TL;DR: Identity governance is shifting from simple visibility to operational governance, with 325+ integrations, AI-powered access review, NHI and AI agent inventory, MCP server discovery, and automated revocation workflows across human and machine identities, according to Veza. The real change is that identity governance is moving from static review to runtime accountability across NHI, human access, and emerging autonomous actors.
Editorial analysis by NHI Mgmt Group, based on content published by Veza: “2025: The Year of Product Innovation”.
By the numbers:
- Veza says the update adds 325+ out-of-the-box integrations across enterprise systems and AI platforms.
Key questions
Q: How should teams govern non-human identities that support remote access and back-end workflows?
A: They should govern them as distinct identities with explicit ownership, scoped permissions, rotation, revocation and offboarding.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect.
Q: What breaks when rejected access is not actually revoked after review?
A: The review process becomes an audit record rather than a control.
Practitioner guidance
- Inventory effective machine access, not just identities Map service accounts, keys, secrets, and AI agents to the applications, data stores, and tool endpoints they can actually reach.
- Tie review outcomes to automatic revocation Configure access review workflows so rejected entitlements are removed automatically and then verified against the access graph.
- Assign a named human owner to every non-human identity Require accountable ownership for service accounts, keys, and AI agents, and alert when that ownership is lost or ambiguous.
Bottom line: The article shows NHI governance moving from inventory and visibility into operational control across review, revocation, and ownership.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Permission-level governance is replacing identity inventory as the core NHI control model. Once organisations can see machine identities, the next failure is assuming visibility equals control. This update shows the market moving toward effective-permission governance, where owners, entitlements, and actual reach matter more than counts of identities. That is the right direction for NHI programmes because machine risk is defined by what an identity can do, not by whether it is listed in a catalogue.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations treat AI agent access to AWS differently from CI/CD access?
A: Yes. CI/CD access is usually job-bound and repeatable, while AI agent access can be more context-sensitive and less deterministic at runtime. Both should be ephemeral, but agent sessions need tighter scoping, explicit approval boundaries, and stronger attribution because the workflow can change while it is running.
👉 Read our full editorial: Veza’s 2025 access platform update widens NHI governance scope