By NHI Mgmt Group Editorial TeamBased on Oasis Security: “What Are Non-Human Identities (NHIs) and Why Are They Risky?” (October 10, 2025)

TL;DR: Non-human identities now outnumber human users by 45 to 1 in the modern enterprise, with some organisations reaching 100 to 1, according to Oasis Security and Rubrik Zero Labs cited in the article, and many still rely on long-lived secrets, excessive privilege, and weak ownership. Human-era IAM controls stop being sufficient when machine access becomes the dominant identity surface.


At a glance

What this is: This is a governance article explaining why non-human identities have become a larger and riskier identity surface than human users, with scale, secret exposure, and ownership gaps driving the central finding.

Why it matters: It matters because IAM, PAM, and IGA teams can no longer treat machine credentials as edge cases; the article shows that NHI inventory, rotation, and accountability are now core controls.

By the numbers:

  • Non-human identities now outnumber human users by 45 to 1 in the modern enterprise.
  • Some organisations are seeing ratios as high as 100 to 1.
  • The growth represents a 400% increase.

Context

Non-human identities are machine identities used for system-to-system access across cloud, on-premises, and edge environments. In this article, Oasis Security argues that the scale and autonomy of these identities make traditional human IAM controls incomplete, especially when credentials are long-lived and ownership is unclear.

The governance problem is not just volume. NHIs are often created outside central IAM processes, protected only by embedded secrets, and left active long after the workload or integration that created them has changed. That combination creates a persistent access layer that security teams cannot manage well with human-centric review cycles.


Key questions

Q: Why do non-human identities complicate traditional IAM programmes?

A: Non-human identities complicate IAM because they often outnumber human identities, hold broad permissions, and operate outside normal joiner-mover-leaver processes. They are harder to inventory, harder to recertify, and easier to leave behind after a project or vendor relationship ends. That makes ownership and revocation the decisive governance issues.

Q: What is the business impact of unmanaged non-human identities?

A: Unmanaged NHIs increase the chance that a leaked or forgotten credential stays active long enough to be abused. The business impact is broader than account compromise because these identities often sit on critical integrations, cloud workloads, and data paths. One exposed secret can turn into persistent access, outage risk, or large-scale data exposure.

Q: What breaks when non-human identity ownership is unclear?

A: When ownership is unclear, rotation stalls, reviews default to approval, and nobody feels safe removing access. That creates orphaned identities, stale credentials, and broad permissions that persist because the organisation cannot prove what depends on them. The result is a growing attack surface with no accountable decision-maker.

Q: How should security teams decide between dynamic secrets and rotation?

A: Use dynamic secrets for short-lived, task-scoped workloads where access should expire automatically. Use rotation for accounts that must persist for audit, continuity, or integration stability. The decision should follow the identity lifecycle, not the team’s preference for one control pattern. If the account needs to remain visible over time, rotation is usually the safer fit.


Technical breakdown

Why NHI scale breaks human IAM assumptions

Non-human identities are not interactive users, so the controls that work for people do not translate cleanly. Human IAM depends on MFA, SSO, behavioural oversight, and named ownership. NHIs, by contrast, are created programmatically, may be shared across services, and frequently authenticate with API keys, service accounts, tokens, or certificates. Once those identities multiply into the tens or hundreds of thousands, visibility and lifecycle control become the real problem, not simple authentication. The result is a governance model that cannot tell what exists, who owns it, or whether it is still needed.

Practical implication: build a complete inventory and ownership map before trying to enforce policy.

Why long-lived secrets create persistent attack paths

A secret is only as safe as its rotation, scope, and exposure boundary. When API keys, access keys, OAuth tokens, or certificates live for years, a single leak can create a durable access path that survives long after the original business need has changed. The article points out that some NHI credentials have no expiration by default, which turns a temporary configuration choice into a standing control failure. This is why secret sprawl is more than hygiene debt: it is a direct contribution to attack persistence and blast radius.

Practical implication: prioritise short-lived credentials and rotation policies for the highest-risk machine accounts.

How weak ownership turns NHI governance into avoidance

Ownership is the hinge control in NHI governance. If no team can confidently say which application uses a credential, what it touches, and what will break if it is removed, then revocation and rotation get deferred. The article describes this as a practical operational risk because teams avoid change when the dependency map is missing. That avoidance is often mistaken for caution, but it is really governance paralysis. Without clear ownership, every NHI becomes a permanent exception, and every exception expands the attack surface.

Practical implication: assign accountable owners to each NHI and make dependency mapping part of the change process.


Threat narrative

Attacker objective: The attacker aims to convert a leaked machine credential into durable, low-friction access that can be reused across cloud and SaaS environments.

  1. Entry begins when exposed NHI credentials are leaked through public repositories, CI/CD logs, misconfigured storage, or third-party integrations.
  2. Credential access succeeds because the secret alone is sufficient for authentication, with no MFA or user challenge to interrupt abuse.
  3. Escalation follows when over-permissioned service accounts enable access to additional cloud services, data stores, or SaaS platforms.
  4. Impact is persistent, automated access to sensitive systems and data, often without triggering the behavioural signals used for human accounts.

