By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Oasis Security Emerges from Stealth” (May 1, 2026)

TL;DR: Non-human identities now outnumber humans by 50 times, and rotation, revocation, and lifecycle control require full contextual visibility, according to Oasis Security. The core issue is not just secret sprawl, but the governance gap created when identity lifecycles outgrow human-centric access models.


At a glance

What this is: This is a vendor blog announcing Oasis Security’s public launch and arguing that NHI lifecycle management is the missing control for service accounts, API keys, secrets, and tokens.

Why it matters: It matters because IAM teams cannot govern non-human identity risk with human-centric lifecycle assumptions when credentials outnumber people and persist across infrastructure without clear ownership.


Context

Oasis Security’s launch post argues that non-human identities now form a distinct security perimeter, not a side effect of application development. In practice, service accounts, API keys, secrets, and tokens behave as durable access objects that need ownership, rotation, revocation, and offboarding.

The governance problem is that most identity programmes still organise around human joiner-mover-leaver logic, while machine credentials can be created, copied, reused, and forgotten across pipelines and environments. Oasis Security’s central claim is that lifecycle control, not just discovery, is what closes that gap.


Key questions

Q: What breaks when non-human identities are managed with human joiner-mover-leaver processes?

A: Human lifecycle models assume a person has a start date, role changes, and an offboarding event. Non-human identities do not follow that pattern, so service accounts and secrets can persist after the business purpose changes. The result is unmanaged standing access, unclear ownership, and delayed revocation across infrastructure.

Q: Why do non-human identities increase data leakage risk?

A: Non-human identities increase leakage risk because they often have broad machine-to-machine reach, long-lived or reused credentials, and limited human review. Once access is granted, those identities can move data through pipelines, integrations, and AI services faster than traditional governance processes can inspect.

Q: When should security teams remove or rotate NHI credentials?

A: Remove or rotate credentials when the workflow changes, the owner changes, the identity is no longer needed, or the access cannot be justified. For high-risk NHIs, periodic rotation should be routine rather than exceptional, because stale credentials are a common path to compromise.

Q: When does secrets management become an NHI governance problem?

A: Secrets management becomes an NHI governance problem when a credential can be used by a service, bot, or workload to obtain persistent access. At that point, the key question is not where the secret is stored but who owns it, when it expires, how it is rotated, and how it is revoked. That is lifecycle governance, not storage hygiene.


How it works in practice

Why NHI lifecycle management is different from human IAM

Non-human identities are not people with sessions, approvals, or predictable employment events. They are credentials and access artefacts attached to workloads, services, integrations, and automations, which means their risk profile is defined by persistence, reach, and reuse rather than login behaviour. Rotation and revocation matter, but only if the organisation can see where an identity exists, what it can reach, and who owns its removal. The lifecycle problem emerges when credential issuance and credential retirement are handled as isolated tasks instead of one governed process.

Practical implication: map NHI ownership and retirement into the same governance model instead of treating rotation as a standalone maintenance task.

Why broad visibility is necessary but not sufficient

Oasis Security’s argument is that visibility must be contextual, not just inventory-based. A list of secrets, service accounts, and tokens tells you what exists, but not whether each identity is still needed, where it is used, or whether its privileges match current business reality. In NHI governance, context includes workload dependency, environmental scope, and the downstream data each identity can touch. Without that context, teams can see the problem and still fail to decide which credentials should be rotated, revoked, or re-scoped first.

Practical implication: enrich NHI inventories with ownership, usage, and access context before making lifecycle decisions.

How overexposure turns NHI lifecycle gaps into breach paths

The article ties NHI growth to a larger attack surface and a higher risk of confidential data exfiltration. That is a lifecycle issue because stale or overbroad credentials tend to survive long after their business purpose has ended, especially when they are embedded in pipelines, shared across systems, or left undocumented. In that environment, compromise is often less about one broken control and more about accumulated access that never got retired. The result is durable exposure rather than a single point failure.

Practical implication: prioritise the identities with broad data reach and uncertain ownership when reducing lifecycle risk.


NHI Mgmt Group analysis

NHI lifecycle, not credential inventory, is the missing governance layer: The article is right to move the discussion beyond discovery. Visibility tells teams what exists, but lifecycle governance determines whether an identity should still exist, who owns it, and when it must be retired. That is the discipline gap exposed by NHI growth, and practitioners should treat lifecycle state as the primary control plane.

