By NHI Mgmt Group Editorial TeamBased on Veza: “White Paper” (October 17, 2025)

TL;DR: Modern identity risk now spans privileged users, non-human identities, data systems, and AI agents across SaaS, cloud, and on-prem, with effective permissions only becoming governable when teams can see blast radius and inherited access, according to Veza. The real shift is away from fragmented controls toward continuous entitlement truth, because least privilege fails when access is distributed faster than reviews can follow.


At a glance

What this is: This is Veza’s case for using an identity graph to unify privileged access, NHI, data access and agentic AI governance across complex environments.

Why it matters: It matters because IAM, PAM and NHI programmes cannot control what they cannot see, and identity graphs shift governance from point-in-time review to effective permission visibility.


Context

Enterprise identity has outgrown fragmented admin lists and isolated entitlement reviews. The problem is not only who has an account, but what that account can actually do across SaaS, cloud, data and on-prem systems, including inherited access that traditional PAM and IGA tools often miss.

For NHI, agentic AI and privileged human access, the governance gap is the same: effective permissions are distributed across systems faster than recertification cycles can keep up. Veza frames the answer as shared visibility into blast radius, ownership and privilege drift rather than another narrow control layer.


Key questions

Q: How should security teams govern privileged access across cloud and legacy systems?

A: Teams should govern privileged access by resource class, not with one uniform assumption set. Legacy servers can often tolerate traditional PAM patterns, but cloud databases, Kubernetes, and internal web apps usually need shorter-lived access, broader protocol coverage, and stronger lifecycle controls. The right test is whether the control plane can revoke, log, and prove access consistently across all estates.

Q: Why do non-human identities create a larger governance problem than human accounts?

A: Non-human identities scale faster, are used by systems rather than people, and often carry broad or persistent access. That combination makes ownership, review, and revocation harder than with human accounts. The governance problem is not only visibility. It is also the size of the potential blast radius if a machine credential is exposed or misused.

Q: What are the signs that legacy access controls are failing in a hybrid IT environment?

A: Common warning signs include users juggling separate passwords and MFA factors, security policies that differ by application, slow onboarding and offboarding, and reliance on VPNs for routine app access. Another signal is repeated exceptions for older systems because teams cannot apply consistent modern authentication controls across cloud and on-prem environments.

Q: Why do agentic AI systems need NHI-style access controls?

A: Agentic AI systems can call tools, reach data, and act repeatedly, which makes them behave like non-human actors with permissions that need scoping and revocation. If those permissions are broad or untracked, the model can cross into data exposure or workflow abuse. NHI-style controls help limit what the system can access and for how long.


Technical breakdown

Why identity graphs change privileged access governance

An identity graph models relationships among identities, roles, resources and inherited permissions so teams can see effective access rather than isolated entitlements. In practice, that matters because a user may appear ordinary in one system but carry admin power through federation, nested roles or SaaS delegation in another. The operational difference is that review moves from static account lists to relationship mapping across the full estate. That is the only way to identify dormant admins, over-permitted federated accounts and hidden privilege paths that legacy PAM and IGA views leave fragmented.

Practical implication: build governance around effective permissions, not just assigned roles.

How NHI access becomes invisible without ownership and lifecycle controls

Non-human identities are not only numerous, they are often operationally anonymous. Service accounts, tokens, pipelines and workload identities may persist without clear owners, expiry or review ownership, which makes them easy to forget and hard to offboard. When those credentials can assume cloud roles or impersonate other services, the issue stops being inventory hygiene and becomes privilege governance. The technical failure is lifecycle drift: access exists longer than the business context that justified it, and no control owns the gap end to end.

Practical implication: tie every NHI credential to an owner, expiry condition and review path.

Agentic AI security depends on controlling impersonation paths and issued scope

AI agents become an identity problem when they can call APIs, fetch data and act across systems with delegated authority. The security risk is not simply that an agent exists, but that it can inherit or impersonate permissions in ways that bypass the governance model built for human-paced access. A graph-based approach helps expose which resources an agent can reach, what it can impersonate and where time-bound access is necessary. That moves control from broad trust in the agent runtime to scoped, auditable authority at issuance.

Practical implication: constrain agent access by task scope, delegation path and expiry.


  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity graphs are becoming the control plane for effective permissions. The old access model assumed you could govern identities by system or by role, but modern environments distribute authority across SaaS, cloud, data and on-prem services. That makes inherited access the real security problem, not the visible account alone. Practitioners should treat blast radius mapping as a governance primitive, not a reporting feature.

