TL;DR: Gartner’s 2025 PAM Magic Quadrant now treats machine scenarios, workload identity, and secrets management as expected capabilities, reflecting a market shift that still leaves human-built PAM controls misaligned with workload access patterns, according to Aembit. The governance gap remains structural: access review, session recording, and vault checkout were designed for people, not ephemeral machine identities.
At a glance
What this is: This analysis argues that PAM has expanded to cover machine scenarios, but workload IAM is still needed because human-centric privileged access controls do not match ephemeral workload behaviour.
Why it matters: IAM and PAM teams need to treat machine access as a distinct governance problem because service accounts, pipelines and AI agents do not fit approval, session and vault-based models built for people.
By the numbers:
- Machine identities outnumber human identities by 82 to 1 in enterprises, according to CyberArk’s 2025 Identity Security Landscape.
- The 2025 Gartner PAM Magic Quadrant treats PAM for machines scenarios, workload identity and secrets management as expected capabilities.
- The 2024 Gartner report described PAM vendors as beginning to address nonhuman identities.
- CyberArk found that 42% of machine identities already hold privileged or sensitive access.
Context
Privileged access management was designed for named people, interactive sessions and accountable approvals. That model breaks down when the identity is a workload that authenticates at machine speed, exits after seconds and never waits for a manager to approve a vault checkout. Workload IAM emerges because the access problem has changed, not because the old problem disappeared.
The primary governance gap is not just tooling overlap but control fit. PAM can still govern human administrators, but machine identities, CI/CD jobs and AI agents require attested identity, short-lived access and policy evaluation at request time. Once privileged access includes non-human actors, access governance becomes a lifecycle and runtime issue as much as a secrets issue.
Key questions
Q: What breaks when PAM is used as the primary control for workload access?
A: PAM breaks down when it assumes a human operator, because workloads do not wait for approvals, do not need interactive sessions and often live only for seconds. The result is brittle vault checkout, weak accountability and controls that fit people better than machine identities. Workload IAM is needed where access must be issued and judged in real time.
Q: When should organisations prioritise workload IAM over extending PAM?
A: Organisations should prioritise workload IAM when privileged access is driven by CI/CD, cloud workloads or AI agents that need fast, repeatable access without human interaction. Extending PAM can help at the margins, but the architectural fit is weaker when the identity is ephemeral and the decision must happen at request time.
Q: What are the signs that secrets-based workload access is no longer working?
A: Warning signs include credentials embedded in code or pipelines, broad vault checkout patterns, frequent environment-specific exceptions and access decisions that are still tied to people rather than workloads. If revocation, rotation and approvals lag behind execution speed, the control model is already behind the workload estate.
Q: How should teams govern AI agents that act inside customer accounts?
A: Treat them as delegated non-human identities, not as ordinary customer sessions. Governance should require explicit consent, narrow authorization scope, token binding, and a complete audit record tying each action back to the human principal that approved it.
Technical breakdown
Why human PAM primitives do not map to workloads
Traditional PAM assumes a person who can wait for approval, complete MFA and work inside a visible session. Workloads do none of that. A container, pipeline job or Lambda function may need access for seconds, may fan out across multiple services and may never present a conventional session to record. Vaulting a credential does not solve identity assurance or request-time authorisation. The control problem shifts from session management to runtime proof of identity and policy enforcement at the moment access is issued.
Practical implication: Treat workload access as runtime authorisation, not as vaulted human-style privileged session management.
How attested, secretless authentication changes machine access
Workload IAM replaces stored secrets with attested identity signals from the runtime environment. Instead of checking a credential out of a vault, a service proves where it is running and receives a short-lived credential only for the requested action. That reduces secret exposure, limits replay value and lets policy depend on workload context such as environment health, cluster state or source location. The important shift is that the credential no longer exists as a durable asset to protect; it is issued only when the identity and context justify it.
Practical implication: Move sensitive workloads toward attestation-based issuance so access is bound to the live runtime context.
Why AI agents intensify the workload IAM gap
An AI agent is not merely another automated job. In this article’s framing, it acts on behalf of a user while carrying delegated authority, which makes it a machine identity with human implications. Session-centric PAM struggles here because the agent is not a person, yet it is also not a static background service. Workload IAM handles that distinction better by authenticating the agent under its own identity and evaluating the user’s delegated authority separately at request time. That separation matters because the agent’s access behaviour can change during execution.
Practical implication: Model AI agents as machine identities with delegated authority and govern them with request-time policy checks.
Threat narrative
Attacker objective: The objective is to turn workload access into durable reach across sensitive systems before human-centric PAM controls can intervene.
- Entry begins when a workload, pipeline job or AI agent obtains access through a long-lived secret, vault checkout or delegated credential that was designed for human use.
- Credential abuse follows when the secret can be reused across services, environments or API calls without request-time revalidation.
- Escalation occurs when privileged access is broader than the workload’s immediate task, letting the actor reach downstream systems that were never meant to share the same control path.
- Impact is unauthorized access to sensitive systems, with machine-speed execution making human approval, session review and after-the-fact revocation too late to contain the exposure.
