By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: VezaPublished January 11, 2026

TL;DR: Identity governance is shifting from simple visibility to operational governance, with 325+ integrations, AI-powered access review, NHI and AI agent inventory, MCP server discovery, and automated revocation workflows across human and machine identities, according to Veza. The real change is that identity governance is moving from static review to runtime accountability across NHI, human access, and emerging autonomous actors.


At a glance

What this is: Veza’s 2025 platform update expands access governance across human, NHI, and AI agent estates, with its key finding being that visibility now has to feed remediation, classification, and ownership mapping.

Why it matters: This matters because IAM teams can no longer treat machine identities, AI agents, and human accounts as separate governance problems when the same platform now targets reviews, revocation, and lifecycle controls across all three.

By the numbers:

👉 Read Veza's 2025 round-up of access platform updates for NHI and AI governance


Context

Access governance for non-human identities now has to cover discovery, entitlement review, revocation, and owner accountability in the same control plane. Veza’s 2025 update is a good example of where the market is heading: more integrations, more classification, and more operational linkage between risk findings and remediation across NHI, AI agents, and human access.

The important change is not the number of features, but the governance pattern they imply. When organisations can surface secrets, service principals, MCP server access, and AI agent blast radius in one view, the limiting factor becomes whether identity teams can turn visibility into lifecycle action before privilege drift becomes routine.

For IAM and IGA teams, this is no longer a narrow access-review story. It is a multi-actor identity governance problem where service accounts, autonomous agents, and employee access all need ownership, review logic, and least-privilege enforcement that actually survives operational change.


Key questions

Q: Why do structured queries reduce risk for non-human identities and AI agents?

A: Structured queries reduce risk because they replace multi-step tool improvisation with a single, reviewable request. That lowers context bloat, reduces inconsistent intermediate state, and makes it easier to prove what the identity was authorised to do. The result is tighter scope and better accountability.

Q: How do access reviews need to change for machine identities?

A: Access reviews for machine identities should focus on purpose, owner, system reach, and whether the entitlement still exists for an active workload or integration. A reviewer cannot certify what they cannot contextualise, so reviews must show the business function behind the account rather than just a role name.

Q: What breaks when AI agent access is granted without blast-radius controls?

A: The organisation loses the ability to predict which systems the agent can reach once it starts using tools, connectors, or delegated permissions at runtime. That makes least privilege hard to prove and harder to enforce, especially when the agent can touch data sources, models, and identity systems in one session. If blast radius is not explicit, reviews understate real exposure.

Q: Who is accountable when a service account or AI agent keeps access after offboarding?

A: Accountability should sit with the system owner and the identity governance owner, not just the team that requested the access. If a service account or AI agent keeps access after offboarding, that usually means the lifecycle trigger, downstream revocation, or ownership mapping was incomplete. The control failure is organisational, not just technical.


Technical breakdown

Unified access graphs are now the governance substrate

An access graph is a relationship map that connects identities, entitlements, applications, roles, and dependencies so teams can see effective access rather than isolated assignments. In NHI environments, that matters because service accounts, secrets, and AI agents often inherit access through chains that basic IAM reports do not expose. When the graph also tracks external integrations, role mappings, and downstream permissions, it becomes the system of record for review and revocation. Practical implication: teams should treat graph completeness as a control objective, not just a reporting enhancement.

Practical implication: validate that your access graph covers indirect and inherited permissions before using it for reviews or revocation.

Why AI agent blast radius is a different control problem

Blast radius is the set of systems, data, and actions an identity can reach if its access is misused or overextended. For AI agents, that scope can change faster than traditional review cycles because the agent may connect to new tools, prompts, or MCP-backed data sources during runtime. That is why visibility into foundation models, public MCP servers, and agent-to-data paths is more than inventory. It is the difference between assuming constrained access and seeing where the agent can actually operate. Practical implication: model agent access by reachable systems, not by the label attached to the agent.

Practical implication: map AI agent blast radius to reachable systems and tools, then review that scope as a standing governance control.

Automated revocation closes the review loop only if identity state is trusted

Access review is incomplete when rejected access remains present after the review closes. Built-in revocation verification matters because IGA programmes often assume the workflow outcome equals the technical outcome, which is not true in fragmented enterprise estates. If deprovisioning is delayed, blocked, or only partially propagated, the review becomes a documentation event instead of a control. That is especially relevant for NHIs, where orphaned or over-privileged credentials can continue working long after owners think they are removed. Practical implication: verify revocation at the access graph level, not only in the workflow record.

Practical implication: require post-review verification so a closed access review actually means the permission disappeared.


Threat narrative

Attacker objective: The objective is to turn hidden or over-extended machine access into lateral movement, data exposure, and durable control gaps across the identity estate.

  1. Entry occurs when a service account, secret, or AI agent is connected to multiple systems through broad integrations and the effective access path is not fully visible.
  2. Escalation happens when inherited permissions, permissive roles, or public MCP access expand what the identity can reach beyond the intended task scope.
  3. Impact follows when over-privileged NHI or AI agent access is used to reach sensitive data, impersonate identities, or create persistent governance blind spots.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

NHI governance is now an access-graph problem, not a point-product problem. Once an organisation has hundreds of integrations, multiple identity classes, and review workflows spanning humans, service accounts, and agents, control effectiveness depends on the relationship map more than any single dashboard. That makes lifecycle, entitlement, and ownership data part of the same governance layer. Practitioners should judge tooling by whether it can explain effective access end to end.

