TL;DR: Unosecur says Oracle Cloud Infrastructure identity security is fundamentally a visibility problem because OCI tenancies mix human users, AI agents and non-human identities that the console exposes one profile at a time. Access review in OCI therefore depends on tenancy-wide inventory, not individual account inspection, if teams want to reduce over-permissioned access to least privilege.
Editorial analysis by NHI Mgmt Group, based on content published by Unosecur: “Oracle Cloud Infrastructure identity security: what is inside your OCI tenancy and how to secure it”.
At a glance
What this is: This is a practitioner analysis of OCI identity visibility that argues the console is insufficient for access review because it only shows one profile at a time.
Why it matters: It matters because IAM teams need a tenancy-wide view of users, credentials and AI agents to find over-permissioned access, unused privileges and offboarding gaps.
👉 Read Unosecur's analysis of Oracle Cloud Infrastructure identity security and tenancy visibility
Context
OCI identity governance starts with a visibility gap, not a policy gap. A tenancy can contain human users, AI agents and non-human identities such as API keys, auth tokens and customer secret keys, but the native console is built to inspect one object at a time rather than the whole estate.
That creates a basic IAM problem across NHI, AI agent and human identity programmes: access review cannot reliably work when the reviewer cannot see every credential, policy and entitlement together. In that environment, least privilege is easy to state and hard to verify.
The article is a product-led analysis of how tenancy inventory changes the shape of OCI identity security. The underlying issue is typical of multi-cloud operations, where identity sprawl grows faster than manual review can keep up.
Key questions
Q: Why does OCI console visibility break down for access reviews?
A: Because the console is designed to show one identity, key or policy at a time, while access review requires a complete population view. Without a tenancy-wide inventory, teams cannot reliably identify over-permissioned users, unused credentials or policies that grant more access than intended.
Q: When should teams prioritise tenancy-wide inventory over manual review?
A: Whenever the environment contains more than a handful of users, credentials or policies. Manual inspection becomes unreliable once access can change faster than the reviewer can traverse the list, so inventory must come first and review must follow.
Q: What breaks when non-human identities are not governed like human accounts?
A: Service accounts, API keys, tokens, and AI agents can retain access long after the original task ends because they do not naturally pass through joiner-mover-leaver processes. That creates hidden privilege accumulation, weak ownership, and poor revocation discipline. The result is broader attack surface and slower response when access needs to be removed.
Q: How should teams govern AI agents inside OCI?
A: Treat them as software identities with scoped access, explicit ownership and a revocation path. If an agent can touch cloud resources, it belongs in the identity inventory and should be reviewed with the same discipline as other non-human credentials.
Technical breakdown
Why OCI consoles fail as access review tools
OCI’s console is optimised for administration, not governance. It shows a single user, group, key or token clearly, but access review requires the inverse view: every identity, every credential and every policy at once. Without that aggregate picture, risky combinations like admin privileges without MFA or stale credentials hidden in long lists are easy to miss. The technical limitation is not data absence, but presentation and workflow design. The console can answer individual questions, but it cannot produce a reliable population-level entitlement review across a live tenancy.
Practical implication: build a tenancy-wide identity inventory outside the console before attempting any review or recertification cycle.
Why non-human identities expand faster than human governance
Non-human identities in OCI include API keys, auth tokens, customer secret keys, OAuth client credentials and OCI apps. These credentials authenticate without a person present, yet they are often created ad hoc by engineers and then forgotten because they do not follow human joiner-mover-leaver patterns. That means the identity layer grows invisibly while the governance layer still assumes a person can be offboarded, challenged or reviewed. In practice, the review unit shifts from the user to the credential and the policy that authorises it.
Practical implication: treat every NHI credential as a governed identity object with explicit ownership, lifecycle and revocation handling.
How AI agents change the OCI identity inventory
AI agents inside a tenancy sit between human and machine identity models. They are not people, but they can hold access, consume privileges and act repeatedly inside the environment. That makes them part of the access surface that IAM and NHI teams need to inventory alongside keys and tokens. The control question is no longer only who has access, but which software actors can exercise that access and under what scope. For OCI, that means identity inventory must include agent context, privilege scope and the resources those agents can touch.
Practical implication: classify AI agents as inventoryable identities and review their access paths with the same rigor used for other non-human credentials.
Breaches seen in the wild
- OneLogin API flaw (CVE-2025-59363): A OneLogin API flaw exposed OIDC client secrets to anyone with an API key, including vendors (CVE-2025-59363); fixed with no customer impact.
- iOS apps leaking hard-coded secrets: Cybernews found 71% of 156,080 iOS apps leak hard-coded secrets, with open cloud storage and Firebase databases exposing user data.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Tenancy-wide visibility is the control boundary, not the console screen. OCI identity governance fails when teams rely on per-object inspection to make population-level access decisions. The console can expose details, but it cannot substitute for an estate view that joins users, credentials, policies and workload access into one governance picture. Practitioners should treat incomplete visibility as a structural control gap, not an operational nuisance.
