By NHI Mgmt Group Editorial TeamDomain: Best PracticesSource: Fischer IdentityPublished May 28, 2026

TL;DR: Accounts, roles, and credentials are only the mechanics of identity, while the real governance unit is the relationship that justifies access across employees, contractors, vendors, service accounts, and AI agents, according to Fischer Identity. That shift makes ownership, lifecycle change, and review context central to IAM, not optional metadata.


At a glance

What this is: This is a relationship-aware identity argument: the article says identity governance should start with the business relationship behind access, not the account itself.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes all fail in similar ways when they manage entitlements without explicit ownership, lifecycle, and context.

By the numbers:

👉 Read Fischer Identity’s blog post on relationship-aware identity governance


Context

Identity programmes often treat accounts as the control point, but accounts only show access mechanics. The primary keyword here is relationship-aware identity, because the governance question is not just who has a login, but why the identity exists, who owns it, how long it should last, and what happens when the relationship changes.

That distinction matters across human IAM, NHI governance, and AI agent oversight. The article’s core claim is that lifecycle, ownership, sponsorship, and policy context should be modelled directly, rather than inferred from groups or roles alone. Fischer Identity frames this as moving from account administration to relationship governance.


Key questions

Q: How should organisations govern identity when one person moves through multiple relationship states?

A: They should govern access from the current relationship state, not from a single static identity label. That means defining authoritative sources for each state, mapping entitlement rules to those states, and revoking or changing access when the relationship changes. The key is to make relationship transitions machine-readable so governance can follow them consistently.

Q: Why do accounts alone fail as a governance model?

A: Accounts show that access exists, but they do not explain why it exists, who owns it, or when it should end. Without relationship context, access reviews become checklist exercises and offboarding misses entitlements that still look technically valid but no longer have a business justification.

Q: What do security teams get wrong about identity lifecycle management?

A: They often treat lifecycle management as an onboarding task instead of an ongoing access discipline. Access must change when roles change, applications change, or identities no longer need privilege. Without that continuous adjustment, privilege creep, orphaned accounts, and audit findings become inevitable.

Q: How can security teams make ownership enforceable in IAM?

A: They should require every identity relationship to have a named owner or sponsor before access is granted, and they should link that owner to review, renewal, and retirement workflows. If ownership is missing, the access should be treated as unresolved governance risk.


Technical breakdown

Why account-centric identity models miss governance context

An account is an access container, not the reason access exists. In relationship-aware identity, the governing unit is the business relationship that created or justifies the account, whether that is employment, contracting, vendor support, workload operation, or delegated AI activity. Without that context, access reviews become mechanical and offboarding becomes incomplete because the programme cannot tell which permissions belong to which relationship. The result is orphaned entitlements, ambiguous ownership, and weak accountability across IAM, IGA, PAM, and NHI estates.

Practical implication: Model the relationship as a first-class attribute so review, expiration, and ownership decisions can follow the business context.

How overlapping identities change lifecycle control

The article highlights a practical reality: one person or system can hold multiple active relationships at once. That creates a lifecycle problem because ending one relationship should not automatically remove every entitlement if another valid relationship still exists. The same pattern applies to service accounts and AI agents, which may be tied to more than one application, sponsor, or process. Relationship-aware governance therefore has to distinguish identity state from relationship state and decide which access path each relationship controls.

Practical implication: Separate lifecycle decisions by relationship type so offboarding and renewal do not over-revoke or under-revoke access.

Why ownership is the real control boundary

Ownership turns identity from an unmanaged object into an accountable governance record. The article is explicit that a service account without an owner, a contractor without a sponsor, or an AI agent without a business owner is not just incomplete data, but governance failure. That matters because ownership determines who certifies access, who approves extension, and who is responsible when the relationship changes. In practice, ownership is the control that prevents identity sprawl from becoming permanent risk.

Practical implication: Require an accountable owner or sponsor for every non-human and human relationship before access is granted.


NHI Mgmt Group analysis

Relationship-aware identity is the right abstraction for modern governance. The article correctly rejects the idea that account, role, or credential data is sufficient to explain access. Identity programmes need the relationship that created the entitlement, because that is what determines who owns it, how long it should last, and what review means in context. For practitioners, that shifts identity governance from record management to lifecycle accountability.

Ownership is the control that stops identity drift from becoming orphaned access. A service account, contractor, or AI agent with no accountable owner cannot be governed cleanly because no one can validate scope, renewal, or retirement. The article’s position is especially relevant for NHI estates, where credentials often outlive the operational relationship that justified them. Practitioners should treat ownership as an enforceable governance field, not an administrative label.