Permission-level visibility only matters if it is tied to revocation and ownership. The article’s strongest signal is the shift from seeing access to doing something about it. Review comments, risk scores, and dashboards do not reduce exposure unless they connect to enforceable offboarding, revocation, and reassignment when identities become orphaned. Teams should treat unresolved ownership as a control failure, not an administrative nuisance.

AI agent governance and NHI governance are converging faster than most programmes are structured to handle. The same patterns appear in both domains: broad permissions, hidden dependencies, and weak accountability for runtime decisions. The difference is that AI agents can also change scope through tool use and delegation paths, which means static least privilege assumptions age even faster. Security leaders should stop separating these workstreams and design one identity governance model for all non-human actors.

Dynamic Access Profile assignments create a useful governance pattern only when RBAC and ABAC stay explainable. Rule-driven entitlements can reduce manual drift, but they also make access less transparent if teams cannot trace why a permission was assigned. That matters for auditability, exception handling, and review quality. Practitioners should require explainable entitlement logic before allowing dynamic assignment to become the default operating model.

Unified NHI and AI agent inventory is becoming a prerequisite for credible risk reporting. If the inventory cannot surface dormant keys, unrotated secrets, impersonation paths, and public MCP dependencies, the programme will understate real blast radius. This is the new baseline for NHI security maturity. The practical conclusion is that inventory, classification, and review are no longer separate phases.

From our research:

  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
  • From our research: Systems with least-privileged AI access had a 17% incident rate versus 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
  • From our research: For lifecycle and offboarding patterns across machine identities, see NHI Lifecycle Management Guide, which is the right next step once ownership and revocation become the control focus.

What this signals

Permission-level governance is becoming the right abstraction for mixed identity estates. Once organisations are managing humans, service accounts, keys, and AI agents side by side, the programme has to understand effective access rather than rely on identity labels alone. The next maturity step is to connect review outcomes to actual removal of access, because visibility without enforcement still leaves the blast radius intact.

With 70% of organisations granting AI systems more access than they would give a human doing the same job, the gap is no longer theoretical. That figure from the 2026 Infrastructure Identity Survey shows why agent governance needs explicit ownership, scoped permissions, and post-change verification. Teams that wait for a separate AI governance initiative will continue to inherit over-privileged access by default.

Identity programmes should now treat orphaned access as an operational alert condition. When machine identities lose ownership, the problem is not just administrative drift. It is an accountability break that should trigger reassignment, review, or removal before the identity becomes a silent long-lived exception.


For practitioners

  • Expand access reviews to cover non-human identities and AI agents Include service accounts, API keys, secrets, and autonomous agents in the same review process so excessive permissions are not left outside governance because they are non-human.
  • Validate revocation after every rejected access decision Require the workflow to confirm that the permission actually disappeared in the access graph, not only that the review item was marked complete.
  • Map public MCP server use and external integrations to blast radius Document which agents or NHIs can reach each tool, data source, and model endpoint so hidden runtime dependencies do not expand access scope unnoticed.
  • Assign human owners to every machine identity and agent Create explicit ownership for service accounts, keys, and AI agents, then alert on orphaned identities as a governance incident rather than a housekeeping issue.
  • Use least-privilege access profiles with traceable logic Prefer role and attribute rules that can be explained during review and audit, and avoid dynamic entitlements that cannot be justified after the fact.

Key takeaways

  • Veza’s 2025 update reflects a broader shift from access visibility to enforceable governance across human, NHI, and AI agent identities.
  • The most important operational themes are ownership, revocation verification, blast-radius mapping, and review workflows that can actually close the loop.
  • For IAM and IGA teams, the question is no longer whether to govern machine identities, but whether current controls can prove they are governed end to end.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The post centers on NHI discovery, access review, and lifecycle governance.
OWASP Agentic AI Top 10The article includes autonomous AI agent inventory and blast-radius visibility.
NIST CSF 2.0PR.AC-4Least-privilege access and access management are central to the article.
NIST Zero Trust (SP 800-207)3.1The article emphasizes continuous verification and scoped access.
NIST SP 800-53 Rev 5AC-2Account management and lifecycle controls are central to ownership and orphaned identity handling.

Apply least-privilege and review controls to machine identities, agents, and human access alike.


Key terms

  • Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Orphaned Identity: An orphaned identity is a service account, token, or other machine credential that no longer has a clear owner, purpose, or retirement path. These identities create compliance and security risk because they are easy to forget, difficult to review, and often remain active long after they should have been removed.
  • Revocation Validation: Revocation validation is the process of checking whether a certificate or signing authority is still trusted at the moment of use. It matters because a document can appear technically valid while the underlying credential has already been withdrawn or compromised.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • 325+ integration examples and the specific systems added in the 2025 release
  • Access review, revocation, and verification workflow details for approved and rejected permissions
  • NHI and AI agent inventory views, blast-radius visualisation, and orphaned identity handling
  • Lifecycle Management and JIT policy specifics for joiners, movers, leavers, and exception handling

👉 The full Veza post covers the integration list, review workflows, and NHI governance features in detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org