By NHI Mgmt Group Editorial TeamBased on Oasis Security: “How to manage the NHIs exposed to an offboarded employee?” (May 1, 2026)

TL;DR: Employee offboarding often stops at human accounts while exposed service accounts, API keys, and secrets remain active, leaving lateral-movement paths open, according to Oasis Security. The real control gap is that human leaver processes are not enough when non-human identities outlive the employee who saw them.


At a glance

What this is: This is a practitioner guide on why employee offboarding must include non-human identities, with the key finding that exposed NHIs and secrets are often left active when human accounts are removed.

Why it matters: It matters because IAM and IGA teams can complete a clean human leaver process while leaving service accounts and secrets available for misuse, which means the real offboarding control boundary has not been closed.


Context

Offboarding does not end when a human account is disabled. In environments where employees can see, create, or share service accounts, API keys, and secrets, the real governance gap is that those non-human identities are not owned by the leaver process.

That gap matters in cloud-heavy environments because NHIs support services, applications, and automation, so they cannot be treated like a standard user account. A mover or leaver workflow that only reviews HR records and application entitlements misses the credential estate most likely to remain usable after the employee exits.


Key questions

Q: What breaks when human offboarding is used as the only control for NHIs?

A: The organisation keeps service credentials alive after the person who knew them is gone. That creates an exposure gap where access can continue, lateral movement can begin, and ownership becomes unclear. Human deprovisioning is necessary, but it does not retire machine identity risk by itself.

Q: Why do exposed non-human identities remain risky after an employee leaves?

A: They remain risky because NHIs are tied to systems and processes, not to the employee who handled them. If those credentials are still valid, a former employee or another actor can use them to access resources, bypass normal human offboarding, and potentially move laterally.

Q: How should teams decide between rotation and deactivation during offboarding?

A: Teams should choose based on service dependency. If an NHI supports an active workload, rotate or reassign it in a controlled way; if it is no longer needed, deactivate it. The decision should be driven by operational impact, not by whether the credential was exposed by a person.

Q: What signals show that mover-leaver controls are missing NHI exposure?

A: Common signals include offboarding checklists that stop at human accounts, service accounts that outlive role changes, and secrets that remain valid after a departure. When those conditions appear together, the organisation is managing people cleanly but not the credentials they influenced.


Technical breakdown

Why human leaver workflows miss non-human identities

Human offboarding workflows are built around identities that can be disabled, reassigned, or deleted without collateral impact. NHIs work differently because they are bound to services and workloads, not to a person, and a service account may still be required for production operations after the employee who exposed it has left. That creates a governance blind spot where HR-triggered deprovisioning removes the person, but not the machine credential surface attached to their work. Practical implication: offboarding logic has to inventory and govern exposed NHIs separately from user accounts.

Practical implication: Map offboarding triggers to the NHI inventory, not just the user directory, before any deactivation step.

Why deactivating exposed credentials is not always safe

The article’s AWS example shows the core operational tension: simply disabling an NHI can break services, but leaving it untouched preserves access that a former employee could exploit. That is why the control problem is not identical to human IAM revocation. The right unit of governance is the credential and its dependency chain, including where the secret is used and what service depends on it. Practical implication: offboarding must distinguish between revocation, reassignment, and rotation for each exposed NHI instead of using one blanket response.

Practical implication: Classify each exposed NHI by service dependency before deciding whether to rotate, reassign, or retire it.

How credential rotation closes the exposure window

Rotation reduces the period in which an exposed secret remains useful, but only if the organisation can identify which secrets were actually reachable by the departing employee. In practice, that means correlating human identity exposure with the underlying secrets, service accounts, and scripts those people could see or handle. Without that correlation, rotation becomes broad, slow, and difficult to prioritise. Practical implication: identity-aware secret rotation works best when exposure detection and dependency mapping happen before remediation starts.

Practical implication: Use exposure-aware rotation to target only the NHIs linked to the offboarded employee, then confirm downstream services remain intact.


Threat narrative

Attacker objective: Gain continued access to cloud resources and move laterally using non-human identities that outlive the employee's departure.

  1. Entry occurs when an offboarded employee still knows or can reach a service account or secret that was exposed during their role.
  2. Credential access persists because the NHI remains active after human offboarding, giving the former employee or another actor a usable path back into cloud resources.
  3. Escalation happens when the exposed credential is used to access systems that the employee no longer should be able to reach, including cloud accounts and associated resources.
  4. Impact is unauthorised access and lateral movement inside the organisation through credentials that should have been removed, rotated, or reassigned during offboarding.
  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Human leaver processes do not govern the credential estate that actually remains dangerous. The article shows that HR offboarding and service-desk deprovisioning can finish cleanly while NHIs, keys, and secrets stay active. That is not a gap in user lifecycle management alone; it is a lifecycle mismatch between human processes and machine credentials. The practitioner conclusion is that offboarding governance must include the identities the employee could expose, not only the identity the employee owned.

