By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: UnosecurPublished July 13, 2026

TL;DR: Modern identity sprawl now spans humans, service accounts, and AI agents, and a unified graph is needed to correlate risk, detect toxic combinations, and act before attackers move through fragmented systems, according to Unosecur. The editorial case is that identity governance must shift from isolated inventory to continuously governed identity relationships across every source.


At a glance

What this is: This is an analysis of Unosecur's unified identity fabric approach, which argues that correlating humans, NHIs, and AI agents into one graph is necessary to surface risk and governance gaps.

Why it matters: It matters because IAM teams cannot govern least privilege, visibility, or remediation across NHI and AI agent estates if identities remain fragmented across tools and owners.

By the numbers:

👉 Read Unosecur's analysis of unified identity fabric for humans, NHIs, and AI agents


Context

Identity governance breaks down when the same real-world subject appears as multiple records across cloud, SaaS, on-prem, and AI systems. The primary issue is not missing dashboards, but missing correlation, because least privilege and accountability cannot be enforced against an identity surface no one can see end to end.

That problem now spans three actor types at once: human identities, non-human identities such as service accounts and tokens, and AI agents that can act inside production environments. Unosecur frames the answer as a unified identity graph, but the underlying governance challenge is broader than any one platform: identity control has to follow the actor across systems, not stay trapped in silos.


Key questions

Q: How should security teams govern AI agents that use service accounts and MCP tools?

A: Start with ownership, then add runtime attribution and containment. Security teams should know which human deployed the agent, which identity the agent uses, what tools it can invoke, and when to revoke access. If the agent can chain tool calls or spawn sub-agents, governance must cover those paths as well, not just the initial login.

Q: Why do fragmented identity inventories create hidden risk?

A: Because the same actor can appear as separate records across cloud, SaaS, and infrastructure tools, which breaks review quality and obscures privilege relationships. Without correlation, teams miss stale access, duplicate entitlements, and risky combinations that only become obvious when identities are joined across sources.

Q: What breaks when toxic identity combinations are not prioritised?

A: Low-severity findings stay isolated even when they describe a reachable attack path. A stale secret may look minor until it is linked to privileged access, a critical environment, and no monitoring, at which point the real issue is the combined blast radius rather than any single alert.

Q: How should organisations connect IAM, PAM, and governance for NHI security?

A: Start by sharing ownership, entitlement, and session context across the three domains. IAM should not make decisions blind to privilege, PAM should not operate without lifecycle context, and governance should recertify based on real usage. The goal is coordinated control, not a unified toolset.


Technical breakdown

Why identity correlation is the first control layer

A unified identity graph links records from identity providers, cloud platforms, SaaS apps, and infrastructure tools so security teams can see one actor instead of many partial records. Correlation matters because a service account, API token, or human user may exist in several systems with different permissions, owners, and risk states. Without correlation, access reviews, anomaly detection, and remediation all operate on incomplete data. The practical effect is simple: the quality of every downstream identity control depends on whether the inventory represents the same subject consistently across sources.

Practical implication: establish a cross-source identity record before attempting entitlement cleanup, risk scoring, or access certification.

How toxic combinations turn weak signals into real risk

Toxic combination analysis treats identity risk as a pattern problem rather than a single-alert problem. A stale secret, an admin role, no MFA, and a critical workload may each look tolerable on their own, but together they create a credible attack path. This is especially relevant for NHI governance because service accounts and tokens often have broad reach and low human visibility. The technical value is not just prioritisation, but context: the platform connects source identity, permissions, exposure, and environment into one decision surface.

Practical implication: rank identity findings by combined blast radius, not by isolated severity labels.

Why AI agent identity behaves like a higher-risk workload identity

AI agents often appear in IAM inventories like ordinary service accounts, but their runtime behaviour can expand the effective blast radius. The agent may call a model, invoke tools, and trigger downstream services through permissions that were never reviewed as a chain. That means the security question is not only what the agent itself can do, but what each invoked tool and connected service can reach. In practice, this creates a layered identity problem that combines workload identity, delegated tool access, and monitoring of execution paths.

Practical implication: map AI agent permissions as an execution chain, not as a single static principal.


Threat narrative

Attacker objective: The objective is to turn one compromised or overprivileged identity into broad, low-friction access across multiple connected systems before defenders can correlate the path.

  1. Entry begins when an attacker or malicious actor gains access through an overprivileged credential, exposed OAuth grant, or broadly scoped token tied to an identity path that was never fully governed.
  2. Escalation occurs as the actor uses that identity to move through connected systems, harvest additional secrets, and reach resources that were not intended to be reachable from the original principal.
  3. Impact follows when the attacker can enumerate, modify, or exfiltrate data across environments before the organisation has a complete view of which identity enabled the path.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Unified identity correlation is now a baseline control, not a reporting enhancement. When humans, NHIs, and AI agents are scattered across disconnected inventories, every governance process starts from incomplete evidence. The practical consequence is that access reviews, risk scoring, and remediation all inherit the same blind spot: they evaluate fragments rather than identities.