Non-human identity governance fails when ownership is implied rather than explicit. Service accounts, tokens and pipelines become risky when no one is accountable for lifecycle state, rotation or revocation. Veza’s framing reinforces a broader NHI truth: discovery without ownership still leaves privilege unmanaged. Practitioners should insist on identity ownership as a policy condition, not an afterthought.

Agentic AI changes the meaning of least privilege because scope can change at runtime. Access models designed for stable, human-paced sessions do not hold when an agent can call tools, assume roles and continue execution without the same decision loop. The assumption that privilege can be reviewed after the fact weakens once the actor can complete meaningful work inside a short autonomous run. Practitioners must re-evaluate where review stops and issuance controls begin.

Continuous entitlement truth is replacing point-in-time attestation as the useful governance measure. Recertification still matters, but it no longer provides enough control if effective permissions drift continuously underneath it. The field is moving toward systems that can show what access actually exists right now, across identities and resources, so audit evidence and operational enforcement come from the same dataset. Practitioners should align PAM, IGA and NHI governance to one live access model.

Privilege, data and AI governance are converging into one identity security programme. The article reflects a market reality that separate point tools no longer answer the core question: what can this identity actually reach? That convergence will push teams to re-evaluate ownership boundaries between PAM, NHI, cloud security and data governance. Practitioners should plan for a shared control language across those teams.

From our research library:

What this signals

Identity graph governance is the operational answer to entitlement sprawl. When permissions are distributed across SaaS, cloud and on-prem, point-in-time review cannot keep pace with inherited access and privilege drift. Teams need a live model of effective permissions if they want blast radius reduction to be more than a board-level phrase.

Non-human identity ownership is the missing control in many programmes. Service accounts and pipelines are governable only when someone owns them, reviews them and can revoke them. A policy that names owners, expiry conditions and review paths changes NHIs from invisible infrastructure into managed identities.

97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs. That figure reinforces a simple conclusion: entitlement visibility is not optional, because the majority of machine identities already sit above the privilege line.


For practitioners

  • Map effective permissions across the estate Build a single view of who can do what across SaaS, cloud, data and on-prem, including inherited access and cross-account role assumption. Use that view to prioritise the identities with the largest blast radius first.
  • Assign owners to every non-human identity Require a named owner, business purpose and lifecycle state for each service account, token, pipeline and workload identity. Treat unknown ownership as a governance defect, not an inventory gap.
  • Time-box delegated and impersonated access Set expiry conditions for federated roles, workload assumptions and agent permissions so access cannot persist beyond the task or business use case that justified it.
  • Separate privileged access issuance from effective access review Use PAM to govern how elevated credentials are issued, then validate actual permissions through continuous entitlement monitoring so hidden privilege paths are caught outside the review cycle.

Key takeaways

  • Modern identity programmes fail when they track accounts without tracking effective permissions across systems.
  • Non-human identities and agentic AI both increase the importance of ownership, lifecycle state and delegated scope.
  • The practical response is a shared identity model that connects PAM, NHI governance and continuous entitlement monitoring.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on excessive permissions across service accounts, tokens and workloads.
NHI-01 — Improper OffboardingThe article stresses lifecycle ownership and revocation for dormant NHIs.
NHI-10 — Human Use of NHIThe article links NHIs and AI agents to delegated human and machine use of credentials.
Recommendation — Reduce standing entitlements and review NHI privilege against actual blast radius. Offboard unused NHIs and revoke access when the business owner or use case changes. Prevent humans from using NHIs as shared bypass identities and track delegated usage.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe piece is fundamentally about governing effective permissions and entitlements.
Recommendation — Continuously validate permissions and authorisations against current business need.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article discusses privilege paths that enable credential abuse and movement across systems.
Recommendation — Map exposed privilege paths to ATT&CK and prioritise the identities with the largest blast radius.

Key terms

  • Identity Graph: An identity graph is a relationship map that connects identities, assets, data, and permissions so teams can see how access actually flows. In NHI programmes, it helps explain which agent is related to which owner, which system, and which policy boundary.
  • Effective Permissions: Effective permissions are the access an identity can actually use after role inheritance, scope, and policy are applied. In Azure AI environments, they often matter more than the assigned role name because inherited rights can widen access to data, logs, and secret stores.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Identity Ownership: Identity ownership is the assignment of a responsible human for each identity's purpose, access, review, and retirement. For non-human identities, ownership must be explicit because the creator is not always the right person to approve ongoing access. Without ownership, review and revocation become inconsistent and slow.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org