TL;DR: A wider shift toward unified access visibility, monitoring, lifecycle management, and NHI and AI agent governance across identity programmes is highlighted in Veza’s 2025 product innovation roundup. For practitioners, the signal is less about feature volume than about the convergence of governance controls around all identity types, including non-human and autonomous access.
At a glance
What this is: This is Veza’s 2025 product innovation roundup, which points to identity governance converging around visibility, monitoring, lifecycle management, and controls for non-human and AI agent access.
Why it matters: It matters because IAM, IGA, PAM, and NHI teams are being pushed toward one governance model that can handle human users, service accounts, and AI-driven access without separate control planes.
Context
Veza’s product innovation roundup centres on a familiar but still unresolved governance problem: identity programmes now have to manage access across human users, non-human identities, and AI agents in one view. The article is less about any single feature than about the direction of travel for access governance.
That matters because the old separation between IGA for people and ad hoc controls for machine access no longer holds when organisations need access visibility, monitoring, lifecycle management, and access request workflows to cover all identity types. The question for practitioners is not whether to add more controls, but whether the governance model can span every actor type consistently.
Key questions
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.
Q: Why do non-human identities make access reviews less effective?
A: Non-human identities often have broader, longer-lived access than people, and their permissions can be hard to see in periodic reviews. If the identity is not being used as expected, a certification process may still approve it. Continuous usage analysis is needed to find stale or excessive access.
Q: What breaks when lifecycle management is treated as an HR-only process?
A: Non-human identities fall outside the trigger model. Service accounts and agents do not join, move, or leave like employees, so access can persist after the workload, integration, or automation they support has changed. That leaves ownership unclear and revocation too late.
Q: How can identity teams tell whether governance is really unified?
A: Look for one access graph, one ownership model, and one offboarding path across human, NHI, and agent identities. If each identity class still needs a separate process to answer basic questions about privilege and retirement, the programme is still fragmented.
Technical breakdown
Unified access visibility across human and non-human identities
Access visibility is the control layer that shows what an identity can reach, how that access was granted, and where privilege accumulates over time. In mixed identity environments, the technical challenge is correlation across users, service accounts, tokens, and agent credentials so governance teams can see effective access rather than isolated entitlements. Without that graph, reviews and monitoring operate on partial data and miss inherited or indirect access paths.
Practical implication: build one access inventory that covers human, NHI, and agent identities before expanding review automation.
Lifecycle management for service accounts and AI agents
Lifecycle management applies to every identity type, but the events differ. Human identities have joiner-mover-leaver milestones, while service accounts and AI agents need creation, delegation, rotation, suspension, and offboarding events tied to workload or system changes. The article points toward a governance model where lifecycle is not an HR process alone, but a control plane for all active identities and their permissions.
Practical implication: define offboarding triggers for non-human and autonomous identities with the same rigour used for employee leavers.
Access reviews are shifting from periodic certification to continuous governance
Periodic access reviews work when entitlements are relatively stable and the review cycle can catch privilege drift in time. In environments with frequent application changes, ephemeral automation, and delegated access, governance needs continuous monitoring plus event-driven review logic that can detect when access changes faster than the certification cadence. That does not replace formal recertification, but it changes what can be reliably governed by cadence alone.
Practical implication: use continuous monitoring to feed access reviews so high-risk access is visible before the next certification cycle.
NHI Mgmt Group analysis
Identity governance is converging on a single operating model across humans, NHIs, and AI agents. Veza’s product direction reflects a broader market shift away from separate tooling for each identity class. That convergence is being driven by the reality that access paths now cross people, service accounts, and autonomous systems in the same workflows. Practitioners should treat governance architecture as shared infrastructure, not a set of parallel point solutions.
Access visibility is becoming the prerequisite control for modern governance. Without a complete view of effective access, lifecycle management and access review programmes remain incomplete by design. The most important governance question is no longer whether an entitlement exists, but whether the organisation can explain how it exists, who or what owns it, and when it should disappear. That is the standard now needed for NHI and agentic access as well as human IAM.
