TL;DR: IGA programs still miss the identities that now carry the most operational risk: service accounts, API keys, OAuth tokens, cloud service principals, and AI agent credentials, according to Zluri. NHI governance closes that blind spot by extending discovery, ownership, lifecycle, review, and audit controls to machine identities that were never tied to HR events.
At a glance
What this is: This article argues that NHI governance is the missing layer in IGA because service accounts, API keys and AI agents sit outside employee-centric lifecycle controls.
Why it matters: It matters because IAM, IGA and PAM teams need a governable model for machine identities that create real breach and audit exposure without HR triggers.
By the numbers:
- Non-human identities outnumber human identities by 40 to 1 in the typical enterprise.
- The NHI population grew 44% year-over-year between 2024 and 2025.
Context
Service accounts, API keys and AI agent credentials are machine identities, not employee identities. They authenticate software, integrations and workloads, but they rarely enter the HR-driven lifecycle that most identity governance and administration programmes depend on.
Zluri's analysis frames the governance gap clearly: traditional IGA can show who a person is and what they can access, but it usually cannot see the non-human identities that person creates, inherits or leaves behind. That creates a parallel identity estate with weak ownership, weak reviews and delayed revocation.
The article's core point is operational rather than theoretical. When machine identities are unmanaged, access persists beyond project end, developer turnover and tool changes, which is why NHI governance has become a control issue for security, audit and cloud operations teams.
Key questions
Q: What problem does ownership attribution solve for service accounts and API keys?
A: It closes the gap between exposure detection and accountable remediation. Many organisations can find the secret, but not the human who introduced it, maintains it, or can safely replace it. Ownership attribution gives security teams a practical way to assign action without relying on informal knowledge that disappears during staff changes.
Q: Why do non-human identities create more risk than many human accounts?
A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review. That combination increases the chance that a single exposed secret or delegated token can be reused across systems without detection. The risk is not just compromise, but silent persistence inside automated workflows and third-party integrations.
Q: How do teams know if NHI governance is actually working?
A: Look for complete inventory coverage, clear ownership, enforced rotation, and reliable decommissioning. If new credentials appear faster than they are classified, or if stale secrets stay valid after workload changes, the programme is not governing machine identities effectively.
Q: What is the difference between secrets detection and NHI governance?
A: Secrets detection finds exposed credentials, while NHI governance tracks how those credentials are issued, reused, rotated, and retired. Detection answers whether a secret is visible. Governance answers whether the identity behind that secret is controlled throughout its lifecycle. Mature programmes need both because exposure without lifecycle control leaves the same risk open.
Technical breakdown
Why IGA misses machine identity lifecycle events
Traditional IGA is built around joiner-mover-leaver events sourced from HR systems. That model works when the identity is a person because hiring, role changes and termination create natural triggers for provisioning and removal. Service accounts, API keys and AI agent credentials are created by developers, operators or platforms, so they never pass through the same lifecycle checkpoints. The result is a governance gap at birth, review and offboarding. If the system of record is human-centric, machine identities remain invisible unless another control plane discovers them first.
Practical implication: extend discovery and offboarding logic beyond HR events so machine identities enter the governance lifecycle at creation.
Why long-lived secrets become governance failures
An NHI usually authenticates through a secret, token or certificate rather than interactive login. That means the credential often becomes the de facto identity control, and if it is long-lived, the blast radius lasts far beyond the original task. Rotation helps, but rotation alone does not answer who owns the identity, whether it still needs to exist, or whether its privileges still match its purpose. In other words, secret hygiene and identity governance solve different parts of the same problem, and both are required.
Practical implication: pair secrets management with ownership, attestation and decommission workflows instead of treating rotation as a complete control.
How AI agent credentials change the identity model
AI agents add another layer because they can call tools, access systems and act through credentials that may be provisioned outside normal workforce governance. They are still non-human identities when they operate through tokens, service accounts or API permissions, but their usage pattern is more dynamic than a static integration account. That makes access scope, purpose and owner context more important, not less. If an agent can access production APIs, its governance has to cover what it can do, who is responsible for it and how it is retired when the workflow changes.
Practical implication: treat AI agent access as governed NHI access, with explicit ownership, scope and retirement controls.
Threat narrative
Attacker objective: The objective is to reuse trusted machine access to reach systems, data or administrative pathways that were never meant to be exposed through a single credential compromise.
- Entry occurs when attackers obtain a non-human credential such as a service account secret, API key or token that was never brought into the governance workflow.
- Escalation follows when that credential still has standing access, allowing the attacker to move through systems that trust the machine identity more than the human controls around it.
- Impact is driven by broad, persistent access, which turns one overlooked credential into a path into workstations, SaaS data or production APIs.
