By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Celebrating the first year of Oasis NHI Security Cloud” (May 1, 2026)

TL;DR: Non-human identities outnumber human identities by 20x on average, with visibility, rotation, ownership, and attestation now treated as core controls rather than optional hygiene, according to Oasis Security’s first-year summary. Traditional human-centric IAM models are too rigid for fragmented cloud identity perimeters and automated workload access.


At a glance

What this is: This is Oasis Security’s first-year summary of why NHI governance needs dedicated controls for discovery, ownership, attestation, rotation, and least privilege.

Why it matters: It matters because IAM teams now have to govern machine identities as a lifecycle problem, not just inventory them as technical objects.

By the numbers:

  • NHIs outnumber human identities by a factor of 20x on average, according to Oasis Security.

Context

Cloud infrastructure and SaaS have fragmented the identity perimeter, so each service increasingly behaves like its own identity provider. That shifts NHI governance away from a single central directory model and toward distributed control across systems, secrets stores, pipelines, and cloud services.

The core problem is not just inventory. NHIs now include service accounts, API keys, access tokens, database users, automation scripts, and cloud service identities that often carry privileged access without the ownership, attestation, and lifecycle governance that IAM teams expect for human accounts.


Key questions

Q: What breaks when non-human identities are left out of governance?

A: When non-human identities are left out, ownership becomes unclear, credentials stay active too long, and audit cannot verify who approved the access or why it still exists. That creates a blind spot for service accounts, bots, and AI agents that often hold powerful permissions but rarely get the same lifecycle scrutiny as people.

Q: Why do unrotated secrets and overprivileged NHIs create so much risk?

A: They combine persistence with excess reach. A long-lived credential stays usable after exposure, while an overprivileged identity gives that credential more places to go once it is abused. The result is a larger blast radius, especially in CI/CD pipelines, SaaS integrations, and cloud services where machine identities often operate without direct human oversight.

Q: How do security teams know if NHI ownership controls are working?

A: Ownership controls are working when every live NHI has a responsible team, a current business purpose, and a clear retirement path. You should see fewer orphaned accounts, faster revocation when systems are decommissioned, and cleaner access reviews. If any live identity cannot be assigned to an accountable owner, the control is failing.

Q: What is the difference between human IAM controls and NHI governance?

A: Human IAM is built around people joining, moving roles, and leaving the organisation. NHI governance is built around credentials, workloads, integrations, and software change. That means machine identities need inventory, ownership, rotation, and offboarding tied to technical events, not just HR events or periodic access reviews.


How it works in practice

Why fragmented identity perimeters create NHI governance drift

When cloud services and SaaS platforms each maintain their own identity boundaries, the control plane for access becomes distributed by design. That matters because non-human identities are often created close to the workload, consumed by automation, and never fully registered in the systems that track human access. The result is governance drift: the identity exists, the permissions work, but the lifecycle is invisible to central IAM processes. In practice, this is why inventory alone is insufficient. Teams need context about ownership, usage, consumers, and entitlements before they can reason about risk.

Practical implication: map where identities are issued and consumed, not just where they are stored.

How overprivilege and unrotated secrets become the real risk

Oasis Security’s summary ties NHI exposure to two familiar failure modes: overprivileged accounts and unrotated secrets. Overprivilege widens the blast radius if an identity is misused, while long-lived credentials increase the chance that a leaked secret remains valid after exposure. Because these identities are often embedded in pipelines, integrations, and cloud tooling, the risk is persistence rather than a single broken login event. Governance has to treat credential lifespan and permission scope as linked controls, not separate hygiene tasks.

Practical implication: review privilege scope and secret lifetime together, especially for pipeline and integration identities.

Why ownership, attestation, and decommissioning are lifecycle controls

The article’s strongest governance point is that NHI control is a lifecycle discipline. Ownership answers who is responsible for the identity, attestation verifies that the identity still needs the access it has, and stale-account decommissioning removes identities that outlive their business purpose. That combination matters because unmanaged NHIs can persist long after the system, team, or integration that created them has changed. Without lifecycle controls, least privilege becomes a policy statement rather than an operational state.

Practical implication: require named ownership and periodic attestation before a machine identity can remain active.


NHI Mgmt Group analysis

Identity perimeter fragmentation is now the governance problem, not a side effect of modern architecture. When every cloud service and SaaS platform behaves like its own identity provider, central IAM loses the clean boundary it was designed around. That shifts the burden from directory-centric administration to distributed governance across NHIs, secrets, and workload access. Practitioners should treat identity perimeter drift as a structural control issue, not an inventory issue.

20x machine-to-human scale changes how access risk must be measured. The article’s 20x figure is not just a volume statistic, it is a signal that human-centric review cadence and approval models no longer map cleanly to non-human estates. At that scale, unmanaged ownership and stale entitlements are not edge cases. The implication is that NHI governance must prioritise automated discovery and continuous context before manual review can be trusted.

