By NHI Mgmt Group Editorial TeamBased on SailPoint: “SailPoint Announces Intent to Acquire Entro to Accelerate and Enhance Agentic Fabric and Secure the Future of AI-Driven Enterprises” (June 15, 2026)

TL;DR: Identity programmes are moving from periodic governance to continuous control over human, machine, and agent access as SailPoint’s intent to acquire Entro combines secrets discovery, NHI scanning, and lineage mapping across more than 1,000 identity types, 1,200 credential types, and 70 enterprise sources, according to SailPoint.


At a glance

What this is: SailPoint's planned acquisition of Entro is a market move to fuse NHI discovery, credential visibility, and governance into one identity security model for AI-driven enterprises.

Why it matters: IAM and NHI teams need to treat machine and agent access as a governed identity layer, because discovery alone does not establish ownership, privilege scope, or operational accountability.

By the numbers:

  • Entro's coverage extends to more than 1,000 NHI or agent types across enterprise environments.
  • The platform discovers over 1,200 credential types, including secrets, keys, tokens, and certificates.
  • The coverage spans 70+ critical enterprise sources, including cloud, developer, CI/CD, and SaaS environments.

Context

SailPoint's planned acquisition of Entro sits at the intersection of NHI governance, secrets discovery, and AI-agent access control. The article's core point is not the transaction itself, but the governance problem it is trying to solve: enterprises now have to account for credentials and machine identities that move across cloud, CI/CD, SaaS, and agent workflows.

That matters because traditional identity programmes were built around slower review cycles and clearer ownership boundaries. Once agents, workloads, and service identities can reach critical data through many credential forms, governance has to connect discovery, privilege scope, lineage, and revocation in the same operating model.


Key questions

Q: What breaks when machine identities have no clear owner?

A: When machine identities have no clear owner, offboarding, remediation, and accountability all fail together. Credentials may still be logged, but no one is responsible for validating purpose, reducing scope, or revoking access when the system changes. That creates governance debt and makes incident response slower and less reliable.

Q: When should organisations prioritise NHI monitoring over more access approvals?

A: Organisations should prioritise NHI monitoring when identities are created frequently, reused across systems, or tied to automation and AI workflows. More approvals do not solve drift if the environment already has unmanaged service accounts and bots. Real-time visibility and revocation reduce risk faster than adding another manual gate.

Q: How do security teams know if NHI governance is actually working?

A: A working NHI programme shows clear ownership, short-lived credentials, frequent revocation, and low numbers of dormant or shared machine accounts. Teams should be able to trace every high-risk nonhuman identity to a business purpose, a runtime policy, and a retirement path. If they cannot, governance is fragmented.

Q: What is the difference between NHI visibility and NHI governance?

A: Visibility shows what identities exist, where they live, and how they behave. Governance adds ownership, policy, remediation, and accountability. A team can have dashboards without control, but it cannot govern identities effectively without a trusted inventory and a way to act on what it finds.


How it works in practice

Why NHI discovery has become an access control problem

NHI discovery is the process of finding machine identities, credentials, and the systems where they are used. In this announcement, the technical value is not simple inventory. It is the ability to identify which tools, APIs, secrets, tokens, and certificates are actually in play across cloud and developer environments. That matters because visibility without context does not tell you whether a credential is active, over-scoped, or tied to a human owner. Once AI agents and workloads can generate or consume credentials at runtime, discovery becomes the front door for governance, not a separate hygiene exercise.

Practical implication: build discovery coverage around live credential usage, not static account lists.

How lineage mapping turns visibility into accountability

Lineage mapping ties a discovered non-human identity back to an owner, permissions, usage history, and blast radius. That is the difference between knowing a secret exists and knowing who is responsible for it, what it can reach, and what should happen if it is abused. In NHI governance, ownership is not administrative decoration. It is the control that makes recertification, remediation, and offboarding possible when identity objects are shared across teams, platforms, and deployment pipelines.

Practical implication: require ownership metadata and blast-radius context before a machine identity is considered governed.

Why real-time detection matters for agent and machine identities

Real-time detection for NHIs watches for behavioural anomalies after a credential or identity has been registered. The article frames this as machine-speed protection because static certification alone cannot contain abuse that unfolds between review cycles. That is especially relevant where privilege is consumed briefly, by automation, or by agent workflows that touch multiple tools in one task. The governance challenge is not just whether access was approved, but whether the identity stayed within its intended operational boundary while active.

