TL;DR: User activity is creating persistent machine identities through OAuth apps, browser-stored credentials, SaaS tokens, and shadow IT, and Clutch Security says many enterprises underestimate the resulting attack surface. The governance problem is not just visibility, but controlling user-generated NHI sprawl without breaking productivity.
At a glance
What this is: This analysis argues that everyday user actions are spawning persistent NHIs in the user domain, especially through OAuth consent, stored credentials, and unmanaged SaaS access.
Why it matters: IAM and NHI teams need to treat user productivity tooling as an identity creation surface, because these credentials can persist, spread, and evade normal governance.
Context
The user domain is the part of the enterprise where employee productivity tools, SaaS apps, browsers, and collaboration workflows intersect. In that environment, ordinary actions can create non-human identities that outlive the original user task and operate outside traditional access review cycles.
That creates a governance gap for IAM and NHI programmes. Visibility tools may show the activity, but they do not automatically control who approved it, how long it should live, or when it should be revoked once the business need ends.
Key questions
Q: What breaks when machine identities are not included in governance reviews?
A: Human-style reviews miss the identities that actually run automation, so orphaned service accounts, overprivileged APIs, and stale certificates remain active outside ownership and expiry controls. The result is not just weak visibility. It is a control gap where the largest access population can keep operating without recertification or clear accountability.
Q: Why do user-granted OAuth apps increase enterprise risk?
A: Because the app can keep using delegated access after the initial user task is finished. That turns a convenience approval into a durable access path that may reach mailboxes, files, or SaaS data without looking like a classic account takeover.
Q: What signs show that user-domain NHI sprawl is getting out of control?
A: Look for broad OAuth scopes, repeated personal token creation, unmanaged SaaS approvals, and secrets stored in browsers or endpoints. Those signals indicate that access is being minted faster than security teams can govern its lifecycle.
Q: How should teams balance productivity and control for user-generated NHIs?
A: Put friction only at high-risk decision points, such as broad permissions, sensitive data access, and unmanaged app approvals. Routine productivity tools should stay fast, but durable delegated access should not be granted without review and revocation paths.
Technical breakdown
OAuth consent creates persistent delegated access
When a user grants an OAuth application access, the result is not just a login event. It is a delegated authorization relationship that can persist through refresh tokens and broad scopes long after the original productivity use case is forgotten. In practice, the risk comes from consent granted under human intent but enforced by machine-readable credentials that continue acting autonomously within the permission boundary. Because the token is attached to the user’s authorisation decision, not to an explicit lifecycle owner, the access can remain valid even when the app is no longer needed.
Practical implication: govern OAuth app approval and revocation as lifecycle events, not as one-time user permissions.
Browser-stored credentials turn endpoints into distributed vaults
Modern browsers can retain session tokens, API keys, and other secrets on endpoints that security teams do not manage as vaults. That creates a distributed credential surface across laptops, home devices, and shared workstations, where compromise of one endpoint can expose many machine identities at once. The technical issue is not only theft, but unmanaged persistence: secrets stored for convenience often lack the rotation, ownership, and expiry controls applied to centrally managed credentials. This makes the endpoint a credential repository as much as a user workspace.
Practical implication: treat browser-based secret storage as a governance problem and inventory where sensitive tokens can persist.
Shadow IT expands the ungoverned identity perimeter
User-installed SaaS tools and automation apps often create new identities, API connections, and access paths outside central review. These services may request broad permissions to multiple business systems, then operate with the trust of the original user account. The problem is architectural: every unmanaged app becomes another delegated identity relationship that IAM cannot reliably see at provisioning time. Even when the app looks harmless, it can later be used for data access, token reuse, or lateral movement across connected SaaS environments.
Practical implication: bring user-installed SaaS and personal access token usage into discovery and approval workflows before access spreads.
Threat narrative
Attacker objective: The attacker wants legitimate-looking, persistent access to enterprise SaaS and data systems through user-generated machine identities.
- Entry begins when a user grants consent to a malicious or over-permissioned OAuth application, or when malware steals stored browser credentials from an endpoint.
- Credential access follows as refresh tokens, API keys, or session tokens are harvested from browsers or applications and reused outside the original user workflow.
- Escalation occurs when the stolen or overbroad credentials provide access to connected SaaS systems, data stores, or collaboration platforms beyond the initial application scope.
- Impact is long-lived authenticated access, including data exfiltration, unauthorized system access, and persistence that can continue after the user activity that created it has ended.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
User activity is now an identity factory, not just an access consumer. The enterprise user domain continuously creates NHIs through consented apps, saved credentials, and personal automation. That means IAM teams are no longer governing only employees and service accounts, but also the machine identities generated by human productivity patterns. The implication is that identity governance has to extend into the user workflow itself, not stop at the login boundary.
