-time certification was designed for identities whose access states were relatively stable and human-readable. That assumption weakens when the estate includes service accounts, machine identities, and AI systems that can accumulate or use access in more dynamic ways. The implication is that identity governance must move from review-centric to context-centric models.

Runtime identity visibility: governance now depends on seeing entitlement change as it happens across human and non-human access paths. This is especially important where regulated organisations need defensible audit trails and least-privilege evidence. A system that can only explain yesterday’s access is already behind the actual risk. Practitioners need governance evidence that tracks live state, not just historical certification.

AI identities force IAM teams to think beyond classic joiner-mover-leaver logic. An AI identity is not just another service account with a new label. If it can interact with tools or workflows in runtime, its access behaviour can change without the familiar human lifecycle signals that drive offboarding and recertification. That means IAM and IGA teams must decide where human governance ends and machine or agent governance begins, then document that boundary clearly.

From our research:

What this signals

Identity governance will keep moving toward live-state enforcement as mixed estates become the norm. Organisations that still separate human IAM, NHI governance, and AI identity controls will struggle to prove who had access, when it changed, and why it remained in place. The practical shift is toward a shared control plane that can support lifecycle processes for managing NHIs without losing human accountability.

Runtime identity visibility: the next governance gap is not just missing inventory, but missing change context. If a credential, token, or delegated permission can be created, reused, and retired faster than the review process can observe it, the programme cannot claim continuous governance. That is why NHI and AI identity teams should align their operating model to the NIST Cybersecurity Framework 2.0 rather than relying on annual certification alone.

As organisations expand cloud and AI adoption, the pressure shifts from proving that access was reviewed to proving that access was actively controlled. The teams that prepare now will be the ones that can connect governance evidence to live identity state, not just to a completed review form.


For practitioners

  • Map identity ownership across mixed estates Inventory human users, service accounts, machine identities, and AI agents in one control view, and require each to have an accountable owner, purpose, and lifecycle state.
  • Shift high-risk access to continuous review triggers Trigger review and enforcement when privileges change, integrations are added, or service accounts are repurposed, rather than waiting for periodic certification cycles.
  • Eliminate standing privilege in shared and reusable identities Identify credentials that remain valid beyond the business task they support, then reduce their lifetime or scope so access cannot accumulate silently.
  • Tie offboarding to secret and token revocation When an employee, contractor, workload, or AI workflow is retired, ensure the associated credentials, certificates, and delegated access are revoked in the same workflow.
  • Document audit evidence for runtime governance decisions Preserve logs that show when access changed, why it changed, and who approved it, so regulated teams can demonstrate continuous governance instead of static certification.

Key takeaways

  • Modern identity governance has to cover humans, service accounts, machine identities, and AI identities in one operating model.
  • Standing privilege and lifecycle drift are the governance failures most likely to survive traditional access review cycles.
  • Continuous visibility and event-driven enforcement are becoming the practical standard for regulated identity programmes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Continuous governance and access visibility align to access control and identity management.
NIST SP 800-53 Rev 5AC-2Account management is central to lifecycle control across human and non-human identities.
NIST Zero Trust (SP 800-207)The article’s continuous access model aligns with Zero Trust verification principles.
OWASP Non-Human Identity Top 10NHI-03Lifecycle control and privilege reduction map directly to common NHI governance failure modes.

Apply AC-2 to ensure accounts, service identities, and delegated access are provisioned and removed with ownership.


Key terms

  • Continuous Identity Governance: An operating model where access decisions, lifecycle changes, and risk signals are handled as an ongoing process rather than a periodic campaign. It uses authoritative events, telemetry, and policy automation to keep access aligned with current business and security conditions.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Identity Lifecycle Drift: Identity lifecycle drift is the gap between the business reason for access and the access that continues to exist after that reason changes. It appears when provisioning, review, and offboarding do not stay aligned. In ITSM-heavy environments, drift often shows up as approved access that was never fully revoked or reassigned.
  • Runtime Identity Visibility: Runtime identity visibility is the ability to see which non-human identity accessed which dataset, through which tool, and at what time. It connects identity governance to privacy control by making machine behaviour auditable instead of inferred from process documentation.

What's in the full announcement

Oleria Security's full post covers the operational detail this post intentionally leaves for the source:

  • How the partnership positions continuous governance across regulated public sector and healthcare environments
  • The vendor's description of automated access reviews, lifecycle management, and standing privilege removal
  • Specific language on visibility across human, non-human, and AI identities in transformation programmes
  • The quoted partner framing on digital transformation and trusted governance

👉 Oleria Security's full post covers the partnership context and the product framing behind continuous governance across identity types.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org