Practical implication: pair governance controls with behavioural monitoring on high-risk machine identities.


NHI Mgmt Group analysis

Identity governance is shifting from periodic review to runtime control. The article points to a market where discovery, lineage, and behavioural monitoring are being brought together because static certification cannot keep up with agentic and machine access. That does not mean recertification disappears. It means the control point has moved closer to issuance and active use, where non-human access is actually consumed.

Ownership attribution is now a governance control, not a reporting feature. A discovered NHI without a named human owner, permissions context, and blast-radius mapping is still an unmanaged asset. In practice, this is where many programmes fail: they can find credentials, but they cannot assign accountability fast enough to govern them. The implication is that NHI inventory, access certification, and offboarding must operate as one closed loop.

Blast-radius reduction is becoming the defining metric for NHI maturity. The important question is no longer how many NHIs a platform can see, but how much damage a single credential can do before it is contained. That changes prioritisation for PAM, secrets management, and cloud identity teams alike. Practitioners should measure whether governance changes the reachable scope of each credential, not just whether it was catalogued.

Agentic access forces identity teams to govern operational boundaries, not just accounts. AI agents do not simply add another identity class. They collapse the distance between discovery, tool selection, and action, which means access governance has to understand what the identity can do inside a task, not only what it was assigned at provisioning. The implication is that identity architecture has to follow work execution, not organisational charts.

Runtime visibility becomes the only durable answer when machine identities outnumber human review capacity. The article's direction is consistent with where the market is heading: more automation around non-human discovery, more context around ownership, and more response at machine speed. That validates continuous governance models and makes delayed access review a secondary control rather than the primary one.

From our research library:

What this signals

Ephemeral credential trust debt: the more a programme relies on discovery without ownership, the more unresolved risk accumulates in credentials that remain live after their business purpose changes. That shifts the operating question from whether a secret exists to whether the organisation can still justify its access path.

The practical signal for IAM teams is simple: if a credential can be found but not owned, certified, and retired through the same workflow, it is already outside mature governance. That is where NHI programmes start to fail in real operations, especially across cloud and CI/CD estates.


For practitioners

  • Define the machine-identity ownership model Assign a human owner, business purpose, and remediation path to every discovered secret, token, key, certificate, and service account.
  • Map active credential use to blast radius Track which tools, APIs, and data stores each NHI can reach so over-privilege is measured by reachable scope, not just account count.
  • Merge discovery with offboarding workflows Treat uncovered NHIs as governed only when discovery feeds revocation, rotation, or decommissioning steps for unused or orphaned credentials.
  • Add runtime monitoring for high-risk NHIs Watch for anomalous behaviour in agent and machine identities that can signal scope drift, unusual tool use, or access outside expected boundaries.

Key takeaways

  • The article shows that NHI governance is moving toward continuous control over machine identities, secrets, and agent access rather than periodic review alone.
  • Entro's contribution is framed around discovery, lineage, and detection across more than 1,000 NHI or agent types and 1,200 credential types.
  • The governance lesson is that ownership attribution and blast-radius reduction matter more than inventory size when machine access becomes dynamic.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article centers on discovering secrets, tokens, keys, and certificates tied to NHIs.
NHI-05 — Overprivileged NHIThe acquisition is about reducing excess access and blast radius for machine identities.
NHI-07 — Long-Lived SecretsThe article highlights credential types that persist beyond safe operational windows.
Recommendation — Scan for exposed NHI secrets and revoke any credentials that appear outside governed storage. Review NHI entitlements against actual task scope and remove access that exceeds need. Shorten credential lifetimes and eliminate long-lived secrets where rotation is feasible.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe post is about governing access permissions and entitlements across machine identities.
Recommendation — Apply entitlement review and authorization controls to every non-human identity path.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe source discusses secrets, keys, tokens, and certificates that require lifecycle management.
Recommendation — Manage authenticators for NHIs through rotation, storage, and revocation controls.
MITRE ATT&CKTA0006;TA0040 — Credential Access; ImpactThe article addresses the abuse and impact of exposed machine credentials.
Recommendation — Map exposed NHI credentials to credential-access and impact tactics in detection workflows.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Lineage Tracking: Lineage tracking records how a model or dataset was created, changed, and reused over time. It gives security, compliance, and engineering teams a defensible history of dependencies, which is essential when proving what was tested, approved, and deployed.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org