By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Solving Non Human Identity Ownership with Oasis. Part 2: Ownership attestation” (May 1, 2026)

TL;DR: Ownership discovery and attestation are intended to keep non-human identities accurate, accountable, and compliant over time, while reducing manual review cycles, unresolved ownership, and audit friction, according to Oasis Security. The governance issue is not review cadence alone, but the fact that many NHI programmes still cannot prove who owns what, when access is no longer needed, or whether attestation decisions are timely.


At a glance

What this is: This is a blog on NHI ownership attestation, showing that discovery alone is not enough unless teams can repeatedly confirm ownership, usage, and need for each non-human identity.

Why it matters: It matters because IAM, IGA, and PAM teams cannot govern service accounts and other NHIs effectively when ownership is unclear, attestation is manual, and outdated permissions remain in place.


Context

Non-human identity ownership attestation is the process of repeatedly confirming who is responsible for a service account, token, key, or other machine identity and whether it still needs access. Discovery can locate identities, but governance fails when ownership is not assigned or cannot be proven.

The operational problem is not just review cadence. Campaign-based attestation, manual follow-up, and spreadsheet-driven ownership chase create delay, fatigue, and gaps in accountability, which leaves NHIs with permissions that no one has actively revalidated.


Key questions

Q: What breaks when NHI ownership is missing?

A: When NHI ownership is missing, access reviews lose context, incident response slows, and stale identities persist longer than they should. The programme may still have tools and policies, but it lacks the accountable decision path needed to execute them reliably.

Q: Why do periodic NHI attestation campaigns often stall?

A: They stall because the programme keeps reassembling ownership context instead of governing from a stable record. Each cycle forces teams to rediscover who should review what, which creates manual chasing, late responses, and fatigue. The weaker the ownership data, the slower the governance loop becomes.

Q: How do security teams know if NHI authorization is actually working?

A: Look for consistent allow and deny decisions at runtime, complete audit logs for each request, and fewer services that need code-level permission checks. If teams still rely on service-wide roles or cannot explain why a request was allowed, authorization is not being enforced tightly enough. The signal is decision precision, not credential rotation frequency.

Q: Who should own NHI attestation decisions in an IAM programme?

A: Ownership should sit with the business or technical team that can validate the identity’s purpose and accept the risk of continued access, with IAM or IGA providing the control framework. If the reviewer cannot explain why the identity exists, the attestation model is too detached from operations.


Technical breakdown

Why ownership discovery and attestation are different controls

Discovery answers what exists, while attestation answers whether each identity still has a valid owner and a valid business need. In NHI programmes, those are separate control points. A discovered account can still remain unmanaged if no one is accountable for reviewing its permissions or confirming its continued use. Attestation turns static inventory into governance evidence by binding identities to named human reviewers and documented decisions.

Practical implication: treat ownership discovery as the inventory layer and attestation as the control layer that proves ongoing governance.

Why campaign-based NHI reviews break down at scale

Campaign attestation assumes identities can be gathered, assigned, and reviewed on a fixed cycle without losing context. That model is brittle when thousands of NHIs span teams, systems, and business units. The friction comes from repeatedly rediscovering ownership, not from the review action itself. Manual workflows increase the chance of stale assignments, late responses, and identities drifting beyond their intended scope between review windows.

Practical implication: reduce dependency on periodic bulk campaigns by making ownership data continuously usable, not episodically reconstructed.

How attestation decisions map to lifecycle outcomes

Attestation only matters when each outcome drives a lifecycle action. Approved means the identity remains authorised, not needed means it should be deactivated or removed, and not the owner means the governance record is wrong and must be corrected before the next review. Without those outcome paths, attestation becomes a reporting exercise rather than a lifecycle control. The value is in forcing a decision that can change access state or accountability.

Practical implication: connect every attestation response to a removal, reassignment, or approval workflow so the decision changes the identity record.


NHI Mgmt Group analysis

Ownership is the missing control plane for NHI governance: discovery without accountable ownership leaves machine identities visible but not governable. The problem is not that organisations lack inventory, but that inventory does not tell you who can certify use, revoke access, or accept risk. That gap is why attestation becomes the governance bridge between visibility and action. Practitioners should treat ownership as a lifecycle control, not a directory field.

Campaign attestation is still a compensating control, not a complete model: periodic reviews can reduce stale access, but they also inherit the weaknesses of batch governance. If ownership must be rediscovered every cycle, the process is already behind the environment it is supposed to govern. The result is administrative fatigue, delayed decisions, and a higher chance that overdue identities keep their permissions by default. Practitioners need to measure how much manual effort the campaign itself consumes.

