By NHI Mgmt Group Editorial TeamBased on Veza: “Forrester Recognizes Veza for IGA, ISPM, and NHI/AI Identity Management” (January 15, 2026)

TL;DR: Workforce identity now spans humans, service accounts, and AI agents, while 0.01% of non-human identities control 80% of cloud resources and the average worker holds 96,000 entitlements, according to Veza. The governance problem is no longer visibility alone, but authorization, lifecycle control, and auditability across a sprawl of identities that conventional IAM models were never built to manage.


At a glance

What this is: This is a market analysis of workforce identity security platforms that argues identity has become the enterprise control plane as access spans humans, NHI, and AI agents.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes now have to govern authorization, entitlement sprawl, and audit evidence across mixed identity estates, not just human logins.


Context

Workforce identity security has moved beyond login control. The article argues that identity now sits at the centre of enterprise risk because organisations have to govern what humans, service accounts, machines, and AI agents can actually do across cloud, SaaS, and third-party environments.

For IAM and NHI teams, the governance gap is not visibility alone. The harder problem is turning fragmented identity data into enforceable authorization, lifecycle control, and audit-ready evidence before permission sprawl becomes identity debt.


Key questions

Q: Should organisations use the same controls for humans, NHIs, and AI agents?

A: No. The control family may overlap, but the operating assumptions differ. Human identity controls focus on authentication and user context, while NHIs need lifecycle and credential governance, and AI agents require both NHI controls and runtime oversight for autonomous action. The correct model is shared governance with actor-specific enforcement.

Q: Why does entitlement sprawl create more risk than simple account growth?

A: Account growth is a count problem, but entitlement sprawl is a control problem. Risk rises when identities accumulate overlapping permissions, inherited access, and dormant entitlements that remain valid long after the original business need has changed. That creates privilege creep, toxic combinations, and a much larger attack path than account volume alone suggests.

Q: What are the signs that identity governance is not working in practice?

A: Common warning signs are repeated access workarounds, ignored approval workflows, super admins holding too much power, and teams bypassing the process because it is too slow or hard to use. If access reviews are always behind, permissions stay stale, and IT has to chase owners for answers, governance is operating more as paperwork than control.

Q: When should organisations prioritise continuous identity evidence over quarterly access reviews?

A: Prioritise continuous evidence when identities change frequently, access is delegated across cloud and SaaS, or auditors need proof of control operation rather than policy intent. Quarterly reviews can still exist, but they should consume live evidence, not replace it. Continuous control is especially important where NHIs and AI agents can alter access faster than human review cycles.


Technical breakdown

Why workforce identity platforms shift control from authentication to authorization

Traditional IAM answers who a user or workload is, but workforce identity platforms are increasingly judged on what that identity can do after authentication. That shift matters because modern enterprises have many identities sharing overlapping access paths across apps, systems, and data. Once identity becomes the perimeter, the core control question is no longer just successful sign-in. It is entitlement scope, privilege inheritance, and whether access can be governed consistently across human and non-human actors.

Practical implication: map your highest-risk access decisions to authorization controls, not just sign-on controls.

How entitlement sprawl changes NHI and AI agent governance

The article highlights the scale problem behind workforce identity control. When a tiny share of NHIs controls a large share of cloud resources and workers hold massive entitlement sets, governance fails if access is managed as a collection of isolated approvals. Entitlement sprawl creates hidden privilege paths, toxic combinations, and persistent access that outlives the business need. AI agents make that harder because access may be delegated, reused, or amplified through automated workflows that operate faster than manual review cycles.

Practical implication: inventory entitlements by effective reach, not just by account count or provisioning source.

Why audit-readiness now depends on continuous identity evidence

The report frames compliance as a continuous evidence problem rather than a quarterly paperwork exercise. Manual spreadsheets cannot reliably prove dormant-account handling, separation of duties, third-party access review, or privilege creep remediation across modern identity estates. A workforce identity control plane has to produce operational evidence from the same access data it governs. That is what turns audit readiness into a live control state instead of an after-the-fact reporting task.

Practical implication: build identity evidence collection into daily operations instead of treating it as an audit project.


NHI Mgmt Group analysis

Workforce identity security is now an authorization problem, not an access-login problem. The article is right to move the control plane conversation beyond authentication because modern risk sits in what identities can do after they are accepted. That matters for humans, NHIs, and AI agents alike, but the governance lens is clearest when teams focus on effective permissions, not sign-in events. The implication is that identity programmes must be measured by authorization quality, not login success.

