TL;DR: Legacy SQL-based IAM and IGA models cannot keep pace with sprawling SaaS, multi-cloud, and non-human identities, because they fail to resolve effective permissions across billions of relationships, according to Veza. Its access graph approach makes access traceable and reviewable, but the deeper issue is that visibility without governance still leaves least privilege incomplete.
At a glance
What this is: This is a vendor analysis of why graph-based identity data models are needed to answer who can do what on what data across people, workloads, and NHIs.
Why it matters: It matters because IAM and NHI teams need effective-permission visibility, not just entitlements, if they want access reviews, least privilege, and remediation to be credible.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
👉 Read Veza’s analysis of access graphs, effective permissions, and NHI governance
Context
Identity programmes still fail when they can see accounts but not the effective permissions those accounts actually have. That gap becomes more severe as access expands across SaaS, cloud platforms, local systems, and non-human identities, because a simple entitlement list no longer explains how access is granted or inherited.
Veza’s article is really about the limits of relational identity models in a graph-shaped access environment. For IAM, IGA, and NHI governance teams, the core issue is not storage format alone but whether the control model can represent nested roles, policy combinations, and cross-system access paths accurately.
The article also points to a practical governance shift: access reviews need to validate outcomes, not just approvals. For teams building out service account, workload identity, and human access governance together, the relevant benchmark is whether the programme can explain and prove effective access rather than merely record assignments.
Key questions
A: Start with a single inventory of identities, entitlements, and connected applications across your cloud estate, then segment reviews by risk and identity type. Human users, shared accounts, and service accounts need different certification logic, because ownership, expiry, and remediation differ. The goal is not just approval, but provable removal of access that no longer matches business need.
Q: Why do non-human identities complicate least-privilege implementation?
A: Non-human identities often need persistent access for automation, integration, and orchestration, which makes least privilege harder to enforce without strong scoping and rotation. The answer is not more standing access. It is tighter ownership, shorter credential lifespan, and continuous verification of what each identity can do.
Q: What breaks when access reviews are based only on granted permissions?
A: Reviews based only on granted permissions miss whether access was actually used, whether it was excessive, and whether it still matches the job or workload. That creates false confidence and weak audit evidence. Security teams need activity-aware review data so they can prove that privilege is not just assigned correctly but also kept current.
Q: How can organisations prove that revoked access is really gone?
A: Use a control that checks the post-review access state against the graph or access inventory, then block closure until the entitlement is no longer effective. This is especially important for privileged and non-human identities, where stale access is often the result of incomplete downstream removal. Verification should be part of the control, not an audit sample later.
Technical breakdown
Why graph models outperform SQL for identity access relationships
A relational database can store identities, roles, and permissions, but it struggles to express the many-to-many and nested relationships that define modern access. Graph models are better suited to identity because they represent entities and edges directly, so a reviewer can follow the path from identity to group, role, policy, and resource without flattening context. That matters when the access fabric spans billions of relationships across SaaS, cloud, and NHI estates.
Practical implication: map where your current IAM data model loses inheritance, nesting, or cross-system context before you trust it for access decisions.
Effective permissions versus recorded entitlements
Recorded entitlements show what was assigned. Effective permissions show what the identity can actually do after policies, inheritance, resource rules, and platform-specific overrides are applied. In cloud systems, the difference is material because a group membership may not equal the real action boundary, and a denial in one layer may be overridden in another. Governance fails when review processes certify the recorded state instead of the executable state.
Practical implication: base access reviews and remediation on effective permissions, not on raw group or role assignments.
Why NHI visibility needs first-class identity governance
Non-human identities are not a side category of human IAM. Service accounts, tokens, secrets, and workload identities often carry broader privileges, longer lifetimes, and weaker ownership signals than employee accounts. When these identities are treated as secondary objects, teams miss hidden access paths and overestimate control coverage. A first-class model is required if NHI governance is to be auditable, revocable, and explainable at scale.
Practical implication: bring service accounts, tokens, and workload identities into the same governance workflow as human identities, with ownership and revocation controls attached.
Threat narrative
Attacker objective: The objective is to exploit hidden or over-privileged access paths that identity teams cannot accurately see or revoke.
- Entry occurs when fragmented identity data prevents security teams from seeing which accounts, roles, and policies can reach sensitive resources across systems. Escalation follows when nested permissions and inherited access are not resolved into effective permissions, leaving hidden privilege paths intact. Impact is sustained overexposure, because reviews certify incomplete data and remediation misses the actual access that matters.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- Snowflake breach — Snowflake breach compromised Ticketmaster, Santander and others via cloud credential abuse.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Graph fidelity is now a governance requirement, not just an architecture choice. Identity programmes increasingly fail because the data model cannot represent the access fabric they are trying to govern. When permissions are nested across cloud, SaaS, and NHI estates, a flat entitlement view produces false confidence. Practitioners should treat graph fidelity as the minimum condition for credible access governance.
