Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI identities: is your inventory and delegation model ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: At Identiverse, IAM practitioners argued that AI identities are not the core problem and that inventory, delegation, and access visibility are the real gaps, according to Hitachi ID. The discussion also reframed access reviews as a maturity signal rather than a governance outcome, while pointing toward just-in-time, task-scoped access for agents.

NHIMG editorial — based on content published by Hitachi ID: a live Identiverse discussion on AI identities, inventory, and delegation

Questions worth separating out

Q: How should security teams govern AI-assisted work that inherits human credentials?

A: Treat it as a delegated identity path, not a simple user session.

Q: Why do access reviews often fail to improve identity governance?

A: Access reviews fail when teams treat completion as success.

Q: What breaks when an AI agent is not part of identity inventory?

A: When an AI agent is not part of identity inventory, governance breaks at the point of discovery.

Practitioner guidance

  • Create a live inventory of AI-linked identities Enumerate agents, service accounts, tokens, certificates, and workload identities in one governed register with owner, purpose, and access scope.
  • Model agent access as delegated workload identity Assign task-scoped permissions to agents and avoid borrowing human credentials for machine execution.
  • Treat access reviews as a fallback control Use reviews where telemetry is incomplete, but track how many entitlements can be removed first and restored later without business interruption.

What's in the full article

Hitachi ID's full podcast episode covers the operational detail this post intentionally leaves for the source:

  • The full Identiverse conversation on how senior IAM practitioners are thinking about AI identity inventory and access visibility.
  • The live discussion of access review fatigue, revocation design, and why usage-based governance is replacing blanket certification.
  • The delegation versus impersonation framing for AI agents, including how task-scoped permissions change the audit model.
  • The unanswered audience questions that did not fit into the live session but matter for implementation planning.

👉 Read Hitachi ID's live Identiverse discussion on AI identities, inventory, and delegation →

AI identities: is your inventory and delegation model ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

AI identities are exposing an inventory problem, not a naming problem. The field keeps talking about agentic risk as if the label itself changes the control model, but the real issue is whether the organisation can enumerate what exists and what it can touch. Inventory is the precondition for governance across NHI, human, and autonomous workflows. Without it, access reviews, recertification, and least-privilege decisions are all built on partial information.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows why inventory-first governance is still the baseline problem.

A question worth separating out:

Q: When should organisations prefer revocation over blanket certification?

A: Organisations should prefer revocation when access can be removed safely and restored quickly without breaking operations. That approach exposes whether the control model is truly usage-based, while blanket certification usually hides unclear ownership and slow entitlement cleanup.

👉 Read our full editorial: AI identities expose the inventory gap in modern IAM governance



   
ReplyQuote
Share: