By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Breaking Down Non Human Identity Security: 5 Critical Challenges in 2025” (May 1, 2026)

TL;DR: Non-human identities are multiplying across cloud, SaaS, DevOps, AI, and third-party integrations, yet many organisations still lack visibility, ownership, and lifecycle control, according to Oasis Security. The real issue is not just secret sprawl but governance built for identities that are easier to inventory than machine accounts with on-demand creation and hidden dependencies.


At a glance

What this is: This analysis explains why NHI security in 2025 is still being undermined by poor inventory, unclear ownership, weak lifecycle control and overexposed service accounts.

Why it matters: IAM, PAM and NHI teams need to treat discovery, access scope and offboarding as one governance problem because hidden machine identities become operational and security liabilities fast.

By the numbers:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

Context

Non-human identity governance is about knowing what machine identities exist, what they can access, who owns them and when they should disappear. In this article, the gap is not a single missing control but a programme design problem: most enterprises still discover service accounts, API keys and automation identities late, if at all.

That matters because cloud services, SaaS integrations, DevOps pipelines and AI workflows create identities in ways human IAM processes were never built to track. If ownership, lifecycle and usage are unclear, least privilege and revocation become partial controls rather than reliable governance.


Key questions

Q: What breaks when organisations cannot see their non-human identities?

A: When NHIs are invisible, least privilege, credential rotation, and access review all become incomplete. Teams cannot certify what they do not know exists, and shadow AI can keep operating outside policy for long periods. The result is unmanaged access with weak ownership, weak logging, and a much larger blast radius if credentials are abused.

Q: Why do service accounts create more governance risk than many IAM teams expect?

A: Service accounts often persist longer than the systems and teams that created them, which makes ownership and review harder over time. That persistence turns them into hidden access paths when privilege is not regularly reviewed or revoked. IAM teams should treat service account inventory and lifecycle control as core governance work, not as operations plumbing.

Q: When should security teams remove or rotate NHI credentials?

A: Remove or rotate credentials when the workflow changes, the owner changes, the identity is no longer needed, or the access cannot be justified. For high-risk NHIs, periodic rotation should be routine rather than exceptional, because stale credentials are a common path to compromise.

Q: What is the difference between NHI visibility and NHI governance?

A: Visibility shows what identities exist, where they live, and how they behave. Governance adds ownership, policy, remediation, and accountability. A team can have dashboards without control, but it cannot govern identities effectively without a trusted inventory and a way to act on what it finds.


Technical breakdown

Why on-demand NHI creation breaks inventory models

Cloud services, SaaS platforms and automation scripts can create non-human identities without a central request, approval or directory entry. That means the identity estate is often larger than the register teams think they own. Discovery tools help, but the real issue is that creation is distributed across platforms and often detached from IAM governance. When an API key or service account appears outside an explicit workflow, the organisation has no durable source of truth for inventory, ownership or review.

Practical implication: build continuous discovery across cloud, SaaS and DevOps estates so inventory is not dependent on manual registration.

How hidden dependencies turn credential revocation into a risk decision

The article highlights a common operational tension: teams hesitate to revoke a credential because they fear breaking a critical workflow. That is usually a sign that the NHI is supporting an undocumented dependency, not that the credential should stay in place indefinitely. In practice, service accounts accumulate permission and process coupling until nobody can explain the blast radius of removal. That shifts revocation from a simple hygiene task into a change-management and dependency-mapping exercise.

Practical implication: map consumers, downstream services and failure tolerance before revoking or narrowing any NHI credential.

Why lifecycle control matters more than one-time cleanup

NHI security does not improve if organisations only find identities once and then stop. The article's recommended pattern is continuous ownership, expiration and access review, which is the only way to keep machine identities aligned with actual use. Without a lifecycle model, stale service accounts, hardcoded credentials and forgotten integrations persist long after the original project ends. That creates governance debt that accumulates quietly across cloud, on-prem and third-party environments.

Practical implication: assign owners, expiry dates and recurring review triggers to every NHI, including legacy and third-party identities.


Threat narrative

Attacker objective: The objective is to use poorly governed machine identities as a durable access path into cloud, SaaS or integration environments.

  1. Entry begins when developers, vendors or automation systems create non-human identities on demand, often outside central tracking.
  2. Escalation occurs when those identities accumulate excess permissions or persist after their intended use, expanding the exposed access surface.
  3. Impact follows when attackers or failed workflows exploit forgotten credentials, undocumented dependencies or third-party access paths to reach connected systems.
  • Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
  • Cisco Active Directory credentials leak 2025: Kraken leaked Cisco Active Directory hashes, including service and krbtgt accounts; Cisco says they came from its 2022 breach, not a new one.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Non-human identity visibility is now a baseline governance requirement, not an inventory project. If an organisation cannot reliably enumerate service accounts, API keys and automation identities, it cannot prove ownership or control. The problem is not just secret sprawl but the absence of a defensible system of record. Practitioners should treat discovery as an ongoing control, not a one-time clean-up exercise.

