By NHI Mgmt Group Editorial TeamBased on WorkOS: “Astrix Security vs. WorkOS: Non-Human Identity Meets Enterprise Authentication” (November 3, 2025)

TL;DR: Enterprise identity now requires two parallel layers: human authentication and machine identity governance, according to WorkOS. Astrix Security focuses on discovery, rotation, monitoring, and AI agent controls for the non-human identity layer, including API keys, service accounts, and OAuth tokens. The practical takeaway is that modern IAM programmes need separate control models for humans, workloads, and autonomous agents.


At a glance

What this is: This article argues that enterprise identity has split into distinct human and machine layers, and that AI agents now add a governed MCP authorization layer on top of the non-human identity problem.

Why it matters: IAM and PAM teams need separate control models for human users, service accounts, API keys, OAuth tokens and AI agents because the same governance patterns do not fit all identity types.

By the numbers:

  • for every human employee, there are roughly 100 non-human identities operating across cloud infrastructure, SaaS applications, and AI platforms.

Context

Modern enterprise identity is no longer a single access-control problem. Human users authenticate through one set of controls, while machine identities such as API keys, service accounts, OAuth tokens and workload identities require separate governance because they authenticate differently, live longer, and are often distributed across cloud, SaaS and AI environments.

The article’s main point is that the identity stack has split into two operational layers, with MCP authorization introducing a third governance concern for autonomous workloads. That matters because machine and agent credentials create a larger attack surface than user logins, and legacy IAM programmes often treat them as if they were the same problem.


Key questions

Q: What breaks when non-human identities are governed like human users?

A: Lifecycle triggers, ownership, and review processes stop working because machine identities do not generate joiner, mover, or leaver events. Access can persist after the original purpose disappears, leaving valid credentials outside normal certification paths. That creates a blind spot where privileged access remains active even though nobody can clearly explain why it still exists.

Q: Why do service accounts and long-lived credentials undermine zero trust?

A: Service accounts and other long-lived credentials weaken zero trust because they create persistent access that attackers can reuse after a compromise. If credentials are broadly scoped or rarely reviewed, a single theft can expose data, applications, and administrative functions. Zero trust works best when access is continuously verified, tightly scoped, and removed when no longer needed.

Q: How should teams judge whether AI agent access is properly constrained?

A: Teams should look for whether the agent’s permissions are issued with narrow scope, short duration and explicit boundaries around which tools and resources it can use. If those controls are missing, the agent is effectively operating with reusable trust that can outlive the task it was meant to perform.

Q: What is the difference between machine-to-machine authentication and machine identity governance?

A: Authentication answers whether a machine can prove it is allowed in at the moment of connection. Identity governance answers who owns the machine identity, what it can access, how long it should exist, and how quickly it must be revoked. Practitioners need both, because strong authentication without lifecycle controls still leaves persistent trust paths.


Technical breakdown

Why machine identities behave differently from human accounts

Machine identities are not just user accounts by another name. They are credentials and principals used by software, infrastructure and integrations to call APIs, move data and trigger workflows without a person present. Their risk profile is defined by scale, persistence and distributed ownership: one environment can contain thousands of service accounts, tokens and secrets that authenticate far more frequently than employees do. That changes how access is governed because discovery, rotation, scope and offboarding become continuous control problems rather than periodic user administration.

Practical implication: treat machine identity inventory and lifecycle management as a separate operating model from employee IAM.

How NHI discovery, rotation and monitoring work as a control stack

A machine identity control stack usually starts with discovery, because teams cannot govern credentials they cannot see. From there, rotation reduces the value of leaked or stolen secrets, while behavioural monitoring looks for misuse such as unusual access locations, spikes in token use or dormant identities suddenly becoming active. The important point is that these controls work together. Discovery without rotation leaves exposure in place. Rotation without monitoring leaves abuse undetected. Monitoring without inventory leaves blind spots in ownership and scope.

Practical implication: build an inventory-first workflow that ties each secret, token or service account to an owner, purpose and renewal path.

What MCP authorization changes for AI agents

MCP authorization adds a standards-based access layer for AI agents and MCP servers, but it does not remove the underlying NHI problem. Agents still need scoped credentials, client registration, refresh controls and token verification, which means the security model shifts from static secrets to governed OAuth flows. The key architectural change is that agent access can be issued, inspected and constrained through authorization policy rather than embedded credentials alone. That is a material improvement in control surface, but it still depends on correct scope design and lifecycle governance.

Practical implication: apply OAuth 2.1 policy design to agents the same way you would to any other non-human workload.


Threat narrative

Attacker objective: The attacker wants persistent, broad access through non-human credentials that are harder to notice and govern than human logins.

  1. Entry occurs when machine credentials such as API keys, OAuth tokens or service-account secrets are discovered in pipelines, logs or application memory.
  2. Credential abuse follows when those identities are reused with broad or stale permissions that were never tightly scoped or rotated.
  3. Impact emerges when overprivileged or dormant machine identities are used to access cloud resources, SaaS data or AI workflows at machine speed.
  • Hugging Face Spaces breach 2024: Unauthorised access to Hugging Face Spaces may have exposed secrets users stored for AI apps; tokens were revoked and org tokens removed.
  • CrewAI Uncrew GitHub token exposure: A CrewAI provisioning error exposed an admin GitHub token for all its private repositories; Noma reported it and CrewAI fixed it in hours.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity governance has split into two control planes, not one. Human authentication and machine identity governance now solve different problems, with different lifecycles, owners and failure modes. Treating them as a single IAM programme creates blind spots around discovery, rotation and offboarding for credentials that never log in like a person does. Practitioners should design separate operating models for human access and NHI control.