Human-centric joiner-mover-leaver models do not translate cleanly to non-human identities: Service accounts, API keys, secrets, and tokens do not follow employment events, so the traditional assumption that access can be managed through user-centric processes breaks down. The practical consequence is that machine identities can persist after their purpose changes, making offboarding a technical and governance problem at the same time.

Complete contextual understanding is the difference between rotation and governance: Rotating credentials without knowing ownership, workload dependency, and access scope only changes the secret, not the exposure model. The article points to a more precise concept: identity lifecycle control debt, where unmanaged persistence accumulates because no one has enough context to safely revoke or re-scope access. Practitioners should treat that debt as an operational risk signal.

Non-human identity growth turns exfiltration risk into an access governance issue: Broader access to sensitive data means the blast radius of one forgotten credential is no longer localised to a single system. The field should stop treating this as just another secrets problem and recognise it as an IAM governance issue for machine identities. That shifts the practitioner question from how to store secrets to how to govern their full existence.

Oasis Security’s exit signals a category shift from secret management to lifecycle management: The important takeaway is not the vendor event itself, but the market signal behind it. NHI governance is maturing from point controls on credentials into a broader lifecycle discipline that spans creation, use, review, rotation, and retirement. Practitioners should expect tooling evaluations to increasingly centre on that end-to-end scope.

What this signals

Identity lifecycle control debt: Machine identities accumulate when teams can create credentials faster than they can prove they still need them. The governance challenge is not just finding secrets, but proving that every persistent identity remains justified across workload, owner, and environment changes.

NHI programmes should now be measured by how quickly they can move from discovery to ownership, revocation, or retirement. That is the point at which secrets management stops being a hygiene exercise and becomes identity governance for machines.


For practitioners

  • Map NHI ownership to lifecycle state Create a governed inventory that links each service account, API key, secret, or token to an owner, purpose, environment, and retirement trigger.
  • Separate rotation from retirement decisions Treat credential rotation as only one step in a broader decision path that also determines whether the identity still has a valid business purpose.
  • Prioritise identities with broad data reach Review the credentials that can touch sensitive data across multiple systems first, because they create the largest blast radius if left in place.
  • Embed offboarding into NHI operations Define explicit revocation and decommissioning steps for machine identities so dormant access does not survive application, pipeline, or vendor changes.

Key takeaways

  • The central risk is not only that non-human identities exist, but that they outlive the business purpose that created them.
  • Oasis Security says non-human identities outnumber human identities by 50 times, which expands the attack surface and the scope of lifecycle governance.
  • Practitioners need ownership, contextual visibility, rotation, revocation, and offboarding in one governed process if they want to reduce machine identity exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centres on retiring service accounts, secrets, and tokens when they are no longer needed.
NHI-07 — Long-Lived SecretsThe post highlights the danger of persistent credentials that outlive their intended lifecycle.
NHI-05 — Overprivileged NHIBroad access to sensitive data is a core risk described in the article.
Recommendation — Build offboarding controls that revoke machine identities when their business purpose ends. Shorten secret lifetimes and track every long-lived credential to an owner and retirement trigger. Reduce privilege scope on machine identities that can reach sensitive data across multiple systems.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential rotation and revocation are central to the lifecycle problem discussed.
Recommendation — Apply authenticator management to rotate, revoke, and retire machine credentials on a governed schedule.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing entitlements for non-human identities.
Recommendation — Review and reauthorise machine entitlements so access matches current need rather than inherited scope.

Key terms

  • Non-Human Identity Lifecycle: The Non-Human Identity Lifecycle is the full sequence of creation, use, control, review, and retirement for identities that are not tied to a person. It covers service accounts, API keys, certificates, tokens, bots, and AI agents, including issuance, rotation, monitoring, revocation, and secure decommissioning across systems and environments.
  • Credential lifecycle debt: The accumulation of secrets and access paths that are created quickly but not retired at the same pace. In practice, it shows up when bootstrap convenience produces credentials that remain valid after the project, team, or use case has changed, creating hidden exposure.
  • NHI Ownership Transfer: NHI ownership transfer is the reassignment of a non-human identity from one employee to another during a change event such as offboarding. It is used when the credential still supports a live business process and cannot simply be revoked. Effective transfer requires context, dependency mapping, and governance approval.
  • Credential Revocation: Credential revocation is the process of disabling a secret, token, or key so it can no longer authenticate or authorize action. It is the operational half of detection, because exposed credentials remain dangerous until they are invalidated and replaced across every dependent system.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org