TL;DR: Continuous machine and AI-driven access is pushing security away from vault-and-session privilege models toward per-request authorization, according to Pomerium’s analysis. That shift matters because static PAM assumptions break when software acts continuously and identity decisions must happen at the moment of action.
At a glance
What this is: This article says request-based authorization is overtaking privilege management because machine-operated environments now need continuous, context-aware access decisions.
Why it matters: For IAM, PAM, and NHI teams, the shift matters because access control is moving from credential handling and sessions toward per-request policy enforcement for software identities.
Context
The core problem is simple: older privilege models assume access is checked out, used, and returned in a human-paced cycle. That assumption breaks when AI agents, workloads, and APIs act continuously and independently of a user session.
In this environment, the identity question changes from who has elevated access to whether a non-human identity should be allowed to execute a specific action right now. That makes authorization a control plane issue, not just a permissions issue.
Pomerium frames this as a shift in control architecture rather than a minor PAM adjustment. The article argues that organisations built around credentials and sessions are trying to govern machine behaviour with controls designed for human administrators.
Key questions
Q: What breaks when privilege management is used for continuous machine access?
A: Privilege management breaks when the access pattern is continuous, because vaulting and session brokering assume a bounded human workflow. In machine-operated environments, requests arrive constantly and the security decision needs to happen at action time, not after a credential has been checked out or a session has started.
Q: Why does per-request authorization reduce risk for workloads and agents?
A: Per-request authorization reduces risk because it limits each action to the exact context in which it is requested. That matters for workloads and agents that can change targets, frequency, and execution path quickly, making broad standing access harder to justify and harder to control.
Q: How should security teams reduce standing privilege for non-human identities?
A: Security teams should replace persistent access with time-bound, task-scoped entitlements, then automate revocation when the task ends. The key is to govern service accounts, tokens, and agents as operational identities, not as permanent administrators. Review the highest-risk workflows first, especially production access and cross-cloud automation.
Q: Should organisations still use PAM for machine access?
A: Yes, but selectively. PAM still matters for legacy systems, administrative access, and regulated environments, yet it should not be the primary access layer for continuously operating software. For machines, the stronger model is continuous authorization tied to the specific request and its context.
Technical breakdown
Why credential vaulting struggles with continuous machine requests
Credential vaulting was built around the idea that privileged access is rare and bounded. That works when a human admin checks out a credential, performs a task, and ends the session. It breaks when workloads call APIs continuously and AI agents can generate long chains of actions without human pauses. In that setting, vaulting becomes an awkward intermediary, because the real security question is not where the secret lives but whether the request itself is permitted. The control point moves from possession of a credential to evaluation of each action in context.
Practical implication: treat vaulting as a containment control for legacy access, not the primary decision point for machine execution.
Request-based authorization as the new control plane
Request-based authorization means every action is evaluated at the moment it is attempted, using identity and context rather than standing privilege. This is different from session-based trust, where a successful login or brokered session can implicitly carry broad rights for too long. For agents and workloads, the useful unit of control is the request, because software can change state, intent, and target rapidly. That makes authorization continuous, contextual, and more closely aligned to how modern distributed systems actually operate.
Practical implication: move policy decisions closer to the resource action and enforce them on each request, not just at session start.
Why autonomous software changes the trust model
Autonomous and agentic systems do not simply use privilege more often. They compress decision and execution into the same runtime flow, which means the traditional separation between approval, elevation, and action can disappear. That is why the article argues that software now makes decisions without waiting for approval. Once that happens, the old model of rare elevation no longer describes the threat surface. The governance problem becomes one of continuous verification and bounded action scope, especially for identities that are not human and do not operate on a ticket-based cadence.
Practical implication: redefine trust boundaries around runtime context and allowed action scope rather than around human-style elevation events.
NHI Mgmt Group analysis
Per-request authorization is the structural answer to machine-speed identity behaviour. The article is correct that the old privilege model assumes access is episodic, reviewed, and returned. When workloads and agents act continuously, that assumption stops matching operational reality, so the security control has to move to the moment of action. Practitioners should recognise this as an access-model shift, not just a product category change.