Permission sprawl is the new form of identity debt. The report’s emphasis on millions of entitlements and concentrated NHI control reflects a broader truth: enterprises accumulate access faster than they can govern it. Once permissions spread across SaaS, cloud, and delegated workflows, recertification alone cannot recover control. The implication is that identity teams must treat entitlement inventory and privilege scope as core risk indicators.

Continuous evidence is becoming a governance requirement, not a reporting feature. Auditors, insurers, and internal risk teams increasingly expect proof that access decisions are current, explainable, and enforceable. Manual reconciliation cannot keep pace with mixed human and machine identity estates, especially when access changes through automation. The implication is that identity governance must produce live control evidence, not periodic attestations.

Unified workforce identity platforms are converging on the same control-plane logic across humans, NHIs, and AI agents. That convergence is not a product trend alone; it signals that the enterprise has outgrown identity silos. The same governance patterns now need to cover joiner-mover-leaver control, privilege review, and delegated access across every actor type. The implication is that practitioners should evaluate whether their current stack can govern identity by function, not by subject type.

Identity security is becoming a board-level resilience issue because it now governs operational reach. When access defines what business systems can be touched, identity controls directly shape outage risk, fraud exposure, and breach blast radius. That makes workforce identity architecture part of enterprise control design, not just security tooling. The implication is that IAM, IGA, PAM, and NHI owners need a shared operating model.

From our research library:

What this signals

Identity control is moving from periodic governance to continuous enforcement. Security and IAM teams should expect the next phase of workforce identity programmes to be judged on whether they can prove access quality in motion, not after the fact. That is especially true where NHIs and AI agents can accumulate or shed privileges faster than human review cycles can respond.

The practical shift is toward policy, telemetry, and evidence living in the same operational loop. If an identity programme cannot show who can act, where the access came from, and when it was last validated, it will struggle to support both resilience and audit demands.


For practitioners

  • Define the workforce identity control plane Document which systems are authoritative for identity data, authorization decisions, review evidence, and revocation across humans, NHIs, and AI agents.
  • Baseline entitlement concentration Measure where a small number of identities control disproportionately large access surfaces, then rank those identities by business reach and privilege concentration.
  • Replace periodic review with continuous evidence Collect access, approval, and revocation evidence continuously so auditors can trace dormant accounts, toxic combinations, and third-party access without spreadsheet reconciliation.
  • Tie NHI and AI agent access to lifecycle ownership Assign accountable owners for non-human and agentic identities, and require every high-risk entitlement to have a revocation path tied to the owning business service.

Key takeaways

  • The article frames workforce identity as a control-plane issue because access decisions now span humans, NHIs, and AI agents.
  • The governance challenge is not only scale but the ability to prove and enforce authorization continuously across sprawling entitlements.
  • Practitioners should align identity data, review evidence, and revocation paths into one operating model before permission sprawl becomes unmanageable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centers on entitlement sprawl and concentrated access across machine identities.
NHI-09 — NHI ReuseWorkforce identity platforms are meant to reduce identity reuse across apps and delegated access paths.
Recommendation — Review NHI privilege scope and remove excessive access from identities that control broad resource sets. Detect reused credentials and shared identity patterns that blur ownership across services and workloads.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing entitlements and authorization across the workforce.
Recommendation — Align access permissions to business need and continuously validate authorizations across the identity estate.
CIS Controls v8CIS-5 — Account ManagementContinuous account and entitlement management is central to the report’s governance theme.
Recommendation — Maintain authoritative account inventories and revoke dormant or orphaned access promptly.
NIST Zero Trust (SP 800-207)Continuous verificationThe control-plane model depends on continuous verification of identity and authorization state.
Recommendation — Apply continuous verification to identity decisions instead of relying on point-in-time trust.

Key terms

  • Workforce Identity Security: Workforce identity security is the control layer that protects employee access across hiring, onboarding, support, role change, and offboarding. It combines identity proofing, access governance, and recovery controls so an attacker cannot exploit business processes to obtain or restore trusted access.
  • Entitlement Sprawl: The gradual accumulation of too many discrete permissions, often with overlapping access and unclear ownership. It makes access review noisy and offboarding fragile. Grouping entitlements into profiles is one way to reduce that sprawl, provided the groups are designed around real work patterns.
  • Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.
  • Continuous Identity: A governance model that turns identity data into live access decisions. Instead of relying on static approvals and periodic reviews, continuous identity reevaluates whether access should still exist based on current context such as risk, device state, ticket status, or business need.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org