TL;DR: Ungoverned credentials, fragmented workflows, and late-stage remediation leave NHI risk baked in before teams can react, according to Oasis Security, whose NHI provisioning capability creates and governs non-human identities from the start, with policy enforcement, ownership assignment, vaulting, rotation, and deprovisioning set during request approval and applied through the lifecycle.
At a glance
What this is: This is a product announcement about NHI provisioning that shifts policy, ownership, vaulting, rotation and deprovisioning to the moment an identity is created.
Why it matters: It matters because IAM, IGA, PAM and NHI teams cannot treat provisioning as a later cleanup step when access, accountability and secret handling are all decided at birth.
Context
NHI provisioning is the point where a non-human identity is created, approved, and attached to access, ownership, and secret handling. When that step is fragmented or left to follow-on workflows, the identity estate starts life outside consistent governance.
Oasis Security frames the problem as one of governance starting too late, especially in cloud and hybrid environments where teams move quickly and ownership gets diluted. The article argues that policy, vaulting, rotation and deprovisioning need to be established before the identity exists, not after exceptions accumulate.
The practical issue for identity programmes is not just speed. It is whether provisioning becomes the control point that prevents unmanaged NHIs from ever entering the environment in the first place.
Key questions
Q: What breaks when NHI provisioning happens without ownership and policy at creation time?
A: The identity enters production already outside governance. Ownership, rotation, and decommissioning then become reactive clean-up tasks instead of built-in controls, which increases the chance of orphaned credentials, inconsistent vaulting, and delayed audit response. Provisioning is the moment when intent should be fixed, not inferred later from usage.
Q: How should teams choose between credential-based and federated NHIs?
A: Use federated identity when the workload can authenticate through trust relationships instead of storing a secret. Use credential-based identities only when the use case truly requires a managed credential, and then enforce vaulting, rotation, and offboarding from day one. The decision should be driven by governance risk, not developer convenience alone.
Q: What are the signs that NHI governance is failing in an enterprise?
A: Common warning signs include unclear ownership for service accounts, secrets stored in code or configuration instead of managed vaults, infrequent rotation, and weak offboarding of API keys. Other red flags are excessive permissions, third-party exposure without controls, and low visibility into where non-human identities exist or how they are used across the stack.
A: They should standardise the request and approval logic so every path applies the same policy decisions before identity creation. The goal is not to eliminate tooling variety, but to stop governance from varying by channel. Provisioning must produce the same ownership and lifecycle outcome regardless of entry point.
How it works in practice
Why NHI provisioning is the control point, not an admin task
NHI provisioning is the workflow that creates the identity, binds it to an access model, and records who owns it. In mature governance, that step should also define where credentials live, how rotation works, and how deprovisioning will happen. If those decisions are made later, the organisation is effectively allowing unmanaged identity state to exist first and be governed second. That is the core failure pattern this article addresses: identity sprawl begins at issuance, not during remediation.
Practical implication: treat NHI provisioning as a governance gate that must set ownership, credential handling and lifecycle policy before access is issued.
Credential-based identities versus federated identities
The article separates two provisioning outcomes: credential-based identities, which require secret generation and storage, and federated identities, which rely on trust relationships such as IAM roles, managed identities, or OIDC. That distinction matters because the governance burden is different. Credential-based NHIs create rotation, vaulting and leakage risk, while federated identities shift the control problem toward trust configuration, scope and offboarding. The right provisioned form depends on how the resource is accessed and what lifecycle burden the team is willing to govern.
Practical implication: choose the identity form first, then apply controls that match the resulting trust and secret model.
How policy-based ILM changes NHI lifecycle enforcement
Policy-based identity lifecycle management ties provisioning-time decisions to later enforcement. In this model, the same request that creates the NHI also seeds rules for ownership, vaulting, rotation and deprovisioning, which are then enforced as the identity moves through inventory, posture and detection workflows. The architectural value is consistency: the control logic does not depend on a separate cleanup project or a manual handoff. For governance teams, that means lifecycle controls become part of issuance rather than a separate aftercare function.
Practical implication: align provisioning with ILM policy so every newly created NHI enters inventory with enforceable lifecycle rules attached.
NHI Mgmt Group analysis
Provisioning-time governance is now the boundary where NHI risk is decided. When ownership, rotation and deprovisioning are deferred until after creation, the organisation has already accepted unmanaged identity state into production. That is not a minor process gap, it is a lifecycle design flaw. The implication is that identity programmes should measure control at issuance, not only at audit or cleanup time.