Overprivilege and secret persistence are the two controls that matter most here. The article repeatedly points to unrotated secrets and overprivileged accounts as the practical failure modes that expand attack surface. Those are not separate issues in machine identity estates, because the same identity often carries excessive permissions and a long-lived credential. Teams should frame NHI remediation around blast-radius reduction, not just better inventory.

Ownership and attestation are the missing accountability layer for NHIs. A machine identity without an owner is a governance orphan, even if it is technically visible. Attestation keeps that ownership current and forces the business context to stay attached to the identity as systems change. Practitioners should treat attestation as the mechanism that makes lifecycle controls auditable rather than advisory.

NHI lifecycle control is converging with compliance readiness. The article’s references to PCI 4.0, NIST, and SOC 2 show that governance expectations are moving from internal hygiene to externally defensible control evidence. That does not make compliance the goal; it makes lifecycle discipline measurable. Practitioners should align NHI ownership, rotation, and decommissioning evidence with audit requirements now, not after the next assessment cycle.

From our research library:

What this signals

NHI governance now has to start at issuance, not at review. Human-centric IAM assumes access can be certified after the fact, but non-human identities are frequently created inside pipelines and integrations where no one ever sees them as a discrete event. That means the programme question changes from “who approved this?” to “who owns this identity before it reaches production?”

Lifecycle evidence is becoming the control plane for machine identity. Visibility is necessary, but it is not the finish line. Ownership, attestation, and safe decommissioning are what turn an inventory of service accounts, tokens, and secrets into a governable estate.

Developer behaviour is part of the NHI control problem. Only 44% of developers are reported to follow security best practices for secrets management, which shows that the control gap is not purely technical. IAM and security teams need to design governance that accounts for how engineering teams actually create and use secrets, not how policy assumes they do.


For practitioners

  • Map every NHI source system Inventory where machine identities originate, including cloud providers, SaaS platforms, secrets managers, CI/CD tools, and automation scripts, then reconcile those sources against the identities your IAM team can actually see.
  • Separate privilege review from secret review Assess permission scope and credential lifespan together for service accounts, API keys, access tokens, and database users so that overprivilege and long-lived access are remediated as one control problem.
  • Assign explicit ownership for every NHI Require a named business or technical owner for each non-human identity, with attestation evidence that confirms the identity is still needed and still correctly scoped.
  • Build stale-identity decommissioning into lifecycle processes Use verified inactivity, ownership loss, or service retirement as triggers to safely decommission NHIs instead of leaving dormant access in place.
  • Treat compliance evidence as a byproduct of governance Capture rotation, ownership, and attestation records in a form that can support audit reporting without turning compliance into a separate workflow.

Key takeaways

  • Non-human identities have outgrown human-centric IAM assumptions, and fragmented cloud and SaaS environments have made that gap operational.
  • The main failure modes are overprivileged access, unrotated secrets, and identities with no durable owner or attestation trail.
  • The practical response is to govern machine identities as a lifecycle discipline with discovery, ownership, rotation, and safe decommissioning.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centers on highly privileged NHIs that lack effective governance.
NHI-07 — Long-Lived SecretsSecret rotation is a named control outcome in the article.
NHI-01 — Improper OffboardingThe article stresses safe decommissioning of stale NHIs as a core lifecycle control.
Recommendation — Review NHI permissions against NHI-05 and reduce standing access that exceeds workload need. Apply NHI-07 to shorten credential lifetime and remove secrets that remain valid too long. Use NHI-01 to offboard stale non-human identities before they remain active without purpose.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential rotation and management are central to the article's governance model.
Recommendation — Apply IA-5 to govern authenticator lifecycle, rotation, and revocation for machine identities.
MITRE ATT&CKTA0006 — Credential AccessExposed or long-lived machine credentials create the primary threat path discussed.
Recommendation — Map exposed secrets and credential reuse to TA0006 and prioritise them for hunting and removal.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsLeast privilege and entitlement governance are direct themes in the article.
Recommendation — Use PR.AA-05 to audit entitlements and enforce least privilege for NHIs.

Key terms

  • Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials, ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.
  • Identity Perimeter: The identity perimeter is the access boundary defined by who or what is requesting entry, not by where the request comes from. In zero trust, it is the point where authentication, authorization, and risk context decide whether a caller can proceed.
  • Ownership attestation: Ownership attestation is the explicit assignment and verification of accountability for a non-human identity. It tells security teams who is responsible for its use, revocation, and remediation, which is essential when an alert must become an action rather than a dashboard entry.
  • Secrets Rotation: Secrets rotation is the practice of replacing credentials on a schedule or after an event so exposed values stop working quickly. In NHI programmes, rotation must be tied to ownership and automation, otherwise credentials remain valid long after teams believe the risk has been addressed.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org