Effective permissions are the real control surface. A role assignment is not the same thing as actionable access, especially when platform-specific policy evaluation changes the result. Reviews that certify assignments instead of outcomes create governance theatre, not risk reduction. The practitioner conclusion is simple: if you cannot compute effective permissions, you cannot prove least privilege.
Non-human identities need first-class lifecycle governance. Service accounts, tokens, and workload identities often outlive the people and systems that created them, and that is where over-privilege becomes persistent. The failure is not merely visibility, but ownership and revocation discipline across the full NHI lifecycle. Teams should govern NHIs with the same lifecycle rigor they expect for human access.
Access review remediation closes only if the underlying entitlement actually disappears. This article highlights a familiar governance gap: approval workflows that do not validate the post-decision state. Without verification, recertification becomes a recordkeeping exercise instead of a control. The implication for practitioners is to make outcome validation part of the review itself, not a separate afterthought.
Least privilege at enterprise scale depends on unifying identity and permission metadata. IdPs know who is linked to a group, cloud platforms know what a role can do, and SaaS systems know only part of the picture. None of those views alone is enough to answer who can do what on what data. The field is moving toward unified access intelligence, and teams should align their governance model accordingly.
From our research:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- For lifecycle controls, the Ultimate Guide to NHIs , Key Challenges and Risks shows why visibility, rotation, and offboarding need to be governed together.
What this signals
Access governance is moving from recordkeeping to verification. Teams that still rely on static role inventories will keep missing the effective-permission problem, especially where SaaS and cloud policies override simple assignment logic. The practical shift is toward control planes that can prove what an identity can do, not just what it was given.
With 92% of organisations exposing NHIs to third parties, per the Ultimate Guide to NHIs, vendor-connected access is no longer a fringe risk. IAM and NHI programmes should prioritise integration review, ownership mapping, and revocation validation before expanding to lower-risk systems.
Unified identity and permission metadata will become a baseline expectation. The teams most exposed to privilege creep are the ones that keep identity, cloud, SaaS, and NHI views separate. A single access graph is not the end state, but it is increasingly the minimum usable substrate for governance automation.
For practitioners
- Define the effective-permission source of truth Make one system responsible for resolving inherited roles, policy overrides, and resource-based permissions into the actual action boundary used for reviews and approvals.
- Bring NHIs into the same governance workflow Inventory service accounts, tokens, certificates, and workload identities alongside human accounts, then attach ownership, review cadence, and revocation paths to each.
- Validate revocation after every access decision Require evidence that rejected access was removed from the access graph, not just marked closed in the workflow, before the review is considered complete.
- Map high-risk integrations first Start with SaaS, cloud, and custom applications that carry the widest privilege inheritance, then expand the graph to lower-risk systems once the model is reliable.
Key takeaways
- Legacy IAM models struggle because they cannot represent modern access relationships accurately enough to govern them.
- Effective permissions matter more than assigned entitlements when the question is who can actually perform an action on data.
- Teams should unify human and non-human access governance, then verify that removals really change the access state.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | The article centers on NHI visibility and governance across fragmented systems. |
| NIST CSF 2.0 | PR.AC-4 | Effective permissions and access review validation align with access control management. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the core control issue in effective-permission governance. |
| NIST Zero Trust (SP 800-207) | Unified identity and access evaluation supports continuous verification. |
Use OWASP-NHI to map where service account visibility and ownership are missing in your access model.
Key terms
- Effective Permissions: Effective permissions are the access an identity can actually use after role inheritance, scope, and policy are applied. In Azure AI environments, they often matter more than the assigned role name because inherited rights can widen access to data, logs, and secret stores.
- Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
- NHI Lifecycle Management: The end-to-end governance of a non-human identity from creation and onboarding through active management, monitoring, credential rotation, and secure decommissioning.
- Entitlement Inheritance: The way access granted at one layer, such as a group, role, or policy, flows into additional permissions at another layer. It is central to modern IAM risk because the final access outcome can differ materially from the original assignment.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- How the Access Graph resolves inherited roles, nested groups, and policy combinations into effective permissions
- Product update notes on remediation validation in Access Reviews and how entitlement removal is verified
- Integration coverage across SaaS, cloud, on-prem, and custom apps for teams that need implementation detail
- Examples of Open Authorization API usage for bringing homegrown applications into the access model
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org