Identity sprawl is a provisioning problem before it becomes a detection problem. The article shows that inconsistent provisioning creates the conditions for later misconfiguration, because every ungoverned identity expands the attack surface from day one. Security teams cannot reliably detect their way out of identities that were never born under policy. Practitioners need to treat provisioning controls as the first line of NHI governance.
Federated identity reduces secret burden, but it does not remove governance burden. The article correctly distinguishes identities with managed credentials from identities created through trust relationships such as OIDC or cloud-native roles. That distinction matters because the control point shifts from secret handling to trust scope, ownership and revocation logic. Teams should not confuse credentialless access with governance-free access.
Automation only helps when the policy is already encoded. The article's strongest contribution is the idea that inventory, posture, rotation and cleanup can all inherit from the request workflow. That is a meaningful operating model for NHI governance because it turns provisioning into the place where policy becomes executable. Practitioners should view this as lifecycle enforcement architecture, not just a provisioning convenience.
Vendor access without lifecycle offboarding is the same failure pattern in different clothing. The same governance gap appears whenever an identity outlives the accountability structure that created it. The Coupang Signing Key Breach is a reminder that creation without a clean revocation path leaves credentials exposed after the original business purpose ends. Identity teams should use provisioning to bind issuance to offboarding from the start.
From our research library:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
- Read next: Ultimate Guide to NHIs
What this signals
Provisioning is becoming the governance choke point for NHI programmes. If teams cannot set ownership and lifecycle policy at creation time, every downstream control has to compensate for a decision that was already made too early. That changes the operating model for IAM, IGA and PAM teams, because issuance now matters as much as review.
Identity programmes should distinguish secret-bearing NHIs from federated trust-based identities. Those are different governance problems even when they support the same workload. One path concentrates risk in vaulting, rotation and leakage, while the other concentrates it in trust scope and offboarding.
NHI lifecycle controls are no longer optional plumbing. 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs. That makes provisioning policy a prerequisite for any serious zero-trust or identity governance programme.
For practitioners
- Define provisioning as a governance gate Require every NHI request to set ownership, credential model, vault destination, rotation policy and deprovisioning rules before the identity is created.
- Separate credentialed and federated paths Route use cases toward federated identities where trust relationships are sufficient, and reserve credential-based provisioning for cases that genuinely need stored secrets.
- Bind lifecycle policy to approval workflow Make the approval step the point where ILM rules are attached so inventory, posture checks and cleanup inherit the same policy from day one.
- Audit for identities created outside policy Review cloud, vault and ticketing workflows for NHIs that were issued before ownership or rotation policy existed, then close those process gaps first.
Key takeaways
- The article argues that NHI risk starts at creation when ownership and lifecycle controls are not bound to provisioning.
- Its central operational theme is that governance, not just automation, must be encoded before an identity is issued.
- For practitioners, the control lesson is to make provisioning the point where policy, ownership and deprovisioning are fixed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article emphasises deprovisioning and ownership from creation through the full NHI lifecycle. |
| NHI-02 — Secret Leakage | The workflow generates and stores credentials inside a controlled vaulting path. | |
| NHI-05 — Overprivileged NHI | The article ties approval-time policy to the access granted at identity creation. | |
| Recommendation — Bind provisioning to deprovisioning so every NHI has an exit path before it is created. Route secret generation and storage through governed vault processes instead of ad hoc handling. Set privilege boundaries during provisioning so access scope matches the approved use case. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about governing entitlements at the moment of identity issuance. |
| Recommendation — Use PR.AA-05 to ensure NHI entitlements are approved and traceable at provisioning time. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential generation, storage and rotation are central to the provisioning flow. |
| Recommendation — Apply IA-5 to manage NHI authenticators from creation through rotation and revocation. | ||
Key terms
- NHI Provisioning: NHI provisioning is the process of creating a non-human identity and attaching the access, ownership and lifecycle rules it needs to operate safely. In strong governance models, provisioning is where secret handling, rotation, deprovisioning and approval are decided before the identity enters production.
- Federated Identity: Federated identity lets one organisation trust an external identity provider so a user can access another service without creating a separate account. It simplifies access, but it also expands the trust relationship that must be monitored. Weak federation settings can turn a single compromise into cross-domain access.
- Citizen Identity Lifecycle Management: The governance of a citizen’s identity across its full lifespan in government systems, from initial establishment through legal changes, agency interactions, and policy-driven termination events. It requires continuity, reconciliation, and auditability across multiple applications and administrations, not just login and registration features.
- Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org