By NHI Mgmt Group Editorial TeamBased on Aembit: “The Story Behind Snowflake’s Push to Rein in Non-Human Identities” (July 2, 2025)

TL;DR: Snowflake’s workload identity experience shows how non-human identities can quietly outnumber employees, with static credentials, manual provisioning, and inconsistent controls creating both operational drag and security exposure, according to Aembit. The lesson is that visibility alone is not enough when machine access has to be automated, policy-based, and auditable at scale.


At a glance

What this is: This analysis shows how Snowflake’s growth exposed the limits of static credentials and manual workload access controls across a large NHI estate.

Why it matters: IAM and security teams should treat workload identity as a lifecycle and governance problem, not just a secrets problem, because scale turns inconsistency into risk.


Context

Snowflake’s experience is a plain example of NHI sprawl: as cloud services, internal applications, and automation expand, the number of machine identities grows faster than the controls built for human users. The core problem is not inventory alone. It is that static credentials and manual provisioning do not scale to environments where access changes constantly.

The article also shows why workload identity belongs in identity governance, not only in secrets management. When service accounts, CI/CD systems, and AI-connected workflows all depend on long-lived credentials, the operational burden shifts to the teams that own infrastructure, while security teams lose consistency, auditability, and control.


Key questions

Q: What breaks when workload access still depends on static secrets?

A: Static secrets create persistent access paths that outlive the workload, which makes compromise easier to exploit and harder to contain. The real failure is governance, because the environment assumes credentials can be tracked, rotated, and retired at the same pace as services. In cloud-native estates, that assumption is often false.

Q: Why do long-lived service account secrets increase breach risk?

A: They extend the window in which a leaked or reused credential remains valid, so a single exposure can become persistent access. Without expiry, rotation discipline, and dependency mapping, the secret itself becomes the control point the attacker needs.

Q: How can organisations tell whether NHI governance is actually working?

A: NHI governance is working when every machine identity has an owner, a purpose, a minimum-necessary entitlement, and evidence of rotation and review. If teams can produce that chain without manual reconstruction, the programme is mature enough to withstand audit pressure. If they cannot, the governance model is still fragmented.

Q: Should teams prioritise workload identity over more secrets management?

A: Yes, when the core problem is reusable credentials rather than storage. Secrets management can hide and organise credentials, but workload identity changes the access model itself by removing the need for persistent secrets in many cases. That is a stronger control when machine access is large-scale and continuous.


Technical breakdown

Why static credentials break at workload scale

Static credentials assume that a machine identity can be issued once and left in place until someone remembers to rotate it. That model fails when applications, pipelines, and services multiply across clouds and teams. Hardcoded secrets, mismanaged service accounts, and reused credentials create the same control problem in different forms: access exists longer than the business need, and ownership becomes unclear. In practice, the result is not just exposure but governance drift, because no single control plane can reliably track where each credential is used.

Practical implication: replace long-lived workload secrets with issuance controls that remove persistent credentials from the operating model.

How policy-based workload IAM changes authentication

Policy-based workload IAM replaces stored secrets with dynamic credential issuance during authentication. The system evaluates policy and environment signals at request time, then issues access only for the current transaction or session. That changes the security model from possession of a static secret to proof of context and policy compliance. It also creates a cleaner audit trail, because the access decision is centralized rather than scattered across vaults, scripts, and cloud-specific mechanisms.

Practical implication: design workload access around authenticated requests and policy checks instead of reusable credentials.

Why visibility tools alone do not solve NHI governance

Visibility tells you what exists, but not how access is governed or whether credentials still need to exist at all. The article shows that governance tools can map the problem, yet they do not issue credentials, reduce manual work, or remove the anti-pattern of keeping secrets in circulation. That distinction matters because NHI governance is lifecycle control, not discovery alone. If the control stack stops at inventory, teams still inherit manual rotation, inconsistent access patterns, and weak offboarding of machine identities.

Practical implication: pair discovery and reporting with lifecycle controls that revoke, replace, or eliminate machine credentials.


NHI Mgmt Group analysis

Static credential sprawl is the failure mode, not just a hygiene issue. Snowflake’s story shows that long-lived machine credentials become a governance liability once the NHI estate expands faster than human oversight. The problem is not merely the presence of secrets, but the fact that those secrets outlive the operational need, circulate across teams, and bypass any consistent identity lifecycle. Practitioners should treat static credential sprawl as a control-plane failure.