Lifecycle management has to be recast as identity-state governance, not user administration. Service accounts, tokens, and AI agents do not follow employee lifecycles, but they still create ownership, renewal, and offboarding obligations. The operational implication is that teams need one governance model that can express state changes for every identity type without assuming a human employment event as the trigger.
Cross-domain governance is the named concept now emerging: unified identity control plane. The practical idea is simple. If visibility, monitoring, requests, and lifecycle controls sit in different systems, the organisation cannot govern access consistently across identity types. The implication is not another dashboard, but a more coherent control architecture for access decisions, accountability, and remediation.
AI agent and NHI governance will be judged by whether they fit existing IGA discipline. The market signal here is not that autonomous or machine identities are special cases forever. It is that identity teams now need a durable way to classify, review, and retire access regardless of whether the identity is human, workload-driven, or autonomous. That will reshape how IAM, IGA, and PAM programmes are scoped.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: Top 10 NHI Issues
What this signals
Unified identity control plane: the operational shift is from separate workflows for people and machines to one control model that can explain effective access, ownership, and retirement across all identity types. That matters because governance failures now happen at the seams between systems, not just inside them.
Access review cadence remains useful, but only when continuous monitoring feeds it with current identity state. In mixed environments, the decisive issue is whether the organisation can see access change soon enough to govern it before the next certification window closes.
For practitioners
- Define one governance model for all identity types Map human users, service accounts, tokens, and AI agents into a single access governance model so ownership, review cadence, and offboarding rules are consistent across the estate.
- Inventory effective access, not just assigned entitlements Correlate direct grants, inherited permissions, delegated access, and machine credentials to expose the real blast radius of each identity.
- Tie lifecycle events to non-human identity state changes Create explicit triggers for creation, rotation, suspension, and retirement of service accounts and agent identities when workloads or integrations change.
- Use continuous monitoring to inform access reviews Feed monitoring data into certification workflows so that stale access, privilege drift, and unexpected non-human usage surface before periodic review windows close.
Key takeaways
- Identity governance is moving toward a shared control model that covers humans, service accounts, tokens, and AI agents together.
- The hardest problem is no longer adding more identity features, but proving who owns access and when it should end across different identity classes.
- Practitioners should align visibility, lifecycle, and review processes so non-human access is governed as consistently as human access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article stresses lifecycle and offboarding control across non-human identities. |
| NHI-05 — Overprivileged NHI | The roundup centres on access visibility and governance of non-human privilege. | |
| Recommendation — Map service account and agent retirement processes to NHI-01 and remove access when identity ownership ends. Review effective access for NHI-05 and reduce standing privilege across service accounts and tokens. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing entitlements across all identity types. |
| Recommendation — Apply PR.AA-05 to keep entitlements visible, reviewable, and removable across human and machine identities. | ||
| CIS Controls v8 | CIS-5 — Account Management | The governance themes depend on disciplined account lifecycle and ownership management. |
| Recommendation — Use CIS-5 to standardise account creation, review, and removal for users and non-human identities. | ||
| MITRE ATT&CK | TA0006 — Credential Access | Non-human credential governance is central to preventing misuse of access paths. |
| Recommendation — Track service account and agent credential exposure under TA0006 and prioritise the identities with the broadest blast radius. | ||
Key terms
- Unified Control Plane: A unified control plane is an identity architecture where discovery, access governance, audit, and response operate across humans, machines, and AI agents together. It reduces blind spots caused by siloed tooling and gives security teams context for decisions about permissions, data, and containment.
- Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
- Lifecycle Management: Lifecycle management is the process of creating, reviewing, rotating, and retiring identities and their secrets in a controlled way. For NHIs, it is essential because stale credentials, orphaned accounts, and incomplete offboarding are common paths to long-lived exposure and unauthorised access.
- Access Review Cadence: The schedule at which an organisation rechecks whether access is still justified. In GDPR programmes, cadence is not administrative detail, because access can become non-compliant as soon as business need changes. For NHI and delegated access, cadence must be tight enough to catch drift before it becomes exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org