Machine identity sprawl is now the baseline condition, not the exception. The article’s 100:1 ratio is a useful signal because it reflects how cloud, SaaS and AI platforms multiply credentials faster than teams can manually manage them. That scale changes the governance question from who is logged in to what can authenticate, where, and for how long. The implication is that inventory, ownership and renewal discipline must be foundational controls.

Autonomous agents expose a scope problem that classic access review was never built for. Least privilege was designed for access that remains stable long enough to be reviewed. That assumption fails when an AI agent can request, use and discard credentials inside a short task window while selecting tools and timing at runtime. The implication is that access governance for agents has to move toward issuance-time constraints and session-bound authority, not periodic certification.

MCP authorization is best understood as a governed interface, not a complete identity strategy. OAuth 2.1 for MCP can give teams a cleaner authorization layer for agents and server interactions, but it does not solve stale secrets, overprivileged machine accounts or shadow identities elsewhere in the estate. This separates protocol-level control from estate-level governance. Practitioners should avoid mistaking standardised agent auth for full non-human identity governance.

Ephemeral credential trust debt: The more teams rely on short-lived or dynamically issued credentials, the more they need assurance that ownership, scope and revocation are still enforceable across every machine identity. Without that, temporary access becomes temporary only in theory, not in governance. That is the real operational gap this article exposes.

From our research library:

What this signals

Machine identity governance is becoming a first-class programme, not a subtask of IAM. As cloud, SaaS and AI systems multiply credentials faster than teams can review them, the control question shifts from user access to ownership and lifecycle for every secret, token and service account. Programmes that still treat NHI control as an edge case will miss the highest-volume part of the estate.

Identity convergence now means governing humans, NHIs and agents on different timelines. Human access can still be managed through login assurance and role governance, but machine and agent identities need issuance-time controls, rotation discipline and behavioural monitoring. The practical signal for practitioners is that convergence does not mean identical controls; it means coordinated control planes.

Epicenter of trust debt: when ephemeral credentials, OAuth grants and embedded secrets expand faster than offboarding and review processes, the organisation accumulates trust that no one can easily account for later. That is the point at which visibility, revocation and ownership become the decisive controls.


For practitioners

  • Map the machine identity estate Inventory API keys, service accounts, OAuth grants, workload identities and automation credentials across cloud, SaaS and AI systems. Tie each one to an owner, purpose, expiry and offboarding path so the estate can be governed as a lifecycle rather than a pile of secrets.
  • Separate human and non-human governance Run human authentication, role assignment and login assurance as one control plane, and NHI discovery, rotation and monitoring as another. This prevents employee IAM processes from being stretched across credentials that do not behave like user accounts.
  • Constrain agent access at issuance time Issue AI agent credentials with narrow scopes, short lifetimes and explicit tool boundaries, then verify token use against those constraints. The goal is to prevent agents from carrying broadly reusable access into unrelated tasks.
  • Monitor for stale and dormant privileges Flag service accounts, OAuth grants and integration secrets that have not been used recently but still retain active permissions. Dormant access is often the easiest path to unnoticed misuse because it escapes normal user-centric review cycles.

Key takeaways

  • Machine identities now form a separate governance problem from human users, because their scale, persistence and access patterns do not fit employee IAM controls.
  • The article’s 100:1 ratio underscores that NHI sprawl is already large enough to dominate the operational identity risk surface in cloud-first environments.
  • Practitioners need split control models for humans, non-human identities and AI agents, with lifecycle management and scoped authorization at the centre.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centers on lifecycle gaps for service accounts, tokens and dormant machine identities.
NHI-05 — Overprivileged NHIOverprivileged service accounts and broad OAuth grants are called out as core risks.
NHI-07 — Long-Lived SecretsThe article highlights static API keys and long-lived OAuth grants as major exposure drivers.
Recommendation — Audit offboarding paths for every non-human credential and revoke access when the identity is no longer needed. Right-size scopes for service accounts, API keys and tokens to the smallest usable permission set. Replace long-lived machine secrets with short-lived credentials and enforce expiry where possible.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential lifecycle management is central to the NHI control stack described here.
Recommendation — Apply authenticator management controls to rotate, revoke and replace machine credentials on schedule.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe threat pattern described is credential misuse followed by movement through connected systems.
Recommendation — Map NHI abuse scenarios to credential access and lateral movement tactics in detection engineering.

Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Machine identity lifecycle: Machine identity lifecycle is the full governance process for a non-human identity from creation to retirement. It includes provisioning, access scoping, rotation, renewal, offboarding, and auditability, and it fails when any one of those steps is handled manually or inconsistently.
  • MCP authorization: MCP authorization is the control layer that decides whether an agent or client may use a specific tool in a specific context. In secure deployments, it must go beyond token claims and incorporate user identity, resource ownership, and policy at request time.
  • Long-Lived Secret: A long-lived secret is a credential, token, API key, or certificate that remains valid for an extended period without frequent renewal. In NHI environments, it creates durable exposure because one leaked secret can keep granting access long after the original use case has changed.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org