By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: VezaPublished January 11, 2026

TL;DR: A wider shift toward unified access visibility, monitoring, lifecycle management, and NHI and AI agent governance across identity programmes is highlighted in Veza’s 2025 product innovation roundup. For practitioners, the signal is less about feature volume than about the convergence of governance controls around all identity types, including non-human and autonomous access.


At a glance

What this is: Veza’s product innovation roundup frames access visibility, monitoring, lifecycle management, and NHI and AI agent security as converging identity governance priorities.

Why it matters: It matters because IAM, IGA, PAM, and NHI teams are now being asked to govern the same access estate across human users, service accounts, and AI-driven identities.

👉 Read Veza's 2025 product innovation update on identity governance and NHI security


Context

The core governance problem is no longer whether identity teams can see access in one system. It is whether they can continuously understand who or what has access, why that access exists, and when it should be removed across human and non-human identities. In that environment, NHI protection and agentic AI governance become extensions of identity security rather than separate projects.

Veza’s 2025 product innovation theme reflects that convergence, with attention on access search, intelligence, monitoring, reviews, lifecycle management, and NHI and AI agent controls. The practitioner question is not whether the surface area is expanding, but whether current IAM and IGA operating models can keep pace with machine identities, delegated access, and increasingly dynamic runtime behaviour.


Key questions

Q: Why do service accounts and AI agents need different controls from human users?

A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.

Q: Why do lifecycle models break down for non-human identities?

A: Because NHI lifecycles are driven by workload change, application retirement, vendor relationships, and key expiry rather than employee movement. If offboarding remains tied to HR events or quarterly reviews, credentials outlive their business purpose and remain usable long after they should have been revoked.

Q: What do security teams get wrong about AI agent identity governance?

A: They often assume human IAM patterns can be reused with minor adjustments. That fails because agents can invoke tools dynamically, operate continuously, and combine multiple systems in one session. Governance has to focus on runtime scope, delegated identity, and revocation, not just authentication.

Q: Should organisations unify NHI, IGA, and PAM workflows?

A: Yes, where effective access overlaps. The main reason is operational: privileged access, lifecycle review, and non-human entitlement management are increasingly describing the same risk surface. Unification does not mean one tool for everything. It means one governance model for who or what can reach sensitive systems and data.


Technical breakdown

Access visibility across human and non-human identities

Access visibility is the ability to answer who has access to what, through which relationships, and under which effective permissions. In modern environments, that means modelling direct entitlements, inherited access, group membership, delegated permissions, and application-level authorisation across SaaS, cloud, and infrastructure. For NHI estates, the challenge is harder because service accounts, API keys, tokens, and certificates often have no human owner in the traditional sense. Without a unified access graph, reviews become partial and revocation becomes reactive.

Practical implication: build a single access inventory that includes NHIs, effective permissions, and ownership metadata before relying on access reviews.

Lifecycle management for identities that do not behave like users

Lifecycle management covers provisioning, change, certification, and offboarding, but the process behaves differently when the identity is a service account or AI agent. Human identity processes assume employment events and review cadences. NHI lifecycles instead depend on application change, workload retirement, key expiry, environment migration, and relationship changes with vendors or upstream systems. If those events are not tied to revocation, credentials persist after their business purpose disappears, creating orphaned access.

Practical implication: connect NHI lifecycle triggers to application and workload events, not just HR or calendar-based recertification.

AI agent security and runtime authorisation

AI agent security introduces a different question from standard automation. An AI agent is only autonomous when it can choose actions, select tools, and decide timing without human approval gates. That means authorisation cannot be treated as a one-time provisioning event if the agent can change its own execution path during a session. Traditional IAM assumes stable intent and bounded execution. Autonomous behaviour breaks that assumption, so governance has to account for tool use, scope drift, and approval bypass at runtime.

Practical implication: separate static access assignment from runtime authorisation controls for any AI system that can act without human approval.



NHI Mgmt Group analysis

Access governance is collapsing into one operating model across human and non-human identities. The product direction here reflects a broader market reality: IAM, IGA, PAM, and NHI controls can no longer be managed as separate programmes. The decisive issue is effective access, not identity type. Practitioners should expect governance tooling to converge around the access graph because that is where human entitlement, service account privilege, and delegated AI access now intersect.