Breaches seen in the wild
- reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Human PAM controls were built for accountable operators, not autonomous workloads. Vault checkout, session recording and approval routing assume a named person who can tolerate delay and be reviewed after the fact. That assumption collapses when the identity is a pipeline job, container or AI agent acting at machine speed. The implication is that access governance for non-human actors must be judged by issuance-time control fit, not by how well it imitates human administration.
Workload IAM is not a feature layer inside PAM, it is a distinct governance pattern. PAM still has a clear role for human privileged access, but the article shows that ephemeral machine access depends on attestation, short-lived credentials and policy at request time. This is the right split because the control objective changes from managing sessions to governing runtime identity behaviour. Practitioners should stop treating machine access as a variant of human privilege.
Machine identity scale has crossed the threshold where human-only privilege models are structurally incomplete. With machine identities already outnumbering people by large multiples and AI agents joining the access estate, the privileged identity perimeter is no longer a person-centric concept. The practical consequence is that entitlement, review and offboarding models must include workloads as first-class governed actors. Teams that keep privileged identity definitions human-only will under-govern the largest part of the access surface.
Ephemeral access creates an identity blast radius problem, not just a secrets problem. A short-lived credential may reduce exposure time, but it does not by itself answer who the workload is, whether it should act now, or whether its authority is broader than the task requires. That is why the governance discussion has moved from storage and rotation into lifecycle, policy and context. Practitioners should align controls to the duration and scope of machine action, not just to secret hygiene.
Workload IAM narrows the machine access gap by making access decisioning conditional on live context. The article’s most useful signal is that central policy only matters when it evaluates the current state of the workload, environment and request. That changes the governance question from who owns the secret to whether the workload should be trusted right now. Identity teams should re-centre control design on request-time trust rather than static credential custody.
From our research library:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Workload IAM changes the control question from who checked out a secret to whether the workload should receive access right now. That shift matters because human-style approval and recording controls do not survive the speed and ephemerality of modern pipelines, containers and AI agents. The governance burden moves upstream into issuance, context and identity proofing.
Identity blast radius becomes the more useful operating concept than secret storage alone. If a credential can be issued per request and expire quickly, the main risk is no longer just leakage but over-scoped authority at the moment of use. Teams should focus on how much reach a workload has before it is allowed to act.
AI agents intensify the same problem because delegated machine access can outlive the human decision that authorised it. Only 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey. The implication is straightforward: access governance must be designed for runtime delegation, not just static entitlement.
For practitioners
- Define machine privilege separately from human privilege Update your privileged identity model so service accounts, pipelines, workloads and AI agents are governed as non-human identities rather than hidden under a human-only privileged user definition.
- Prioritise attested identity for sensitive workloads Start with production databases, identity providers, payment systems and cloud control planes, then replace secret checkout with attestation-based access where the exposure risk is highest.
- Limit access to short-lived, task-scoped credentials Issue credentials at request time with a narrow scope and rapid expiry so a stolen machine credential has little reuse value across services or environments.
- Centralise policy across cloud and on-premises access paths Apply one policy layer across AWS, Azure, GCP, SaaS and internal systems so workload access decisions are consistent when identities move between environments.
Key takeaways
- PAM still governs human privilege well, but workloads and AI agents expose a structural mismatch between interactive controls and machine-speed access.
- Machine identities are now large enough in scale and scope that human-only privilege definitions leave the biggest part of the access estate under-governed.
- The practical control shift is toward attested identity, short-lived credentials and request-time policy for non-human access paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on machine access scope that exceeds what workloads need. |
| NHI-07 — Long-Lived Secrets | Vaulted and scheduled secrets are the default model the article argues is breaking down. | |
| NHI-10 — Human Use of NHI | The article highlights delegated access where humans authorize machine action. | |
| Recommendation — Map workload access paths to NHI-05 and reduce standing privilege for machine identities. Use NHI-07 to replace long-lived machine secrets with short-lived issuance and tighter expiry. Separate human authorization from machine execution under NHI-10 when agents act on behalf of users. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle and rotation remain central to the machine access problem. |
| Recommendation — Apply IA-5 to govern authenticator issuance, rotation and revocation for non-human identities. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about access rights for workloads and AI agents. |
| Recommendation — Use PR.AA-05 to review and constrain workload entitlements before access is issued. | ||
Key terms
- Workload IAM: Workload IAM is the practice of applying identity and access management controls to software workloads instead of relying on static secrets. It uses platform-native identity, policy, and short-lived credentials so access can be verified, scoped, and audited without embedding long-term secrets in applications.
- Attested Identity: Attested identity is identity that is cryptographically backed by the environment running the workload. It shifts trust away from stored secrets and toward verified runtime conditions, which is essential when access is consumed by services or automation rather than by a person.
- Ephemeral Credentials: Ephemeral credentials are short-lived access artefacts issued for a limited task or session. They reduce the window for abuse, but they only improve security when paired with strong scope limits, telemetry, and automatic revocation at task completion.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org