Undocumented dependencies are what make NHI revocation operationally hard. The article correctly points to the fear of breaking something critical, which usually means the dependency map is missing rather than the credential being essential. That is where governance debt accumulates: access persists because the business impact of removal is unknown. Teams need to understand that uncertainty itself is the control failure.

Lifecycle governance, not isolated hardening, is the decisive NHI control pattern. Ownership, expiry, access review and offboarding have to operate together because machine identities are created, consumed and abandoned across multiple systems. OWASP-NHI, NIST CSF and Zero Trust all converge on the same practical reality: if the identity outlives the business need, the control has failed. The practitioner's task is to make every NHI accountable from creation through decommissioning.

Third-party and AI-related NHIs widen the same governance gap rather than creating a separate one. The article's cloud, SaaS, DevOps and AI examples all point to the same issue: machine identities are now distributed across operational domains that traditional IAM programmes govern separately. That fragmentation makes hidden access easier to miss and harder to retire. Security teams should reframe NHI risk as a cross-programme governance problem, not a narrow secrets problem.

Identity blast radius is the right named concept for this problem space. A machine identity is dangerous when its permissions, consumers and lifetime are all poorly bounded, because the impact of compromise or misuse spreads beyond the original system. That is why least privilege alone is not enough if ownership and offboarding are missing. Practitioners should manage blast radius across the full lifecycle, not just at issuance.

From our research library:

What this signals

Identity blast radius: the article points to a programme failure where machine identities are created faster than they are inventoried, owned and retired. That means the real control objective is not just secret protection but reducing the number of places a forgotten credential can still reach.

The operational signal for practitioners is clear: if a team cannot explain the consumer, owner and expiry of a service account, that identity is already outside governance. The right response is to move NHI control into the same lifecycle discipline used for access reviews, offboarding and privileged access management.

A useful benchmark from NHI Mgmt Group's research is that only 5.7% of organisations have full visibility into their service accounts according to the Ultimate Guide to NHIs. That figure should be read as a governance warning, not a maturity badge, because visibility without ownership still leaves hidden access intact.


For practitioners

  • Implement continuous NHI discovery Scan cloud, SaaS and DevOps environments for service accounts, API keys and automation identities that were never registered centrally.
  • Map every hidden dependency before revocation Document the consumers, workflows and downstream systems that rely on each non-human identity before changing access or deleting it.
  • Assign ownership and expiry dates to all machine identities Make every service account, token and key accountable to a named owner with a review date and removal trigger.
  • Limit access scope to the minimum function Remove broad permissions from identities that support integrations, pipelines or background jobs and validate the reduced access against actual use.
  • Build offboarding into the identity lifecycle Retire stale NHIs as part of joiner-mover-leaver and project closure workflows so abandoned access does not linger in cloud or SaaS estates.

Key takeaways

  • The core problem is not simply secret sprawl but weak governance over machine identities that are created, used and abandoned across cloud, SaaS, DevOps and AI workflows.
  • Oasis Security's article aligns with a wider identity security pattern: organisations cannot control what they cannot inventory, and most still lack full visibility into service accounts.
  • Practitioners should focus on continuous discovery, ownership assignment and lifecycle offboarding because those controls reduce both hidden access and the risk of breaking critical dependencies.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article repeatedly points to stale and forgotten NHIs that remain after their intended use ends.
NHI-05 — Overprivileged NHIThe post warns that service accounts and integrations often carry permissions beyond their actual function.
NHI-07 — Long-Lived SecretsHardcoded credentials and unrotated keys are central to the DevOps and automation risk discussed here.
Recommendation — Track every machine identity to offboarding and remove it when the owning workflow ends. Reduce NHI permissions to the minimum function and review scope whenever usage changes. Rotate long-lived NHI secrets and replace them with shorter-lived credentials where possible.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article's governance gap is fundamentally about who and what can access systems through machine identities.
Recommendation — Review entitlements for NHIs regularly and align access with current business use.
CIS Controls v8CIS-5 — Account ManagementService accounts, API keys and automated identities need disciplined account lifecycle management.
Recommendation — Inventory, monitor and retire non-human accounts using account management processes.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe attack pattern described by the article maps to credential abuse and movement through connected systems.
Recommendation — Hunt for exposed machine credentials and map their downstream access paths for lateral movement risk.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org