Lifecycle controls fail when they are still tied to human change events. Joiner-mover-leaver models were designed for employees and contractors, not for service accounts that outlive applications or AI agents that can be instantiated, repurposed, and retired by systems. The implication is not simply to add more review cadence, but to recognise that non-human lifecycle ownership must track workload and application state. Identity governance programmes that ignore that distinction will continue to certify stale access instead of removing it.

Runtime authority is becoming the new boundary for agentic AI governance. Static entitlement alone does not describe risk when an AI agent can choose tools and execution timing after launch. That creates a governance gap between the moment access is granted and the moment it is exercised. Practitioners should treat runtime authorisation as a separate control plane for autonomous behaviour because provisioning-time approval no longer captures actual exposure.

Named concept, identity blast radius: The practical goal is to reduce how far any single human, service account, or AI agent can move once it has access. Access intelligence, monitoring, and recertification all matter, but only if they reveal where privilege concentrates and where delegated access can spread across systems. The stronger the visibility, the smaller the blast radius. Teams should use this concept to prioritise review of the highest-impact identities first.

NHI and agentic AI controls are now a maturity test for the whole identity programme. Once machine identities and autonomous systems enter the same control environment as human access, organisations can no longer claim maturity if their governance only works for people. The market is moving toward unified identity control planes, and practitioners should measure themselves against that convergence rather than isolated tooling silos.

From our research:

What this signals

Identity teams should expect access intelligence to become the control plane for mixed identity estates. As human, non-human, and autonomous access converge, the programme that can explain effective permissions fastest will also be the one that can reduce risk fastest. That makes access graph quality a governance issue, not just a reporting issue.

Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs. That means most identity programmes are still operating with blind spots in the very accounts that often hold elevated and durable access. The practical consequence is that review cadence alone will not close the gap.

Identity blast radius becomes the right planning concept when access spans systems, vendors, and AI-driven actors. Teams should expect future governance roadmaps to prioritise ownership, revocation triggers, and runtime authorisation over broad policy language. The control objective is smaller exposure, not simply more documented access.


For practitioners

  • Map effective access across all identity types Consolidate entitlements, group memberships, delegated permissions, and application-level authorisation into one access inventory so reviews reflect effective access, not just recorded assignments.
  • Tie NHI offboarding to system change events Trigger revocation when applications, workloads, vendors, or integrations are retired or replaced, and do not wait for periodic reviews to remove stale service account access.
  • Separate runtime controls for autonomous systems Define a runtime authorisation layer for AI agents that can choose actions or tools independently, and monitor for scope drift, approval bypass, and unexpected tool use.
  • Prioritise the identities with the largest blast radius Rank identities by the number of systems, datasets, and delegated privileges they can reach, then review the highest-risk accounts before broadening coverage to low-impact access.

Key takeaways

  • The core issue is not feature expansion, but identity governance convergence across humans, NHIs, and AI agents.
  • Most organisations still lack complete visibility into machine accounts, which leaves lifecycle and review processes operating with incomplete data.
  • Practitioners should align access intelligence, offboarding, and runtime authorisation to the actual actor type, not to a generic identity workflow.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on visibility and governance gaps for non-human identities.
OWASP Agentic AI Top 10AI agent security is explicitly part of the article's product scope.
NIST CSF 2.0PR.AA-1Identity and access management alignment fits access governance and authorization outcomes.
NIST Zero Trust (SP 800-207)4.2Continuous verification and least privilege align with unified access governance.
NIST SP 800-53 Rev 5AC-2Account management is directly relevant to lifecycle, access review, and revocation workflows.

Use OWASP-NHI to assess where machine identities are missing ownership, visibility, or lifecycle controls.


Key terms

  • Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
  • Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

What's in the full article

Veza's full product update covers the operational detail this post intentionally leaves for the source:

  • How Access Graph, Access Intelligence, and Access Monitoring are positioned across identity review workflows
  • How NHI Security and AI Agent Security are organised inside the broader platform for practitioner use
  • How Access Reviews and Lifecycle Management are intended to support access governance decisions
  • How integrations and use-case packaging are grouped for teams evaluating operational deployment

👉 Veza's full update covers the product structure behind access visibility, lifecycle management, and AI agent governance

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org