By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: VezaPublished December 2, 2025

TL;DR: Identity context, least privilege, and access governance are moving into the center of AI-era security operations as ServiceNow’s acquisition of Veza signals, according to Veza; the market is now treating human, non-human, and agentic identities as one control problem, and static access models are no longer enough for modern enterprise risk.


At a glance

What this is: Veza says ServiceNow will acquire it, and frames the deal around identity context, least privilege, and governance for human, non-human, and agentic identities.

Why it matters: For IAM, IGA, PAM, and NHI teams, this matters because identity is being repositioned as an operational control plane for AI workflows, not just an access layer.

👉 Read Veza’s analysis of ServiceNow’s acquisition and identity governance implications


Context

Identity security is shifting from a support function to a control point for how modern enterprises operate. The core issue is no longer only who a person can authenticate as, but how permissions, workload access, service accounts, and emerging AI agents are governed across many systems at once.

That matters because static access models and periodic human-led reviews do not scale to environments where identities proliferate faster than owners can track them. In the NHI context, the governance gap is usually not lack of policy in theory, but lack of usable identity context in practice.

Veza’s announcement uses the language of agentic identities and identity context to argue that access governance must span human, non-human, and agentic identities together. That is a typical direction of travel for enterprises trying to move from inventory-based oversight to operational control.


Key questions

Q: Should organisations merge human IAM and NHI governance after a major acquisition?

A: They should align the operating model, but not collapse the controls into one undifferentiated process. Human authentication, NHI lifecycle control, and agentic access risk have different evidence, ownership, and review rhythms. The right move is a shared identity governance layer with actor-specific policy, not a single review template for every identity type.

Q: Why does identity context matter more when AI agents enter the enterprise?

A: Because agentic systems can scale access decisions, tool use, and data reach much faster than manual governance can track. Without context such as owner, scope, and blast radius, teams cannot tell whether an agent is operating within approved limits or quietly expanding exposure across systems.

Q: What breaks when least privilege is applied only at review time?

A: Least privilege becomes a snapshot rather than a control. In dynamic cloud environments, identities can gain risk, accumulate privilege, or become tied to new findings long before a periodic review occurs. By the time the review happens, the access decision may already be outdated. Continuous evaluation is what keeps the model current.

Q: Who should own AI agent access decisions and lifecycle controls?

A: AI agent access decisions should be owned by the team that deploys and operates the agent, with identity governance and security functions enforcing policy and review. Ownership must be explicit because autonomous behaviour creates accountability gaps if nobody is responsible for the agent's permissions, monitoring, and offboarding.



NHI Mgmt Group analysis

Identity context is becoming the control plane for AI-era access governance. The article points to a real shift: the question is no longer whether an identity exists, but whether its effective privilege, ownership, and blast radius are visible enough to govern. That aligns with OWASP-NHI and zero trust thinking, where access decisions depend on context rather than static assignment. Practitioners should treat context as the operating layer for both NHI and emerging agentic workflows.

Least privilege at machine speed is a governance problem, not a slogan. The article is right to frame machine identities as needing disciplined, measurable restraint rather than after-the-fact review. In practice, that means traditional entitlement review cycles are too slow to catch privilege drift in fast-moving cloud and SaaS estates. The implication is that entitlement evidence must be continuously derived, not manually assembled.

Unified identity governance across human, non-human, and agentic identities is becoming unavoidable. The acquisition reflects a market reality: workflow platforms, identity telemetry, and access governance are converging. That convergence will pressure teams to re-evaluate where identity data lives, who owns access decisions, and which controls must span multiple identity types. Practitioners should assume that siloed human IAM and NHI governance will leave gaps at the seams.

Blast radius, not just access count, is the right metric for modern identity risk. The article emphasizes operational scope, dormant access, ownership, and lateral movement risk. Those are the right signals because raw permission counts say little about actual exposure. The practical conclusion is that identity governance programmes need risk-weighted prioritisation, not blanket certification.

From our research:

  • 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which is exactly the kind of blind spot that turns identity context into a governance requirement.
  • The next step is to pair this market signal with the Ultimate Guide to NHIs so teams can translate acquisition-driven consolidation into lifecycle and access controls.

What this signals

Identity governance is moving toward risk-weighted control planes. As enterprises add AI agents, service accounts, and application identities into the same operational estate, the useful unit of control is no longer the account itself but the scope of access it can exercise. Teams should prepare for programmes that prioritise blast radius, ownership, and dormant privilege rather than counting identities alone.

The practical pressure point is lifecycle evidence. Access reviews, offboarding, and recertification will need to operate across human, non-human, and agentic identities with different review cadences and different proof requirements, which is why resources like the Ultimate Guide to NHIs remain relevant for architecture decisions.

Least privilege at machine speed: if identity is becoming the control plane for workflow automation, teams will need governance that can keep up with system-to-system decisions. The organisations that succeed will be the ones that treat identity telemetry as an operational signal, not just audit evidence.


For practitioners

  • Map identity context to privilege risk Inventory which identities have accountable owners, dormant access, sensitive-data reach, and lateral movement potential. Use that context to prioritise remediation on the identities that can actually expand blast radius.
  • Separate human review from machine-speed control Keep periodic access reviews for governance evidence, but add automated policy enforcement for service accounts, API keys, and agentic workflows that can change faster than review cycles.
  • Classify agent permissions as NHI scope decisions Treat AI agents as non-human identities until the environment proves a higher autonomy model is needed. Tie each agent to an owner, an approved task boundary, and explicit data access limits.
  • Rebuild privilege reporting around blast radius Report who can reach critical records, who can exfiltrate sensitive data, and which permissions have gone unused. That gives IAM, IGA, and PAM teams a common risk language across identity types.

Key takeaways

  • Veza’s acquisition by ServiceNow reflects a broader shift toward treating identity context as a core security control for human, non-human, and agentic identities.
  • The governance problem is not just access volume but blast radius, ownership, dormant privilege, and the speed at which machine identities move.
  • IAM and NHI teams should move toward shared identity governance models with actor-specific controls, continuous evidence, and risk-weighted prioritisation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article is centered on NHI governance, access visibility, and least privilege.
NIST CSF 2.0PR.AC-4Identity and access permissions are the core control theme in the post.
NIST Zero Trust (SP 800-207)Section 2.1The post argues for contextual, continuously evaluated access decisions.
NIST SP 800-53 Rev 5AC-6Least privilege is the central control objective described by the source.

Use OWASP-NHI to structure visibility, ownership, and privilege controls for service accounts and agents.


Key terms

  • Identity context: The entitlement, ownership, and purpose information that explains why an action occurred and whether it was expected. For security operations, identity context turns raw alerts into decisions by showing which human or non-human identity acted and what it was allowed to do.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Least Privilege at Machine Speed: A governance pattern that applies least-privilege discipline to identities that move faster than human review cycles. It requires policy enforcement, visibility, and ownership that keep pace with service accounts, API keys, and AI agents operating continuously across systems.

What's in the full analysis

Veza's full analysis covers the operational detail this post intentionally leaves for the source:

  • The Access Graph model for correlating permissions across SaaS, cloud, data systems, and custom applications
  • Examples of the identity context fields used to assess privilege risk, dormant access, and lateral movement potential
  • How the platform frames least privilege for agentic workflows and machine identities in practice
  • The vendor's explanation of how identity, workflow automation, and access governance are expected to converge

👉 Veza’s full post covers the access graph model, identity context signals, and its view of agentic identity governance

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org