NHI Mgmt Group analysis

NHI governance is no longer a side discipline of IAM. Once machine identities outnumber human users at this scale, they become the primary access fabric for modern enterprises. That changes the control problem from user authentication to identity inventory, ownership, and lifecycle discipline. Practitioners should treat NHI governance as a first-class security programme, not an extension of user administration.

Long-lived secrets create identity blast radius, not just secret sprawl. The article's core risk is that a leaked credential can remain valid for years and reach far beyond its original purpose. That means compromise is not only about exposure, but about how long the exposure remains usable. Practitioners need to think in terms of blast radius reduction, because rotation without scope reduction still leaves a dangerous identity surface.

Human-era IAM controls fail when the subject is a machine. Human IAM assumes a named person, interactive login, and reviewable sessions. NHIs break those assumptions because they are created programmatically, reused across systems, and often invisible to traditional access review. The implication is clear: access governance must move to issuance, ownership, and consumption controls rather than relying on periodic human recertification alone.

NHI ownership is the control that determines whether remediation is possible. The article repeatedly shows that teams hesitate to rotate or revoke credentials when dependencies are unknown. That hesitation is not a process gap at the margin; it is the point where governance breaks down. Practitioners should make accountability and dependency mapping prerequisites for any NHI lifecycle action.

Short-lived credentials are a policy outcome, not a product feature. The article links temporary authentication to lower misuse risk, but only if organisations also reduce hidden dependencies and eliminate default persistence. This is where OWASP-NHI, Zero Trust, and access governance intersect. Practitioners should align machine credential policy with ownership, visibility, and revocation discipline, or the control will remain incomplete.

From our research library:

What this signals

Credential lifetime is the governance variable that matters most. When a machine credential can remain valid for years, the real issue is not whether it was issued securely, but whether it can still be abused long after the original task changed. Identity teams should treat expiry and rotation as core access controls, not maintenance tasks.

Identity blast radius will become the practical measure of NHI risk. The larger the credential scope and the weaker the ownership model, the more one compromise can spill across workloads, SaaS integrations, and cloud data paths. That is why NHI governance needs to be tied to dependency mapping and revocation readiness, not just secret discovery.

NHI ownership and lifecycle controls are now Zero Trust prerequisites. Zero Trust assumes continuous verification, but that model is incomplete when the enterprise cannot answer who owns a machine identity or whether it is still in use. Teams should align governance with issuance, scope, and offboarding, because those are the points where machine access is actually controlled.


For practitioners

  • Inventory every non-human identity Build a complete register of service accounts, API keys, tokens, certificates, and workload identities across cloud, SaaS, and on-premises systems. Include owner, purpose, expiry, last rotation date, and downstream dependencies so you can separate active access from forgotten access.
  • Assign accountable owners Require a named business or engineering owner for each NHI and make that owner responsible for renewal, rotation, and offboarding decisions. If ownership is shared or unknown, treat the credential as a governance exception until it is resolved.
  • Shorten credential lifetime Replace long-lived secrets with short-lived tokens or certificates wherever the integration allows it, and set rotation rules based on usage criticality rather than convenience. Prioritise credentials that have no expiry or have not been rotated in years.
  • Map dependency before revocation Before rotating or removing a credential, identify every workload, application, and external service that depends on it. Use that mapping to prevent production disruption and to distinguish truly dead credentials from hidden shared dependencies.

Key takeaways

  • Non-human identities have become a larger identity surface than human users, and human-era IAM patterns do not govern them well enough.
  • The main risks are persistent secrets, excessive privilege, and unclear ownership, which together make machine access hard to review and easy to abuse.
  • The most effective controls are inventory, accountable ownership, shorter credential lifetime, and dependency mapping before rotation or revocation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article centres on leaked API keys, tokens, and certificates as the main exposure path.
NHI-05 — Overprivileged NHIExcessive permissions turn a leaked credential into broad internal access.
NHI-07 — Long-Lived SecretsThe article repeatedly warns that NHIs persist with credentials that live for years.
Recommendation — Scan for exposed machine secrets and revoke any leaked credential immediately. Reduce machine credential scope to the minimum access each workload actually needs. Replace long-lived NHI secrets with shorter-lived authentication wherever possible.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential issuance, rotation, and revocation are central to the article's governance argument.
Recommendation — Apply authenticator management to enforce rotation and retirement of machine credentials.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on controlling entitlements and ownership for non-human identities.
Recommendation — Review machine entitlements regularly and remove unused access paths.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article describes exposed secrets and overprivileged service accounts as paths to abuse and spread.
Recommendation — Map exposed machine credentials to credential-access and lateral-movement detections.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Secret: A secret is the credential that proves a non-human identity is allowed to act. In practice it may be an API key, token, password or certificate. If it is exposed, reused or left valid too long, the resulting compromise can look legitimate to downstream systems.
  • Workload Identity: The identity assigned to a software workload, such as a containerised application, serverless function, or microservice, enabling it to authenticate to other services without storing static credentials.
  • Credential Sprawl: Credential sprawl is the uncontrolled accumulation of machine secrets, keys, and tokens across systems, teams, and environments. It usually starts with a single use case and ends with overlapping permissions, unclear ownership, and a larger attack surface than the organisation expected.

Deepen your knowledge

NHI governance, machine identity security, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on May 31, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org