Identity blast radius is the right mental model for modern NHI and agent governance. A stale key, a broad role, and a connected production service are not separate findings when they combine into a reachable attack path. That is why toxic combination analysis matters more than isolated severity labels: the risk is in the reachable chain, not the individual signal.

AI agents should be governed as delegated workload identities with execution-chain accountability. Treating an agent like a standard service account misses the fact that its real privilege is distributed across invoked tools, downstream APIs, and model-mediated actions. The implication is that entitlements alone no longer describe effective authority, which forces IAM teams to think in terms of chain-of-access rather than single-principal inventory.

Cross-domain identity governance is converging on one operating model. Human access, machine access, and emerging agent access now share the same failure pattern: provisioned but ungoverned identity. That convergence means IGA, PAM, and NHI programmes can no longer remain separate planning lanes if they are expected to reduce exposure in production.

From our research:

  • 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
  • Another finding from the same survey shows that only 44% of organisations have implemented any policies to manage their AI agents, even though 92% say governing them is critical to enterprise security.
  • For a broader governance lens, see OWASP NHI Top 10 for the control patterns most often missed when agent access expands faster than policy.

What this signals

Identity correlation will become the deciding factor in whether governance programmes can keep pace with AI and workload sprawl. With 70% of organisations granting AI systems more access than human employees, the issue is no longer whether identity controls exist. It is whether they can represent effective authority across human users, NHIs, and agents in one operating view.

Identity blast radius is the concept security teams should use when deciding what to fix first. The next wave of exposure will come from identities that look ordinary in isolation but become dangerous when their permissions, environments, and delegation chains are joined together. That is why continuous correlation matters more than periodic inventory.

Programmes that still treat AI agents as a sidecar to IAM will keep missing the operational reality. The governance model has to shift from single-principal administration to chain-level accountability, with review, ownership, and revocation aligned to how the actor actually executes.


For practitioners

  • Build a single identity graph across all sources Ingest identity data from cloud, SaaS, on-prem, IdP, and workload systems into one correlated record so the same actor is not reviewed as multiple unrelated entries.
  • Prioritise toxic combinations over isolated findings Escalate stale credentials, no MFA, and privileged access when they co-occur in the same production context, because the combined pattern creates actionable blast radius.
  • Map AI agents as execution chains Document every tool, API, and downstream service an agent can invoke, then review the full chain for excess privilege and unmonitored delegation.
  • Separate governance by actor type but unify policy outcomes Keep human IAM, NHI governance, and agent oversight distinct in implementation, while enforcing the same policy outcomes for least privilege, review, and offboarding.

Key takeaways

  • The core risk is identity fragmentation, because governance fails when the same actor is spread across disconnected systems and never reconciled.
  • The scale of the problem is growing across humans, NHIs, and AI agents, which makes toxic combinations and execution chains more important than isolated alerts.
  • Teams should respond by building a unified identity graph, mapping agent authority end to end, and enforcing policy outcomes across all actor types.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on unified visibility and governance across NHIs.
OWASP Agentic AI Top 10AGENT-03AI agents are treated as delegated execution identities with tool use risk.
NIST CSF 2.0PR.AC-4Least privilege and access governance are central to the article.
NIST Zero Trust (SP 800-207)The article relies on continuous verification across identity contexts.
NIST SP 800-53 Rev 5AC-6Least privilege is the practical control theme throughout the piece.

Align identity reviews to PR.AC-4 and remove excess access that no longer matches business need.


Key terms

  • Unified Identity Graph: A unified identity graph is a shared model of users, service accounts, tokens, roles, and permissions that shows relationships across the environment. It matters because fragmented identity data hides ownership, privilege sprawl, and usage patterns that defenders need to govern risk effectively.
  • Toxic Access Combination: A toxic access combination is a set of permissions that becomes dangerous when granted together, even if each entitlement looks acceptable on its own. In identity governance, these combinations matter because they can enable misuse, separation-of-duties failures, or broader compromise.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Execution Chain: The execution chain is the sequence from prompt to tool use to resulting system or business action. It matters because agent risk is often only visible when the whole chain is analysed together, rather than when each step is judged in isolation.

What's in the full article

Unosecur's full article covers the operational detail this post intentionally leaves for the source:

  • The module-by-module description of how the unified graph is assembled and where each identity source feeds into it.
  • The dashboard, risk, and analyzer workflow details that show how findings are prioritised and tracked through remediation.
  • The Ark AI execution flow, including how approved actions are logged and how the conversational interface changes analyst workflow.
  • The compliance mapping output and export model for SOC 2, ISO 27001, CIS, and NIST reporting.

👉 The full Unosecur article covers the module breakdown, detection workflow, and governance model in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 16, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org