Visibility without lifecycle control is an incomplete control model. Clutch Security is right to frame discovery as necessary, but discovery alone does not solve persistence, ownership, or revocation. OAuth grants and browser-stored secrets behave like unmanaged entitlements once created, which is why they demand recertification logic, revocation paths, and clear accountability. Practitioners should stop treating user-generated NHIs as a visibility issue and treat them as governed assets.
Hidden NHI sprawl is the user-domain version of privilege creep. The difference is that the growth happens through consent, convenience, and productivity tooling rather than formal provisioning. Over time, this creates an identity layer that sits outside standard JML discipline and bypasses many access review processes. Security leaders should assume that the most dangerous access in this domain is often the access nobody thinks of as access.
Governance without friction is the real design constraint. If controls are too heavy, users will route around them through shadow IT and unmanaged approvals. If controls are too light, they will silently accumulate broad delegated access. The practitioner challenge is not choosing between usability and security, but defining the decision points where user-generated machine identity must be examined before it becomes durable.
User-domain NHI sprawl is becoming a control-plane problem for enterprise identity. The hidden concept here is the identity blast radius created by ordinary work activity. Once a browser, SaaS app, or OAuth integration can mint persistent access, the user domain stops being peripheral and becomes a core identity surface. Practitioners need to govern the creation point, not just the incident response point.
What this signals
User-domain identity governance needs to move upstream. The control problem is no longer only about human authentication or formal service account management. It now includes the user decisions that create persistent delegated access, which means discovery, approval, and revocation have to operate inside the productivity layer as well as the IAM layer.
Hidden NHI sprawl is best understood as identity accumulation through normal work. The practical implication is that the most effective governance programme will classify OAuth consents, stored secrets, and personal automation as first-class identity assets, not as miscellaneous application noise.
For practitioners
- Map user-generated NHI sources Inventory where employees create machine identities through OAuth apps, browser storage, SaaS approvals, and personal automation tools.
- Establish approval gates for broad consent Require review for applications that request wide scopes, access multiple systems, or connect to regulated data.
- Scan endpoints for stored secrets Search managed and BYOD endpoints for API keys, refresh tokens, and session data that can outlive the user task.
- Build revocation paths for dormant grants Revoke OAuth consents and application credentials that no longer map to an active business requirement or owner.
- Automate risk scoring for user-created access Use behavioural signals to distinguish routine productivity access from suspicious token reuse, overbroad scope, or unusual app behaviour.
Key takeaways
- User behaviour in the productivity layer is creating a growing population of non-human identities that conventional access governance often misses.
- The main risk is not just exposure, but durable delegated access that survives beyond the original business need and can be reused silently.
- Security teams need lifecycle controls, approval gates, and revocation paths for user-generated NHIs if they want to reduce this hidden attack surface.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Browser-stored tokens and API keys are a core exposure path in this article. |
| NHI-03 — Vulnerable Third-Party NHI | OAuth apps and SaaS integrations extend trust to third-party machine identities. | |
| NHI-07 — Long-Lived Secrets | The article highlights tokens that persist well beyond the original business need. | |
| Recommendation — Scan user endpoints for exposed secrets and revoke any credential found outside governed storage. Review third-party app consent and restrict access to integrations with broad or sensitive scopes. Enforce expiry and revocation for user-generated credentials that outlive the task they support. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | User-generated access needs entitlement governance even when it originates in productivity workflows. |
| Recommendation — Apply entitlement review to user-created access paths and remove permissions that no longer match business need. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The article's attack patterns center on stolen tokens and broad access to connected systems. |
| Recommendation — Map token theft and consent abuse to credential access and lateral movement hunts in detection content. | ||
Key terms
- User-Generated NHI: A user-generated NHI is a non-human identity created through normal employee activity, such as approving OAuth access, saving a token, or installing an application. It is often born outside central IAM workflows, which makes ownership, scope, and retirement harder to govern.
- OAuth Consent: The approval that allows an application to access resources on behalf of a user or tenant. In practice, consent can create durable access paths that outlive the original interaction if permissions are broad, unmanaged, or never reviewed. For security teams, it is both an access decision and a lifecycle event.
- Shadow IT Proliferation: The uncontrolled spread of user-installed applications and services outside formal security approval. In this context, it is an identity problem as much as a software problem because each unmanaged tool can create new machine identities, credentials, and trust relationships.
- Token Persistence: Token persistence is the retention of access or refresh tokens beyond the immediate task that justified them. In browser-based integrations, it increases the chance of unauthorized reuse, complicates revocation, and creates a governance problem because the credential outlives the user’s intent.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org