By NHI Mgmt Group Editorial TeamBased on Oasis Security: “What's Broken with Identity Management?” (May 1, 2026)

TL;DR: Non-human identities now outnumber human identities by 10 to 50 times, and the article argues that traditional IAM, PAM, and secret management tools were built for human-centric identity models that cannot keep up, according to Oasis Security. The real issue is not just scale but a governance model that cannot see ownership, usage, permissions, and lifecycle together.


At a glance

What this is: This is an analysis of why traditional IAM, PAM, and secret management controls break down under NHI sprawl, with scale, privilege concentration, and lifecycle visibility emerging as the central gaps.

Why it matters: It matters because IAM and PAM programmes that were designed around human identities can miss ownership, usage, and offboarding problems in service accounts, tokens, and keys, leaving broad enterprise exposure.


Context

Identity management still assumes a world where the identity subject is usually a person. That assumption breaks once the environment is dominated by service accounts, roles, secrets, tokens, and keys that act continuously across cloud, code, and automation pipelines.

NHI sprawl is a governance problem as much as a security one. When ownership, usage, permissions, and lifecycle are not visible together, teams can detect exposure but still fail to determine who can revoke, rotate, or retire the identity safely.

The article treats that mismatch as structural rather than accidental. Human-centric identity tools can still help at the edges, but they do not produce a complete control model for machine-scale identity estates.


Key questions

Q: What breaks when identity management is built mainly for humans but the environment is dominated by NHIs?

A: The control model breaks at ownership, review, and offboarding. Human IAM assumes a named person, a stable authentication pattern, and a manageable certification cycle, while NHIs are often created by platforms and embedded in workloads. That makes traditional reviews incomplete and leaves machine access unmanaged even when vaults and IAM tools are present.

Q: Why do highly privileged NHIs create more risk than simple account counts suggest?

A: Because privilege density determines blast radius. A single overprivileged service account, token, or role can unlock sensitive data, infrastructure changes, or business processes across multiple systems. The risk rises when several permissions combine into toxic combinations that are hard to see in isolated account views.

Q: How can organisations tell whether their NHI controls are actually working?

A: Look for reduced secret sprawl, fewer long-lived credentials, clear ownership records, and rapid offboarding when workloads are retired. If teams cannot account for where secrets live or whether they still work, the control programme is failing. Good NHI governance produces traceable access decisions, not just more tooling.

Q: Should organisations rely on secret managers alone to govern NHIs?

A: No. Secret managers are useful for vaulting and rotation, but they do not provide identity context, lifecycle status, or dependency mapping. Without those elements, organisations can protect a credential while still leaving the underlying machine identity overprivileged, unowned, or impossible to retire safely.


Technical breakdown

Why human-centric IAM breaks under NHI scale

Traditional IAM assumes a stable identity owner, a manageable review cycle, and an individual who can authenticate with human factors such as MFA. Non-human identities do not fit that model because they are created by platforms, embedded in workloads, and often replicated across environments faster than central teams can track them. Once the identity estate expands into service accounts, tokens, keys, and cloud roles, the control problem shifts from user access administration to lifecycle governance. The result is that entitlement lists, reviews, and vaults can all exist while the organisation still lacks a coherent picture of what each NHI is for, who owns it, and where it is used. Practical implication: treat NHI governance as a separate operational model, not as a human IAM extension.

Practical implication: treat NHI governance as a separate operational model, not as a human IAM extension.

Why secret managers do not solve identity governance

Secret managers protect credentials by storing and sometimes rotating them, but that is not the same as understanding the identity behind the secret. A vault can tell you that a token exists, yet still not tell you which workload uses it, what permissions it carries, or what resource it reaches. That is why vault-centric control can reduce exposure without resolving governance. The article’s point is that identity-aware management requires context: ownership, usage, privilege scope, and the downstream systems touched by the credential. Without that context, remediation becomes manual and fragmented, which is exactly where stale access and toxic combinations persist. Practical implication: pair secret handling with identity context and lifecycle tracking, not vaulting alone.

Practical implication: pair secret handling with identity context and lifecycle tracking, not vaulting alone.

Why NHI privilege concentration changes blast radius

The article highlights that organisations often have far more highly privileged NHIs than humans. That matters because machine identities are used to automate business processes, infrastructure access, and service-to-service operations, so one compromised credential can unlock more than a single user session. In practice, overprivileged NHIs create a large blast radius that is difficult to constrain with controls built around human login patterns. The risk is amplified when the identity estate contains toxic combinations, where multiple permissions together create an unintended path to sensitive data or operations. Practical implication: analyse NHI privilege as a system-wide blast-radius problem, not as isolated account hygiene.

