Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Veza’s 2025 access platform update: what changes for NHI teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Identity governance is shifting from simple visibility to operational governance, with 325+ integrations, AI-powered access review, NHI and AI agent inventory, MCP server discovery, and automated revocation workflows across human and machine identities, according to Veza. The real change is that identity governance is moving from static review to runtime accountability across NHI, human access, and emerging autonomous actors.

NHIMG editorial — based on content published by Veza: 2025 access platform round-up covering NHI, AI agent, and lifecycle governance

By the numbers:

Questions worth separating out

Q: Why do structured queries reduce risk for non-human identities and AI agents?

A: Structured queries reduce risk because they replace multi-step tool improvisation with a single, reviewable request.

Q: How do access reviews need to change for machine identities?

A: Access reviews for machine identities should focus on purpose, owner, system reach, and whether the entitlement still exists for an active workload or integration.

Q: What breaks when AI agent access is granted without blast-radius controls?

A: The organisation loses the ability to predict which systems the agent can reach once it starts using tools, connectors, or delegated permissions at runtime.

Practitioner guidance

  • Expand access reviews to cover non-human identities and AI agents Include service accounts, API keys, secrets, and autonomous agents in the same review process so excessive permissions are not left outside governance because they are non-human.
  • Validate revocation after every rejected access decision Require the workflow to confirm that the permission actually disappeared in the access graph, not only that the review item was marked complete.
  • Map public MCP server use and external integrations to blast radius Document which agents or NHIs can reach each tool, data source, and model endpoint so hidden runtime dependencies do not expand access scope unnoticed.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • 325+ integration examples and the specific systems added in the 2025 release
  • Access review, revocation, and verification workflow details for approved and rejected permissions
  • NHI and AI agent inventory views, blast-radius visualisation, and orphaned identity handling
  • Lifecycle Management and JIT policy specifics for joiners, movers, leavers, and exception handling

👉 Read Veza's 2025 round-up of access platform updates for NHI and AI governance →

Veza’s 2025 access platform update: what changes for NHI teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

NHI governance is now an access-graph problem, not a point-product problem. Once an organisation has hundreds of integrations, multiple identity classes, and review workflows spanning humans, service accounts, and agents, control effectiveness depends on the relationship map more than any single dashboard. That makes lifecycle, entitlement, and ownership data part of the same governance layer. Practitioners should judge tooling by whether it can explain effective access end to end.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when a service account or AI agent keeps access after offboarding?

A: Accountability should sit with the system owner and the identity governance owner, not just the team that requested the access. If a service account or AI agent keeps access after offboarding, that usually means the lifecycle trigger, downstream revocation, or ownership mapping was incomplete. The control failure is organisational, not just technical.

👉 Read our full editorial: Veza’s 2025 access platform update widens NHI governance scope



   
ReplyQuote
Share: