TL;DR: Security operations now depend on effective permissions, not just authentication, according to Veza. That shift matters because containment fails when teams cannot map blast radius fast enough or prove least-privilege changes with audit evidence, and Veza positions its Access Graph, Access AI, VQL, and Actions as the operational layer for finding, interrogating, and changing access across human and non-human identities.
At a glance
What this is: This is Veza’s argument that identity security should function as an operational control plane, with access graphs, query tools, and action workflows tied to incident response.
Why it matters: It matters because IAM, PAM, NHI, and SOC teams need a defensible way to map effective permissions quickly, contain access precisely, and prove that least-privilege changes were applied.
Context
Security operations break down when teams can see authentication events but cannot answer the harder question of effective access. In practice, containment depends on knowing who can act on which data, through which inherited rights, and with what audit evidence.
Veza’s article argues that identity security has to be treated as a live control plane rather than a static inventory. That framing spans human users and non-human identities, because service accounts, tokens, and workloads expand blast radius just as quickly as human over-privilege when access is not continuously governed.
Key questions
Q: How should security teams use effective permissions in incident response?
A: Teams should resolve effective permissions first, then make containment decisions based on reachable data and actions rather than on directory membership alone. That prevents over- or under-scoping, especially where access is inherited through groups, roles, or data policies. The goal is a revocation decision that is both precise and auditable.
Q: Why do service accounts and workloads increase blast radius so quickly?
A: They often carry persistent or inherited access across multiple systems, so one compromised identity can expose many resources at once. If ownership, scope, and usage are unclear, the organisation cannot separate legitimate automation from excessive entitlement. That is why non-human identity hygiene is a response issue, not just an inventory issue.
Q: What signs show that identity security posture management is not operational?
A: The clearest signs are slow blast-radius mapping, manual approval bottlenecks, and remediation records that do not line up with the access change that actually happened. If the programme can find toxic access but cannot drive controlled revocation with evidence, it is still a reporting function, not an operational one.
Q: How do security operations teams contain identity-led incidents without losing audit evidence?
A: They should route every scope reduction through approved change workflows, attach the access rationale, and preserve the before-and-after entitlement state. That keeps containment defensible for auditors and useful for post-incident hardening. Without that evidence chain, the team may recover access but lose governance.
Technical breakdown
Access graphs as the source of effective permissions
An access graph models identities, groups, roles, policies, ACLs, and resource metadata together, then resolves them into effective permissions. That matters because the security question is rarely “who is assigned what?” but “what can this identity actually do right now, including inherited rights?” For SOC use, the graph becomes the evidence layer for triage, blast-radius analysis, and post-incident hardening. It also reduces ambiguity across cloud and data platforms where permissions are distributed across multiple policy systems. The practical value is not visualisation alone, but a defensible map of actionable access.
Practical implication: treat the access graph as the control source for containment decisions, not as a reporting layer.
Query-driven investigation with Access AI and VQL
Natural-language query and path-aware query language solve different operator problems. Natural language accelerates first-pass investigation, while a structured query language is needed when analysts must prove inherited access, traverse paths across policies, or isolate a specific data estate. In identity-led incidents, speed without precision creates false confidence, while precision without speed delays containment. A mature SecOps workflow needs both because permission reasoning is a search problem and an evidence problem at the same time. The technical point is that effective permissions must be interrogable, not just stored.
Practical implication: pair conversational investigation with deterministic queries so analysts can move from suspicion to evidence without changing tools.
Actions that turn authorization truth into enforced change
The operational gap in many identity programmes is not detection but execution. Once a risky permission path is identified, teams still need a safe way to scope access, revoke rights, open approvals, notify owners, and capture evidence across ITSM, SOAR, and chat tools. That is what turns identity intelligence into containment. Without the change layer, even perfect visibility leaves the organisation dependent on manual follow-up and brittle handoffs. The architecture matters because authorization truth only becomes security value when it can drive controlled remediation. Practical implication: connect permission analysis to governed change pathways before the next incident exposes the gap.
Practical implication: wire entitlement review to approval-backed change workflows so containment can be enforced, not merely recommended.
Threat narrative
Attacker objective: The objective is to use legitimate or compromised access to reach sensitive data and operations before defenders can understand the effective permission scope.
- Entry begins when a compromised or high-risk identity is detected through security tooling, but the real challenge is determining its effective permissions rather than its login history.
- Escalation occurs when inherited rights, over-privileged service accounts, or broad data access expand the reachable blast radius across cloud and data systems.
- Impact follows if the organisation cannot scope, revoke, and document least-privilege changes fast enough to contain the affected data and preserve audit evidence.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity security is becoming a control plane because effective permissions, not authentication alone, decide operational risk. The industry still talks about login events as though authentication were the main boundary, but most material damage happens after access is granted and inherited. That means SOCs need an operational model that can answer who can do what, on which object, with what evidence. The practitioner conclusion is clear: access truth must sit inside the response workflow, not beside it.
