By NHI Mgmt Group Editorial TeamBased on Veza: “2025: The Year of Product Innovation” (January 11, 2026)

TL;DR: Identity governance is shifting from simple visibility to operational governance, with 325+ integrations, AI-powered access review, NHI and AI agent inventory, MCP server discovery, and automated revocation workflows across human and machine identities, according to Veza. The real change is that identity governance is moving from static review to runtime accountability across NHI, human access, and emerging autonomous actors.


At a glance

What this is: Veza’s 2025 access platform update expands NHI governance from inventory and visibility into review, revocation, and owner accountability across machine identities and AI agents.

Why it matters: It matters because IAM and IGA teams now have to govern machine access that can span legacy apps, cloud services, and agent-driven tool use, not just human entitlements.

By the numbers:

  • Veza says the update adds 325+ out-of-the-box integrations across enterprise systems and AI platforms.

Context

NHI governance now has to answer a more operational question than “what exists”: who owns each machine identity, what it can reach, and how quickly excess access can be revoked. In this update, Veza extends access governance across cloud services, SaaS, legacy applications, and autonomous AI agents, so the identity problem is not inventory alone but control at permission level.

The practical shift is toward lifecycle-linked governance: discovery, review, revocation, and accountability are being tied together in one access graph. That matters for NHI programmes because service accounts, secrets, keys, and AI agents create the same governance pressure in different forms: unmanaged scope, stale access, and weak ownership.


Key questions

Q: How should teams govern non-human identities that support remote access and back-end workflows?

A: They should govern them as distinct identities with explicit ownership, scoped permissions, rotation, revocation and offboarding. Service accounts, tokens and API keys cannot rely on human MFA, so their lifecycle controls must be designed around reach and persistence. The goal is to prevent machine access from becoming the hidden path through the environment.

Q: Why do service accounts and AI agents need different controls from human users?

A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.

Q: What breaks when rejected access is not actually revoked after review?

A: The review process becomes an audit record rather than a control. Rejected entitlements remain usable, ownership stays unchanged, and the access graph no longer reflects reality, which means downstream decisions are made on false assumptions about who can still reach what.

Q: Should organisations treat AI agent access to AWS differently from CI/CD access?

A: Yes. CI/CD access is usually job-bound and repeatable, while AI agent access can be more context-sensitive and less deterministic at runtime. Both should be ephemeral, but agent sessions need tighter scoping, explicit approval boundaries, and stronger attribution because the workflow can change while it is running.


Technical breakdown

Permission-level visibility across machine identities and AI agents

Veza’s update centres on an access graph model that connects identities, applications, entitlements, and observed usage. For NHI governance, that means service accounts, secrets, keys, and AI agents can be represented with enough context to show not just that they exist, but what they can actually access and how that access is inherited or impersonated. The addition of public MCP server discovery is notable because it reveals tool endpoints that AI agents may reach during runtime, creating a separate governance surface from traditional application access. Practical implication: inventory alone is no longer sufficient; teams need permission-level mapping that reaches into agent tool paths and machine-to-machine dependencies.

Practical implication: build governance views around effective access and runtime reachability, not just identity registration.

Automated access review and revocation workflows

The update adds auto-revocation of rejected access, revocation verification, and on-demand reviews that can be triggered from lifecycle, NHI, and segregation-of-duties workflows. This is a move from review-as-evidence to review-as-control, because the system is no longer stopping at certification outcomes. For NHI programmes, that matters because machine access often decays without a human leaving event, so review and revocation need to be embedded in the same operational loop. Practical implication: access review programmes should be measured by how quickly rejected access is removed and verified, not only by completion rates.

Practical implication: tie certification to automatic deprovisioning and verify that revoked entitlements actually disappear from the graph.

Owner mapping and orphaned identity governance

The update introduces agent-to-human ownership mapping and orphaned identity alerts, which addresses one of the most persistent machine identity failures: access without accountable ownership. In NHI governance, the control weakness is not merely over-privilege, but the absence of a named party responsible for a secret, service account, or agent when risk emerges. That is especially important for AI agents, where human accountability can be diluted across teams and workflows. Practical implication: governance models must require a living owner for every non-human identity, with alerting when that link breaks.

Practical implication: enforce named ownership for every non-human identity and treat orphaning as a governance incident.


Threat narrative

Attacker objective: The attacker or mismanaged actor seeks to turn legitimate machine access into broader access to sensitive systems, data, and workflows.

  1. Entry occurs through legitimate machine identity onboarding, API key discovery, or agent registration across cloud and SaaS environments.
  2. Credential access is amplified when excessive permissions, shared secrets, or cross-application impersonation let the identity reach more than it should.
  3. Escalation happens when access graph gaps, orphaned ownership, or unresolved review exceptions allow the identity to retain or widen scope.
  4. Impact is unauthorized reach into sensitive data, privileged workflows, or external tool endpoints, including MCP-connected paths for AI agents.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Permission-level governance is replacing identity inventory as the core NHI control model. Once organisations can see machine identities, the next failure is assuming visibility equals control. This update shows the market moving toward effective-permission governance, where owners, entitlements, and actual reach matter more than counts of identities. That is the right direction for NHI programmes because machine risk is defined by what an identity can do, not by whether it is listed in a catalogue.

