TL;DR: Nonhuman identities now outnumber human identities by roughly 144 to 1, according to Aembit’s discussion of Entro Security’s H1 2025 report, while ephemeral workloads and agentic AI are pushing machine access beyond static service account tooling. The governance question is no longer whether machine access matters, but whether IAM can move from credential administration to runtime identity control.
At a glance
What this is: Aembit argues that NHI has outgrown the service-account-only model because modern workloads, SaaS integrations, and agentic AI require runtime identity governance, not just credential administration.
Why it matters: IAM, PAM, and cloud security teams need to treat nonhuman access as a lifecycle and policy problem, because static account models do not fit short-lived workloads or dynamic machine-to-machine trust.
Context
Nonhuman identity is the access layer for software, workloads, bots, devices, and AI-driven systems that act without a human logging in each time. The governance problem is that many teams still manage this space as if every machine identity were just a service account with a password or key.
That model breaks when workloads are ephemeral, when trust decisions need to change at runtime, and when agentic systems generate their own API calls. The article frames the real issue as an IAM redesign problem: how to govern machine access when lifecycle, privilege, and context all move faster than static account tooling.
Key questions
Q: What breaks when nonhuman identities are managed like simple service accounts?
A: Static service-account management breaks when identities are ephemeral, cross-platform, or context-sensitive. The main failure is that long-lived credentials, manual rotation, and periodic reviews do not match how modern workloads actually authenticate. The result is excess standing access, missed revocation, and poor visibility into who or what can still call critical systems.
Q: Why do ephemeral workloads increase machine identity risk?
A: Ephemeral workloads increase risk because identity, location, and privilege can all change faster than manual processes can track. A short-lived workload may need access for minutes, but its credential and policy footprint can still outlive the task if lifecycle controls are weak. The risk is not just exposure, but stale trust that no longer matches the runtime state.
A: Security teams should treat agentic AI as an identity class that needs continuous observation, not just initial authorization. Governance has to cover who or what gets a secret, how it is used, and whether the observed runtime behaviour matches the intended task. That means combining policy, detection, and rapid remediation so access stays aligned with actual agent activity across the full secret lifecycle.
Q: What is the difference between certificate management and NHI governance?
A: Certificate management focuses on issuance, renewal, and expiry. NHI governance is broader because it also covers identity ownership, access scope, policy enforcement, auditability, and lifecycle controls for the services, workloads, and agents that depend on those certificates.
Technical breakdown
Why service account models stop fitting ephemeral workloads
Service account management assumes relatively stable identities, predictable runtimes, and credentials that can be assigned, rotated, and reviewed on a schedule. That assumption works in legacy server environments, where an account maps cleanly to a host or application. It breaks down when containers, functions, and workloads appear and disappear in seconds, because the identity lifecycle is no longer static. In those environments, the security question becomes whether access should exist for this runtime instance at all, not just whether an account exists in a directory. The article’s core point is that lifecycle and context are now part of the identity decision, not an afterthought.
Practical implication: Treat ephemeral workload identity as a runtime governance problem, not a directory cleanup problem.
How agentic AI changes machine identity governance
Agentic AI changes the access pattern because a single system can generate many API calls across multiple services within one user task. That means the machine identity is no longer just authenticating a service, it is expressing independent action at runtime through delegated access. Traditional service account tooling was built to manage stable credentials and known call paths, not to govern rapidly shifting access intent across chained tool calls. The article shows why that matters: when the system itself decides what to call and when, static privilege models cannot explain the actual access path well enough to govern it cleanly.
Practical implication: Design governance around runtime authorization decisions, not around a single long-lived identity record.
Dynamic trust relationships require policy at the point of use
NHI security in the article is not just about storing secrets more safely. It is about deciding whether a workload, API, or third-party integration should be trusted in the moment it asks for access. That implies conditional access based on runtime environment, workload location, behavior, and service context. Static credentials answer a different question, because they prove possession rather than justify the call. The governance shift is from 'who has the password' to 'should this workload make this request now' and that is a materially different control model for cloud and SaaS environments.
Practical implication: Move access decisions closer to request time so machine trust reflects current context rather than inherited privilege.
Breaches seen in the wild
- Cloudflare Thanksgiving breach 2023: One service token and three service accounts left unrotated after the Okta breach gave a nation-state attacker access to Cloudflare's Atlassian systems.
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
The service-account frame is now too narrow for modern nonhuman identity governance. Service accounts remain part of the problem space, but they no longer define it. Ephemeral workloads, federated cloud access, and agentic AI create access patterns that are governed by runtime context, not by a static directory entry. The implication is that nonhuman identity has become an identity architecture problem, not just an account management problem.