Breaches seen in the wild
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
- iOS apps leaking hard-coded secrets: Cybernews found 71% of 156,080 iOS apps leak hard-coded secrets, with open cloud storage and Firebase databases exposing user data.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
NHI governance is now a baseline identity control, not a specialised add-on. The article is right to frame service accounts, API keys and AI agent credentials as identities that need inventory, ownership and lifecycle governance. When machine identities are created outside HR, the old assumption that identity equals employee no longer holds. Practitioners should treat machine identity governance as a core IGA requirement, not a separate hygiene project.
The real failure is not missing rotation, it is missing governability. Many organisations focus on the secret, but the deeper problem is that no one can reliably answer who owns the identity, why it exists or when it should disappear. That is the control gap attackers exploit when credentials outlive the application, integration or agent that created them. The practitioner implication is that governance must start with identity existence, not secret state.
Service account blind spots are an identity blast-radius problem. Once a machine identity carries excess privilege, every downstream system that trusts it inherits the same exposure. This is why overprivileged NHIs become a breach amplifier and an audit failure at the same time. Security teams should model machine identities as blast-radius multipliers, because one forgotten credential can outlive several human control cycles.
AI agent access collapses the old HR-centric governance model. An AI agent that authenticates through a token or service account still sits inside NHI governance, but its runtime behaviour makes static review assumptions weaker. Access review programmes were designed for identities that persist long enough to be certified on a cadence. The implication is that governance needs to follow the identity at issuance, not wait for a later review window.
Identity blast radius is the right concept for this category. The article's numbers and examples point to a structural issue: NHIs are multiplied across SaaS, cloud and AI workflows faster than teams can review them. That produces a widening exposure surface where the same missing control, ownership and offboarding discipline repeats across many different systems. Practitioners should use that lens to prioritise the identities with the widest downstream reach.
From our research library:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs
What this signals
Ownership, not storage, is the missing control: machine identities become governable only when a named human or team can attest purpose, approve scope and accept retirement responsibility. Without that ownership model, service accounts and tokens drift into an unmanaged parallel identity estate that IGA tooling cannot reliably close.
Service account governance should be treated as lifecycle governance, not a one-time discovery exercise. The real control boundary is at creation and retirement, where the organisation can enforce purpose, scope and offboarding before a credential becomes an enduring exposure.
Access review programmes that stop at employee identities will continue to miss the riskiest credentials in the estate. For many teams, the next maturity step is not broader review cadence, but bringing non-human identities into the same certification logic with machine-specific context.
For practitioners
- Map every machine identity source Inventory service accounts, API keys, OAuth apps, cloud service principals and AI agent credentials across SaaS, cloud and code repositories before setting governance policy.
- Assign a human owner at creation Require explicit ownership for every non-human identity so a named person or team can approve access, attest need and accept revocation responsibility.
- Tie offboarding to application retirement Trigger revocation when the workload, integration or project ends, rather than waiting for a human leaver event that will never arrive for the identity itself.
- Run attestation on machine identities Include service accounts and long-lived tokens in access reviews with usage, privilege and last-activity context so owners can certify or revoke with evidence.
- Scan for stale credentials and orphaned access Continuously detect dormant accounts, unrotated secrets and identities with privileges that no longer match the workload they support.
Key takeaways
- Non-human identities create a governance gap because they are created outside HR-centric identity workflows and therefore escape standard joiner-mover-leaver controls.
- The scale problem is material, with non-human identities outnumbering human identities by 40 to 1 in the typical enterprise.
- The control gap is closed by discovery, ownership, lifecycle management, access reviews and audit evidence for service accounts, API keys and AI agent credentials.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article centres on NHIs that outlive projects and leave no offboarding trigger. |
| NHI-05 — Overprivileged NHI | The article repeatedly notes excessive permissions on service accounts and API keys. | |
| NHI-07 — Long-Lived Secrets | Long-lived API keys and tokens are presented as a primary breach vector. | |
| Recommendation — Build offboarding triggers for every non-human identity when the workload or integration ends. Review NHI permissions against actual workload need and remove excess access. Rotate and expire long-lived NHI secrets on a policy basis, not ad hoc. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post is about governing permissions and entitlements for machine identities. |
| Recommendation — Apply entitlement governance to non-human identities with reviewable access scope. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | API keys, tokens and certificates are the authenticators the article says need lifecycle control. |
| Recommendation — Enforce authenticator lifecycle controls for machine credentials and retire stale ones. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article uses real incidents where compromised machine credentials enabled access and movement. |
| Recommendation — Map exposed machine credentials to credential access and lateral movement paths in detections. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- NHI Governance: NHI governance is the set of policies and controls used to manage non-human identities across their lifecycle. It covers issuance, access scope, monitoring, rotation, and retirement so machine credentials do not become hidden, durable attack paths.
- Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org