Unified NHI and AI agent governance is becoming a single operational problem. The article treats autonomous agents, service accounts, and secrets as different expressions of the same access challenge, and that framing is now correct. Agent tool use, public MCP access, and cross-platform discovery collapse old boundaries between workload identity and emerging autonomous behaviour. Practitioners should stop designing separate control planes for “machine” and “AI” access when the decision point is the same: what is authorised, by whom, and for how long.

Agent-to-human ownership mapping is the named concept that will determine whether NHI programmes remain accountable. A machine identity without a responsible human owner is governance debt, not just inventory debt. The article’s emphasis on orphaned identity alerts shows that the real operational failure is loss of accountable stewardship, especially when access crosses teams, clouds, and tool ecosystems. Practitioners should treat ownership continuity as a first-class control, not a documentation exercise.

Auto-revocation turns access review into an enforcement control rather than an audit artefact. Review programmes fail when rejected access remains live after certification ends. By coupling review outcomes to revocation verification, the update reflects where the market is heading: governance systems that close the loop, not simply record intent. That matters most for NHI estates, where delayed deprovisioning leaves exploitable access in place long after the review is complete.

Public tool discovery is emerging as part of the NHI attack surface. Surfacing MCP servers accessed by agents makes clear that governance now extends beyond internal applications to the external tools that agents can call at runtime. This is an important shift for practitioners because it exposes the trust boundary that traditional access catalogues miss. The control question is no longer only who has access, but which tools an agent can reach and under what authority.

From our research library:

What this signals

Agent-to-human ownership mapping: every non-human identity needs a named accountable owner, and that relationship must survive reassignment, role changes, and tool expansion. When ownership breaks, the governance model no longer has a responsible human to approve, review, or revoke the access it is certifying.

Access reviews are moving toward enforcement, not reporting. If rejected access is not auto-revoked and verified, the programme measures intent while leaving the actual entitlement untouched, which is exactly where machine identity risk persists.


For practitioners

  • Inventory effective machine access, not just identities Map service accounts, keys, secrets, and AI agents to the applications, data stores, and tool endpoints they can actually reach. Use that map to find stale permissions, hidden inheritance, and cross-platform impersonation paths.
  • Tie review outcomes to automatic revocation Configure access review workflows so rejected entitlements are removed automatically and then verified against the access graph. Do not treat review completion as proof of removal.
  • Assign a named human owner to every non-human identity Require accountable ownership for service accounts, keys, and AI agents, and alert when that ownership is lost or ambiguous. Orphaned access should be treated as a governance exception, not a housekeeping issue.
  • Extend SoD checks to NHIs and AI agents Apply segregation-of-duties rules across machine identities and autonomous agents when they span multiple applications or approval paths. Conflicting permissions should be surfaced before they become operationalised.
  • Track agent tool reach as a distinct governance boundary Review public MCP servers and other external tools that AI agents can access, and separate those paths from ordinary application access in your governance model.

Key takeaways

  • The article shows NHI governance moving from inventory and visibility into operational control across review, revocation, and ownership.
  • Its significance is the convergence of machine identity and AI agent governance into one access model, not two separate programmes.
  • The strongest control implication is to link every non-human identity to accountable ownership and verified removal of rejected access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingOrphaned identities and verified revocation are central to this update.
NHI-05 — Overprivileged NHIThe update repeatedly addresses excessive machine access and least privilege enforcement.
NHI-10 — Human Use of NHIHuman ownership of machine identities is a major governance theme in the article.
Recommendation — Tie NHI offboarding to verified revocation so removed access does not persist in the graph. Review machine entitlements against least privilege and remove permissions that exceed actual task needs. Require accountable human ownership for every NHI and alert when that ownership disappears.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article’s risk model centers on machine access that can be reused or expanded across systems.
Recommendation — Map excessive machine permissions to credential-access and lateral-movement paths in your detection strategy.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe update focuses on permission-level governance and entitlement enforcement.
Recommendation — Apply entitlement governance so access reviews and provisioning decisions reflect actual authorisations.

Key terms

  • Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials, ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.
  • Permission Level: A permission level defines how much action a role can take on a record or task, such as View, Create, Edit, or Full. Higher levels expand operational power and can introduce control risk if applied too broadly. Careful level selection is essential to keep access aligned with actual job responsibilities.
  • Orphaned Identity: An orphaned identity is a service account, token, or other machine credential that no longer has a clear owner, purpose, or retirement path. These identities create compliance and security risk because they are easy to forget, difficult to review, and often remain active long after they should have been removed.
  • Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org