Practical implication: analyse NHI privilege as a system-wide blast-radius problem, not as isolated account hygiene.


NHI Mgmt Group analysis

Human-centric identity management no longer matches the identity estate. The dominant failure is architectural: IAM programmes still organise control around people, while modern infrastructure is increasingly driven by machine identities. That mismatch means the programme can be operationally busy and still blind to the majority of access-bearing entities. The implication is that identity governance must be reset around the actual actor mix, not the historical default of human users.

NHI lifecycle blindness is the core governance gap. The article is strongest when it points out that ownership, usage, permissions, and accessed resources are often not held together in one control view. That is not a tooling inconvenience, it is a lifecycle failure that makes review, offboarding, and remediation partial at best. Organisations that cannot connect those data points are governing credentials, not identities.

Privilege density, not just identity count, defines the real exposure. The article notes that there can be materially more highly privileged NHIs than humans, which means the risk profile is shaped by concentration of access, not only volume. A large estate of low-risk identities is manageable in ways a smaller set of overpowered service accounts is not. Practitioners should focus on where machine privilege aggregates into operational dependency.

Secret vaulting is necessary but insufficient because it leaves context outside the control plane. Secret managers help store and rotate credentials, but they do not explain what the secret belongs to or what business process depends on it. That creates a governance gap where security teams can see the secret yet still not understand the identity’s ownership or blast radius. The practical conclusion is that NHI control has to be identity-aware, not credential-only.

NHI sprawl is becoming a business resilience issue, not just a security issue. The article connects incomplete visibility with the possibility of downtime during threat response and even routine maintenance. That means the cost of weak NHI governance is not limited to breach likelihood, because the same blind spots can interrupt critical operations. Teams need to evaluate NHI governance as an availability dependency as much as an access-control problem.

From our research library:

What this signals

Identity sprawl is now a lifecycle problem, not just an inventory problem. NHI programmes that stop at discovery will keep finding more credentials without reducing risk, because the real control point is whether each identity has a clear owner, privilege scope, and retirement path. That is why lifecycle management has to sit beside inventory, not after it.

Privilege concentration deserves its own control focus. A machine identity estate with far more high-privilege accounts than human accounts changes the way blast radius should be measured. The next governance step is to identify where application and infrastructure dependencies make revocation harder than exposure itself.

NHI governance cannot be reduced to vault hygiene. Secret storage and rotation remain necessary, but they do not resolve whether a credential is still legitimate, who depends on it, or what will fail if it is removed. Teams should align control design to the full identity lifecycle, not just the secret lifecycle.


For practitioners

  • Map the full NHI estate Inventory service accounts, roles, tokens, keys, and other non-human identities across cloud and enterprise systems, then classify them by ownership, privilege, and business function.
  • Link every NHI to an owner and purpose Require each machine identity to have a named owner, an explicit workload or application purpose, and a recorded dependency path so it can be reviewed or retired without guesswork.
  • Reduce overprivileged machine access Review highly privileged NHIs first, focusing on accounts that can reach sensitive systems or combine permissions into toxic combinations that widen blast radius.
  • Separate secret storage from identity governance Keep using vaults for credential storage, but add controls for usage tracking, access scope, and lifecycle status so a secret cannot outlive the identity it enables.
  • Build remediation paths for business-critical NHIs Create a response model that can rotate, suspend, or retire machine identities without taking dependent applications down during incident response or maintenance.

Key takeaways

  • NHI sprawl exposes a governance gap because human-centric IAM models do not fully describe machine identities, their ownership, or their lifecycle.
  • The article’s scale signal is stark: non-human identities now outnumber human identities by 10-50x, which expands the attack surface and increases privilege concentration.
  • The practical response is to govern NHIs as identities, not just secrets, with lifecycle, ownership, and privilege scope treated as first-class controls.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • NHI Sprawl: The uncontrolled growth of non-human identities such as service accounts, API keys, OAuth clients, and machine roles. It becomes a governance problem when ownership, purpose, rotation, and decommissioning are unclear, leaving dormant credentials active long after their original use case ends.
  • Toxic Risk Combinations: Toxic risk combinations are unsafe interactions between datasets, access permissions, and AI workflows that only become problematic when combined. Individually they may appear harmless, but together they can expose sensitive information, enable re-identification, or create unintended inferences that traditional controls may miss.
  • Identity-Aware Secret Management: Identity-aware secret management links a credential to the identity, ownership, usage, and lifecycle context behind it. This matters because vaulting a secret is not enough if the organisation cannot tell what workload uses it, what it reaches, or when it can be safely retired.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org