Attestation becomes valuable when it produces enforceable outcomes: an approved identity, a removed identity, or a corrected owner record each change the governance state. That is the difference between compliance theatre and operational control. NHI programmes that stop at review completion but do not drive deactivation or reassignment are not closing the loop. Practitioners should tie attestation to lifecycle enforcement.

Identity accountability for NHIs is now a board-level governance signal: the issue here is not only security hygiene, but whether an organisation can prove responsibility for machine access at audit time. That affects IAM, IGA, and PAM operating models at once. When ownership is implicit instead of explicit, the organisation cannot demonstrate who accepted the access decision or when it became stale. Practitioners should elevate NHI ownership records to governed control evidence.

Persistent ownership ambiguity creates an NHI governance debt: every unresolved owner, every manual chase, and every missed attestation compounds the same problem. The concept is simple, but the operational effect is cumulative: the longer ownership remains unclear, the more access decisions drift away from accountable review. Practitioners should treat unresolved ownership as deferred risk, not administrative backlog.

From our research library:

What this signals

NHI governance debt: unresolved ownership is not just an administrative issue. Each missed attestation leaves a machine identity one step further from accountable review, and the cost compounds when the next campaign has to rediscover the same context again.

Ownership data becomes the control surface: the review workflow is only as strong as the record behind it. When ownership is explicit, attestation can drive removal, reassignment, or approval with minimal friction; when it is not, the programme spends its time reconstructing the basics instead of governing access.

Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs, which is why attestation programs so often struggle to prove who owns what and whether it still belongs in the environment.


For practitioners

  • Define ownership before attestation begins Require every NHI to have a named human owner or accountable team before it enters a review campaign. If ownership is missing, route the identity to reassignment rather than approval.
  • Separate discovery from certification Use discovery to populate the inventory, then use attestation to confirm continued need, approved use, and correct ownership. Do not let the same process try to do both jobs at once.
  • Convert review responses into lifecycle actions Make approved, not needed, and not the owner trigger different downstream outcomes such as keep, remove, or reassign. If the response does not change the identity record, the review has no governance effect.
  • Target high-risk identities first Prioritise NHIs with broad access, unclear ownership, or repeated attestation delays. Those accounts are the ones most likely to accumulate stale permissions and unresolved accountability.
  • Measure attestation friction as a control signal Track late responses, ownership exceptions, and manual follow-ups as indicators that the programme is spending more time recovering context than governing access.

Key takeaways

  • NHI ownership attestation is the control that turns discovered identities into governed identities by confirming who owns them and whether they still need access.
  • Manual, campaign-based review models struggle because they repeatedly recreate ownership context instead of maintaining it continuously.
  • The practical goal is not to complete reviews, but to make every outcome change the identity record through removal, reassignment, or explicit approval.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingNot-needed outcomes and lifecycle removal are central to this attestation workflow.
NHI-05 — Overprivileged NHIAttestation is intended to surface NHIs whose permissions no longer match business need.
NHI-10 — Human Use of NHIThe article is explicitly about humans attesting to and owning non-human identities.
Recommendation — Use NHI-01 to ensure attestation results trigger removal when an identity is no longer required. Apply NHI-05 to review and trim permissions that exceed current operational requirements. Govern human ownership and review responsibility under NHI-10 so accountability stays explicit.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about maintaining accurate access and authorization decisions for NHIs.
Recommendation — Apply PR.AA-05 to keep NHI entitlements current and tied to valid business need.
CIS Controls v8CIS-5 — Account ManagementAttestation supports ongoing account ownership and lifecycle control for machine identities.
Recommendation — Use CIS-5 to maintain accountable ownership and lifecycle oversight for NHI accounts.

Key terms

  • Non-Human Identity Attestation: Non-human identity attestation is the recurring review of who owns a machine identity and whether that identity still needs access. It turns inventory into governance by forcing a human decision on ownership, usage, and continued authorization at the lifecycle stage where stale access can otherwise persist.
  • Ownership Discovery: Ownership discovery is the process of identifying the most likely accountable owner for a non-human identity when that ownership is missing, unclear, or incomplete. In practice, it creates the reference record that attestation depends on, because review cannot be governed when no reviewer can be assigned.
  • Attestation Campaign: An attestation campaign is a structured review cycle that asks owners to confirm, reject, or reassign identities or permissions in scope. For NHI governance, the campaign is only useful when it is linked to lifecycle events and downstream enforcement, otherwise it becomes a reporting task.
  • Governance Debt: The accumulation of unresolved identity control weaknesses created when teams prioritise speed over lifecycle design. In NHI environments, it shows up as accounts with unclear ownership, undocumented purpose, stale credentials, and no reliable retirement path, all of which make later security work harder.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or NHI governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org