Identity decisions for machines are shifting from provisioning-time to request-time control. The old assumption was that least privilege could be set once and then reviewed later. That assumption fails when workloads are short-lived, mobile, or self-directed, because the real security question is whether access should be issued at the moment of use. Practitioners should treat that as a structural change in how machine access is authorised.
Runtime trust is the new control surface for machine identity. When a workload can appear in one environment, call multiple APIs, and disappear minutes later, entitlement reviews alone cannot tell you whether the access was appropriate. The valuable governance object is the trust relationship in motion, including where the identity runs, what it may call, and how long that permission remains valid. Security teams need to evaluate machine access at runtime, not only at creation time.
Ephemeral credential trust debt is the named governance gap this article exposes. Short-lived systems still accumulate risk when the surrounding governance model assumes a stable identity lifecycle and static ownership. That assumption weakens as workloads, APIs, and AI agents proliferate across clouds and SaaS services. The implication is that identity programmes must be built around issuance, revocation, and context-aware verification rather than around a service-account review cadence.
Machine identity governance is becoming inseparable from broader IAM strategy. The article shows why siloed ownership between infrastructure, application, and security teams leaves gaps in attestation, auditability, and scope control. Organisations that keep nonhuman identity in a separate operational box will keep missing shared controls for lifecycle, conditional trust, and privileged access. Practitioners should align NHI governance with enterprise IAM rather than treating it as an isolated admin function.
What this signals
Ephemeral credential trust debt: The biggest governance gap is not the existence of machine credentials, but the way static ownership and review models outlive the workload that used them. As cloud-native systems become more transient, access governance has to move to issuance time and request time.
Organizations that keep nonhuman identity inside a service-account program will continue to miss third-party tokens, federated workload identities, and AI-generated API calls. That blind spot matters because these identities often sit outside directory-centric review processes even when they carry production access.
For practitioners
- Define machine identity by runtime context Inventory which workloads, APIs, and AI-driven processes need access based on where they run, what they call, and how long the access should last.
- Replace static trust with request-time policy Use policy decisions at request time for ephemeral workloads so that access is granted only when current conditions match the intended use.
- Separate legacy service accounts from dynamic NHI workflows Keep traditional service-account processes for stable systems, but move cloud-native and agentic patterns into a governance model that can handle short-lived credentials and revocation on demand.
- Review third-party machine access as a lifecycle asset Track API keys, OAuth tokens, and federated identities used outside your directory model so they are included in ownership, rotation, and offboarding decisions.
- Tie audit evidence to actual access requests Capture every machine-authenticated request so reviews can show who or what asked for access, from where, and under which policy decision.
Key takeaways
- Nonhuman identity is no longer just a service-account issue, because modern workloads and AI-driven systems create runtime access patterns that static account models do not govern well.
- The practical gap is lifecycle mismatch: ephemeral access, third-party credentials, and machine-to-machine trust need controls that operate at request time, not only at review time.
- IAM teams should align NHI governance with runtime policy, revocation, and audit evidence, or the organisation will keep inheriting stale machine trust.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on machine identities whose access scope no longer matches dynamic runtime needs. |
| NHI-07 — Long-Lived Secrets | Static passwords, keys, and tokens are the control weakness the article says no longer fits modern workloads. | |
| NHI-08 — Environment Isolation | The article describes workloads whose access should vary by runtime environment and deployment context. | |
| Recommendation — Review machine access scope continuously and reduce privileges that persist beyond the task. Replace long-lived machine secrets with short-lived credentials tied to runtime conditions. Isolate workload identities by environment so production access cannot bleed into staging or test. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about governing nonhuman permissions and authorizations across modern infrastructure. |
| Recommendation — Align machine entitlements with current business need and runtime policy rather than static ownership. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud workload identity, SaaS access, and federated machine credentials are central to the article. |
| Recommendation — Apply IAM controls to govern nonhuman identities across cloud and SaaS access paths. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article’s risk model includes machine credentials being reused to reach multiple systems. |
| Recommendation — Map exposed machine credentials to credential access and lateral movement paths in detection rules. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
- Runtime Trust: Runtime trust is the idea that access should remain valid only while current context justifies it. Instead of trusting a setup decision indefinitely, teams continuously re-evaluate whether a workload or agent still deserves privilege. This approach is especially important for AI agents that can change behaviour mid-task.
- Ephemeral Cloud Workload: A workload that exists for a short time, often created and destroyed automatically as demand changes. Ephemeral systems are difficult for traditional security tools to track because they may appear, scale, and disappear before manual onboarding or agent deployment can keep pace.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org