Offboarding exposed NHIs is a lifecycle problem, not a deactivation problem. NHIs tied to services and automation cannot be treated like human accounts because they are operational dependencies, not personal entitlements. The article’s AWS example demonstrates why blanket shutdown is unsafe, yet inaction is also unsafe. The implication is that organisations need governed decision paths for rotation, reassignment, and retirement based on service dependency.

Exposed-secret correlation is the named concept this article makes unavoidable. The control failure is not merely that secrets exist, but that the organisation cannot reliably correlate a departing human with the NHIs, keys, and scripts they exposed. That breaks mover-leaver governance at the point where the human lifecycle crosses into machine identity. Practitioners should treat correlation of human exposure to NHI ownership as a first-class governance object.

Identity-aware offboarding shifts the security question from who left to what they left behind. The article makes clear that the real risk window is created by exposed credentials that persist after employment ends. Human IAM closes one door, but NHI governance determines whether the back door stays open. The conclusion for identity programmes is that offboarding maturity now depends on machine identity visibility as much as HR accuracy.

Rotation is a containment control, but only if the organisation knows which secrets are actually exposed. The article’s focus on prioritising exposed secrets is important because broad rotation without exposure context is slow, noisy, and operationally risky. A targeted response preserves service continuity while shrinking the abuse window. Practitioners should therefore anchor offboarding remediation in exposure discovery, not in generic credential hygiene.

What this signals

Exposed-secret correlation: Offboarding programmes need a control layer that ties the departing person to the NHIs, keys, and scripts they could reach. Without that correlation, the leaver workflow can complete while machine credentials remain usable.

Human IAM and NHI governance are converging at the offboarding boundary. The practical shift is to treat departure events as a trigger for identity inventory, secret rotation, and dependency validation, not just account disablement.


For practitioners

  • Build an exposed-NHI offboarding inventory Map every service account, API key, automated script, and secret the departing or moving employee could access, see, create, or share before any human account is deprovisioned.
  • Separate revoke, rotate, and reassign decisions Treat each exposed NHI as a dependency decision: some credentials can be reassigned, some must be rotated, and some should be retired because reassignment would over-privilege a successor.
  • Correlate human exposure to machine credentials Use contextual correlation between the offboarded identity and the secrets or roles they touched so that remediation targets only the NHIs actually exposed by that person.
  • Prioritise rotation by service criticality and exposure Rotate the secrets linked to the offboarded employee first, starting with the accounts that can reach production cloud resources or sensitive data paths.
  • Verify service continuity after remediation After rotation or reassignment, confirm that dependent applications, automation, and cloud services still authenticate correctly and that no stale credential path remains.

Key takeaways

  • Human offboarding is not complete if service accounts, API keys, and secrets that the employee touched are still active.
  • The article’s core risk is continuity of access, not just account ownership, because NHIs can outlive the employee who exposed them.
  • The control that matters most is exposure-aware inventory and rotation, paired with service-dependency checks before any credential is retired.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centers on exposed NHIs left active after employee offboarding.
NHI-02 — Secret LeakageThe risk arises from secrets and keys remaining reachable after departure.
NHI-05 — Overprivileged NHIReassignment can accidentally concentrate too much access in one account or owner.
Recommendation — Inventory and retire exposed NHIs during offboarding instead of stopping at human account deprovisioning. Rotate or revoke secrets that a departing employee could have seen or shared. Review privilege scope before reassigning an exposed NHI to avoid excessive access.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementOffboarding exposed credentials is fundamentally authenticator lifecycle governance.
Recommendation — Apply authenticator management to revoke, rotate, or replace exposed NHIs immediately.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about closing access paths that persist beyond human offboarding.
Recommendation — Reconcile entitlements and authorizations for NHIs when an employee departs or changes role.
CIS Controls v8CIS-5 — Account ManagementAccount management must include service accounts and secrets, not just human users.
Recommendation — Extend account management to non-human identities exposed during employee offboarding.

Key terms

  • Exposed NHI: A non-human identity that a person could see, create, share, or influence during their role, even if the person does not own it. In offboarding, exposure matters because the credential can remain valid after the human account is removed, creating a post-departure access path.
  • Context-Based Secret Rotation: Context-based secret rotation is the process of changing a credential with awareness of the services, permissions, and dependencies that rely on it. It reduces disruption by matching rotation to actual usage, rather than treating every secret as interchangeable or every environment as identical.
  • Joiner-mover-leaver governance: Joiner-mover-leaver governance is the process of creating, adjusting, and removing access as people or systems change state. For privileged access, it is the difference between temporary authority and lingering entitlement, and it becomes even more critical when access spans multiple infrastructure layers.
  • Credential Dependency: Reliance on one authentication source as the only practical way to access a service. This creates operational risk because the downstream account inherits the availability, policy changes, and failure modes of the external identity provider, rather than remaining independently recoverable.

Deepen your knowledge

NHI governance, identity lifecycle, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org