Blast-radius analysis is now the decisive identity security use case. When teams cannot translate identity state into affected data and actions quickly, containment becomes a guess. That is especially true in estates where human users, service accounts, tokens, and workloads all contribute to effective permissions. The practitioner conclusion is to organise identity data around reachable impact, not around directory convenience.
Non-human identity exposure is a governance problem and a SecOps problem at the same time. Orphaned service accounts, long-lived tokens, and unowned workload access turn the attack surface into a moving target. The control failure is not simply too much access, but access that cannot be scoped fast enough to prove ownership and enforce change. The practitioner conclusion is to treat NHI hygiene as a live containment input.
Identity Security Posture Management becomes operational only when it can drive action with evidence. Finding toxic access is not enough if approvals, change records, and audit trails remain disconnected from the remediation step. Veza’s model reflects a broader market shift toward identity visibility and intelligence platforms that connect analysis to execution. The practitioner conclusion is to evaluate whether your identity stack can both explain and change access in the same workflow.
From our research library:
- 96% of security operations teams report critical blind spots, most commonly in cloud infrastructure (74%) and identity and access behaviour (67%).
- Read next: Ultimate Guide to NHIs — Key Research and Survey Results
What this signals
Identity-led containment now depends on proving reachable impact, not simply identifying an account. Programme owners should expect SOC workflows to move from user-centric alerting toward permission-centric investigation, especially where cloud data and NHI estates intersect. The practical pressure point is the ability to translate an alert into scoping evidence before containment stalls.
Effective permissions will become the shared language between IAM, PAM, and SecOps. If the organisation cannot answer who can do what to which data in a way responders trust, access reviews and incident response will keep operating on different timelines. That gap is where identity-led breaches turn into prolonged exposure.
Access graph thinking will matter most where non-human identities outnumber humans. In those environments, the question is not whether you have inventories, but whether you can isolate which permissions are still active, why they exist, and how quickly they can be removed without breaking operations.
For practitioners
- Map effective permissions before containment Require incident responders to resolve inherited rights, ACLs, and role-based paths before revocation decisions are made.
- Separate fast triage from precise querying Use rapid natural-language investigation for first-pass scoping, then pivot to path-aware queries when you need evidence on specific entitlements.
- Link access findings to governed change Route scoping, revocation, approvals, and owner notification through ITSM or SOAR so the containment step produces an auditable record.
- Inventory and de-scope high-risk non-human identities Identify orphaned service accounts, long-lived tokens, and unused workload access, then assign ownership before the next incident forces cleanup.
- Track time-to-know and time-to-contain Measure how long it takes to build a blast-radius map and enforce least privilege after an alert so the programme exposes response friction.
Key takeaways
- Identity security becomes operational when teams can turn permissions data into containment decisions instead of treating it as a reporting artefact.
- The main risk is not just excess access, but the inability to map blast radius and enforce least privilege fast enough to matter during an incident.
- Programmes that connect identity analysis to governed change will contain incidents more cleanly and preserve the evidence chain needed for audit and recovery.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article focuses on excessive effective permissions across non-human identities and workloads. |
| NHI-07 — Long-Lived Secrets | Tokens and long-lived non-human access are named as a cleanup target in the SecOps model. | |
| NHI-03 — Vulnerable Third-Party NHI | The article’s control plane model applies to third-party identities that expand blast radius across systems. | |
| Recommendation — Audit non-human identity entitlements for over-privilege and reduce reachable access before incidents force containment. Inventory long-lived secrets and move high-risk non-human credentials to shorter-lived, governed access paths. Review third-party non-human access paths and revoke any external entitlements that are not actively owned. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The piece is fundamentally about authorised access, effective permissions, and the ability to change them quickly. |
| Recommendation — Apply PR.AA-05 to govern entitlements centrally and validate that access changes are enforceable during response. | ||
| MITRE ATT&CK | TA0006;TA0040 — Credential Access; Impact | The article’s breach logic centres on credential-led reach and the resulting operational impact if access is not contained. |
| Recommendation — Map identity-led incidents to credential access and impact so containment priorities follow reachable damage. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The article describes cloud identity visibility and control across policies, roles, and permissions. |
| Recommendation — Use the IAM domain to align entitlement visibility, approvals, and revocation across cloud services. | ||
Key terms
- Effective Permissions: Effective permissions are the access an identity can actually use after role inheritance, scope, and policy are applied. In Azure AI environments, they often matter more than the assigned role name because inherited rights can widen access to data, logs, and secret stores.
- Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
- Identity Security Posture Management: Identity security posture management is the continuous assessment of identity configuration, privilege, and exposure across an environment. It focuses on drift, overprivilege, and control gaps so teams can see where IAM, PAM, and NHI governance are failing before those gaps become incidents.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org