Lifecycle control only works when the relationship is the trigger, not the account. The article shows why joiner-mover-leaver logic is incomplete when programmes only look for a status change in a directory or HR system. Relationship changes can be narrower than employment status, broader than a single application, and overlapping across multiple access paths. The implication is that review, renewal, expiration, and revocation need to follow relationship state changes, not just account events.

Continuous identity control is the practical outcome of relationship-aware governance. The article’s strongest contribution is the idea that identity should stay aligned to current relationship state rather than past provisioning events. That aligns with modern IAM, IGA, and NHI governance expectations, where access must remain explainable over time. Practitioners should use this as a design principle for governance models that must survive hybrid work, third-party access, workload identity, and AI-enabled processes.

Named concept: relationship-aware identity. This is a governance model that treats the business relationship as the source of meaning for every identity, not just the account. It changes how access is owned, reviewed, renewed, and retired across human, non-human, and AI-enabled identities. The practitioner implication is simple: if the relationship is unclear, the access is not governable.

From our research:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • A separate NHI Mgmt Group finding shows that 97% of NHIs carry excessive privileges, which broadens the attack surface even when identities are partially known.
  • For a deeper lifecycle lens, see NHI Lifecycle Management Guide for the provisioning, rotation, and offboarding controls that relationship-aware governance depends on.

What this signals

Relationship-aware identity is becoming the missing control layer in modern IAM. Programmes that still treat access as an account problem will continue to struggle with contractor expiry, vendor sponsorship, workload ownership, and AI agent accountability. The practical shift is toward governance models that can follow the relationship as it changes, not just the record that first created it.

With only 5.7% of organisations reporting full visibility into their service accounts, the governance challenge is not theoretical, and the visibility gap is a strong reason to pair account inventory with relationship ownership. See the Ultimate Guide to NHIs and the NHI Lifecycle Management Guide for the broader control pattern. Identity teams should expect lifecycle evidence, sponsorship, and review context to become more important in audits than static entitlement lists.

The next maturity step is not more provisioning automation. It is proving that access remains appropriate as relationships overlap, expire, and transfer across human, machine, and delegated use cases.


For practitioners

  • Define relationship type as a governance field Add relationship type, source of authority, owner, sponsor, start date, and end date to identity records so access can be justified by context rather than by group membership alone.
  • Tie every non-human identity to an accountable owner Require a named owner for service accounts, integrations, and AI agents before access is approved, and block orphaned identities from renewal or exception workflows.
  • Split lifecycle decisions by relationship state Build offboarding and recertification logic so one relationship ending does not over-revoke a second valid relationship, especially for vendors, contractors, and dual-role users.
  • Treat access reviews as relationship reviews Ask reviewers who established the relationship, why it still exists, what business outcome it supports, and whether the entitlement should change if the relationship changes.

Key takeaways

  • The article’s central message is that identity governance should be built around the relationship that justifies access, not the account that holds it.
  • Service accounts, contractors, and AI agents all become harder to govern when ownership and lifecycle state are not explicit control inputs.
  • Practitioners should redesign reviews and offboarding so they follow relationship change, because that is where orphaned access starts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Relationship-aware governance addresses ownership and lifecycle gaps across NHIs.
NIST CSF 2.0PR.AC-4Relationship-based access review supports least privilege and entitlement governance.
NIST SP 800-53 Rev 5IA-5Credential and authenticator management underpins lifecycle control for service accounts.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous revalidation as identity context changes.

Track authenticator ownership and retirement so credentials do not outlive their business purpose.


Key terms

  • Relationship-aware identity: A governance model that treats the business relationship behind access as the primary control object. Instead of starting with the account, it asks why the identity exists, who owns the relationship, how long it should last, and what should happen when the relationship changes.
  • Identity relationships: Identity relationships are the connections that define which accounts, tokens, agents, systems, and permissions interact with each other. They matter because risk often emerges from the path between identities, not from any single event seen in isolation.
  • Lifecycle State Management: Lifecycle state management is the process of moving an identity through defined statuses such as approved, active, suspended, and retired. For AI agents, the state determines whether the agent can act, and every transition should be tracked so access and accountability stay aligned over time.
  • Account Ownership: The assignment of a responsible person or team to an identity or credential. Ownership makes review, escalation, and remediation possible because someone is accountable for why the access exists, whether it is still needed, and what happens when risk is found.

What's in the full article

Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:

  • Examples of how relationship-aware identity can be modelled across employees, contractors, vendors, students, service accounts, and AI agents
  • A practical list of governance fields to configure, including owner, sponsor, lifecycle state, start and end dates, and deprovisioning actions
  • How continuous identity control differs from point-in-time access administration in complex enterprise environments
  • The article’s own reasoning on why relationship context improves reviews, renewal decisions, and accountability

👉 The full Fischer Identity post expands the relationship model, lifecycle examples, and governance implications in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org