Privilege management becomes a legacy containment layer once software starts acting continuously. Vaulting, session brokering, and just-in-time privilege still have value for administrators and regulated environments, but they do not define the primary security plane for machine-operated infrastructure. The field is moving toward request-level decisioning because that is where intent is expressed and where misuse can be bounded. Security teams should stop treating PAM as the universal answer for non-human access.
The control boundary is migrating from credentials to decisions. The article’s most useful insight is that the security problem is no longer who holds a secret, but who is allowed to act in this exact context. That is a broader governance change for NHI programmes, because it shifts accountability from secret lifecycle management to policy quality, context signals, and runtime enforcement. Teams should design around decision control, not just credential control.
Identity architectures will split into legacy privilege handling and continuous authorisation layers. The future is not better vaulting for every use case. It is a layered model where privilege tools remain relevant for human and legacy workflows while request-based authorisation governs distributed machine activity. That split is already visible in the market language the article cites, and practitioners should prepare for it in access architecture, operating models, and control ownership.
Request granularity is the named concept that matters here. The article points to a shift from session-based access to per-request authorization, and that is the unit of governance that now best matches software behaviour. For NHI programmes, this means the lasting question is whether policy can evaluate each machine action in context, not whether a broad entitlement was granted at all.
What this signals
Per-request authorization is becoming the more accurate governance model for machine-operated environments because access is no longer a discrete session event. When agents, workloads, and APIs behave continuously, the relevant question is whether each action is allowed in context, not whether a credential was issued.
Identity programmes should expect a split architecture: PAM remains useful for legacy and administrative access, while request-level policy increasingly governs software execution. Teams that keep treating these as interchangeable controls will overuse vaults where policy enforcement is the real need.
The practical consequence is that control ownership shifts from secret stewardship to decision quality. That means access governance, policy enforcement, and runtime context evaluation become the measures that matter most for NHI and agentic systems.
For practitioners
- Map privileged workflows to request-level policy decisions Identify where workloads, APIs, and agents currently rely on standing privilege or brokered sessions, then move those paths toward per-request authorization at the resource boundary.
- Keep PAM for legacy and administrative access Preserve vaulting, approval workflows, and session brokering where human administration or regulated legacy systems still need them, but do not treat those controls as the primary layer for machine-operated systems.
- Separate human admin access from software access Assign different control patterns to people, service accounts, workloads, and AI agents so that machine activity is governed by runtime policy rather than human-style elevation assumptions.
- Design policy around action, context, and timing Define what an identity may do right now, in this environment, with this context, instead of asking only whether it possesses a privileged credential or approved session.
Key takeaways
- Continuous machine activity exposes a mismatch between old privilege controls and how software now operates.
- The article argues that the relevant control point has moved from credential possession to request approval in context.
- IAM and PAM teams need to separate legacy privilege handling from the runtime authorization layer used by workloads and agents.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on moving away from standing privilege for machine identities. |
| NHI-07 — Long-Lived Secrets | It directly critiques secret-centric control models that persist across machine activity. | |
| Recommendation — Reduce standing access for machine identities and enforce request-scoped authorization instead. Shorten secret exposure by replacing credential-centric access paths with runtime authorization. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article is about the limits of credential-centric access governance for non-human access. |
| Recommendation — Manage authenticators as supporting controls and shift primary enforcement to authorization decisions. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Per-request authorization maps directly to permissions and entitlement control. |
| Recommendation — Apply PR.AA-05 to evaluate each machine action against current permissions and context. | ||
| NIST Zero Trust (SP 800-207) | Principle of continuous verification — Continuous verification | The article argues that trust must be re-evaluated at the moment of each request. |
| Recommendation — Continuously verify identity and context before allowing each machine action. | ||
Key terms
- Per-Request Authorization: Per-request authorization means every action is checked individually instead of trusting a session once and assuming all later activity is safe. This matters for agents because the request that causes damage may be generated after the initial interaction has already been approved. It is a stronger fit for dynamic, tool-using identities.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Intent-Based Access Control: An access control model that evaluates not just what an agent is requesting, but the inferred intent and context behind the request, granting or denying access based on whether the action aligns with the agent's declared purpose.
- Machine Operated Environment: An infrastructure or application environment where software identities, workloads, APIs, or agents perform actions continuously with limited or no human intervention. Governance in these environments must account for runtime context, rapid decision cycles, and non-human execution patterns.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org