Non-human identity sprawl is the hidden driver of OCI access risk. API keys, auth tokens, customer secret keys and OAuth client credentials accumulate because they are easy to create and hard to see. That is not a lifecycle edge case, it is the normal operating condition of cloud identity drift. The implication is that NHI governance in OCI has to start from inventory completeness, not from periodic cleanup.
AI agents turn identity review into a mixed-actor governance problem. When software agents hold access inside OCI, the programme is no longer reviewing only human entitlements or static machine credentials. The access review question becomes how to govern software actors whose permissions may be created and exercised faster than human review cycles can observe. Teams should treat agent inventory as part of identity governance, not as an adjacent security concern.
Least privilege in OCI is only real when unused access is removed continuously. Standing privilege between audits is still standing privilege, even if the tenancy looks controlled on paper. The named concept here is identity blast radius: the amount of cloud resource exposure a single account or credential can reach. Practitioners reduce that blast radius only when visibility, review and revocation are all tenancy-wide.
Read-only integration is a governance enabler, not a governance outcome. A read-only connector can surface identities and permissions, but the security result depends on whether teams use that inventory to question privilege scope, revocation lag and offboarding completeness. The lesson for identity programmes is simple: discovery creates the evidence base, but governance begins when that evidence changes access decisions.
From our research library:
- 69% of organisations still authenticate machine identities with long-lived API keys, according to the 2026 State of AI Agent Identity Security Report.
- Read next: Agentic AI Identity Guide
What this signals
Identity blast radius: OCI programmes need a concept for how far a single identity, credential or agent can reach across the tenancy. The practical question is no longer whether access exists, but how much resource exposure each identity can exercise before review catches up.
Multi-cloud governance only works when the same inventory logic is applied to human users, non-human credentials and AI agents. If OCI remains a separate review island, the rest of the estate inherits the blind spot.
Teams should expect access review to move upstream from recertification to issuance time. That shift matters because the review unit is no longer just the user, but the credential, policy and software actor that can exercise it.
For practitioners
- Inventory every OCI credential type Include users, API keys, auth tokens, customer secret keys, OAuth client credentials and OCI apps in a single governed list so that no identity class is omitted from review.
- Review policies across the full tenancy Look for grants that were written to unblock work and never revisited, then recertify them against the resources they can actually touch.
- Track AI agents as first-class identities Record each agent’s access context, owning team and least-privilege target so software actors are reviewed alongside human and machine credentials.
- Revoke unused privileges on a fixed cadence Remove entitlements that have not been exercised and delete stale API keys immediately when their purpose ends, because unused access is the easiest access to remove.
- Separate discovery from approval Use the inventory to identify outliers, then route only the highest-risk accounts and permissions into formal access review and remediation workflows.
Key takeaways
- OCI identity risk is driven by incomplete visibility across users, non-human credentials and AI agents, not by a lack of isolated account data.
- The core operational evidence is tenancy-wide sprawl: keys, tokens, client credentials and policies accumulate faster than manual console review can reliably assess them.
- Practitioners should centralise inventory, narrow standing access and treat AI agents as governed identities rather than side effects of cloud automation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | OCI tenancies in the article contain credentials and agents with more access than needed. |
| NHI-01 — Improper Offboarding | The article notes that NHI credentials are not naturally offboarded like people are. | |
| Recommendation — Review OCI non-human identities for overprivileged access and reduce each credential to least privilege. Put OCI API keys and tokens on an explicit offboarding path with ownership and revocation. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article focuses on identifying and correcting excess permissions across a tenancy. |
| Recommendation — Map OCI entitlements to PR.AA-05 and remove permissions that exceed the approved access model. | ||
| CIS Controls v8 | CIS-5 — Account Management | OCI account and credential inventory is central to the article's governance problem. |
| Recommendation — Maintain a complete OCI account and credential inventory under CIS-5 and review it continuously. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The article is about cloud tenancy identity inventory and access governance. |
| Recommendation — Use the IAM domain to inventory cloud identities, keys and policies across the tenancy. | ||
Key terms
- Tenancy-Wide Identity Inventory: A complete, governed list of every identity object in a cloud tenancy, including users, credentials, policies and software actors. In OCI, this matters because reviewing one profile at a time cannot prove least privilege across the estate.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
What's in the full article
Unosecur's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step OCI connection details, including the five values required from the console
- The exact identity and resource layers the integration inventories inside a tenancy
- How admin status, MFA status and account status are surfaced as review signals
- The first-week workflow for turning inventory into remediation and recurring review
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on October 5, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org