TL;DR: Zero Trust verifies identity and limits access, but Living Security Human Risk Management Platform argues that legitimate users can still become risky when behavior and threat context are missing, leaving human error, deception, and unsafe approvals outside the control model. The practical shift is from authentication-only governance to measurable risk reduction across users and AI agents.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Zero Trust Human Risk: Why Identity Alone Isn't Enough
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams implement Zero Trust for non-human identities?
A: Start by inventorying every machine identity, assigning an owner, and mapping its access to a specific business function.
Q: Why do verified users still create security risk in Zero Trust models?
A: Verified users can still be tricked, pressured, or manipulated into taking unsafe actions inside a legitimate session.
Q: What do organisations get wrong about phishing prevention?
A: They often treat phishing as a training problem instead of an identity control problem.
Practitioner guidance
- Define human-risk signals for privileged workflows Map the identity events that matter most, such as unusual approvals, rapid privilege changes, and abnormal access paths, then decide which combinations should trigger review before the next action completes.
- Correlate identity events with behavioral telemetry Link authentication, session, and user-behaviour data so analysts can compare current activity with normal patterns and threat indicators instead of reviewing access logs in isolation.
- Extend governance to AI agent identities Treat AI agents as scoped identities with explicit owners, bounded permissions, and monitoring that can detect when software action drifts beyond expected intent.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- How the platform correlates behaviour, identity, and threat signals across more than 60 security tools
- The measurement model behind its reported reduction in risky users and data-loss exposure
- How Livvy is positioned to guide triage, remediation, and human oversight in practice
- Where the article extends the discussion from human users to AI-agent identities
Zero trust human risk: is identity enough for IAM teams?
Explore further
Zero Trust is necessary, but it is not sufficient when risk is driven by human decision-making. Identity and access controls can confirm who or what is authenticated, yet they cannot tell practitioners why a legitimate request is dangerous. That is why behavioural context belongs inside governance, not beside it. For IAM and PAM leaders, the conclusion is straightforward: access policy without human risk context remains an incomplete control model.
A question worth separating out:
Q: How should security teams govern AI agents that inherit authority from other identities?
A: Security teams should govern AI agents by tracking identity lineage, not just credentials. That means recording the originating identity, the delegated authority path, and the runtime context for each action. If an agent can inherit permissions from humans, services, or other agents, policy has to evaluate the full chain before access is granted or continued.
👉 Read our full editorial: Zero trust human risk needs behavioral context beyond identity