Workload identity is now part of the identity governance boundary. When CI/CD pipelines, SaaS integrations, and cloud workloads all depend on machine access, identity governance no longer ends at human users. The article shows why this boundary has moved: auditability, ownership, and access scope must now be managed across non-human identities with the same discipline applied to workforce access. Teams that keep treating workload access as an infrastructure afterthought will continue to accumulate hidden risk.

Policy-based issuance is more durable than vault-centred secrets management. Vaults can centralise storage, but they do not change the underlying assumption that a reusable credential is still the unit of access. Snowflake’s experience indicates that the better abstraction is governed issuance, not safer storage of the same secret. That is where the operational and security benefits align, because removing the persistent secret reduces both attack surface and day-to-day friction.

Automated authentication changes the economics of scale for NHI programmes. The operational burden described in the article is a signal that manual provisioning does not merely slow teams down, it makes control consistency unachievable. Once hundreds of services and integrations are in play, every exception becomes a lasting risk multiplier. The practitioner takeaway is straightforward: scale requires control models that can issue, authenticate, and audit machine access without human-driven churn.

Identity convergence is becoming a practical requirement, not a future idea. The article links workforce lessons, workload access, and infrastructure operations into one governance problem. That convergence matters because the same programme that tightened human identity controls can inform NHI governance, but only if the team stops assuming the two domains can be managed with separate operating logic. Security leaders should plan for converged identity governance across human and non-human estates.

From our research library:

What this signals

Ephemeral access beats secret stewardship when the estate is already large. Once workload identity spans hundreds of applications and integrations, the governance problem shifts from keeping secrets safe to eliminating the need for those secrets altogether. That is why static credential reduction has become a practical identity programme priority, not a niche optimisation.

Identity convergence is the real programme signal. The same organisation that hardened workforce identity now has to apply a comparable lifecycle model to non-human identities, or risk creating two separate governance standards. Teams that treat human and machine access differently at the operating-model level will struggle to sustain auditability across both.


For practitioners

  • Audit long-lived machine credentials Identify service accounts, application secrets, and CI/CD credentials that remain valid beyond their business need, then rank them by reuse, blast radius, and ownership clarity.
  • Replace static access with policy-based issuance Move the highest-risk workload connections to request-time credential issuance so access is based on policy and current context rather than stored secrets.
  • Map workload identity ownership Assign explicit owners for every non-human identity used by applications, pipelines, and integrations so offboarding and rotation are accountable, not ad hoc.
  • Extend audit logging to machine access Make every workload authentication event centrally visible so teams can trace which identities requested access, when credentials were issued, and which environments consumed them.

Key takeaways

  • Snowflake’s experience shows that NHI sprawl becomes a governance problem when static credentials, manual provisioning, and inconsistent ownership accumulate across workloads.
  • The scale issue is not theoretical, because modern enterprises often have 25x to 50x more non-human identities than human identities.
  • The practical answer is to reduce reliance on persistent secrets and move workload access toward governed, policy-based issuance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageStatic and hardcoded workload credentials are the central exposure described in the article.
NHI-07 — Long-Lived SecretsThe article argues that long-lived credentials no longer scale across modern NHI estates.
NHI-05 — Overprivileged NHIMismanaged service accounts and inconsistent controls increase the chance of excess access.
Recommendation — Eliminate exposed workload secrets and rotate or revoke any credential that can be hardcoded or reused. Replace persistent machine secrets with short-lived, policy-issued credentials wherever possible. Review machine identity scopes and remove permissions that exceed the workload's current function.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential lifecycle and rotation are directly implicated by the workload access model in the article.
Recommendation — Apply authenticator management controls to reduce persistent workload credential exposure.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe piece focuses on governing who or what can access Snowflake services at scale.
Recommendation — Use entitlement governance to validate workload access scope and reduce standing permissions.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Workload Identity: The identity assigned to a software workload, such as a containerised application, serverless function, or microservice, enabling it to authenticate to other services without storing static credentials.
  • Static Credential: A static credential is a long-lived secret such as an API key, password, token, or certificate that exists outside the moment of use. It creates persistent attack surface because it can be copied, stored, reused, and exposed across code, pipelines, configuration files, and third-party environments.
  • Policy-Based Access: Policy-based access grants or denies access by evaluating rules about context, workload state, and intended action at the moment of request. For AI systems, this is more useful than static roles alone because the same workload may need different privileges across different tasks and environments.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org