TL;DR: Enterprise security programs still assume identity is established at a gate, access is reviewed on a schedule, and policy can be written once, but modern NHI and agentic AI environments now require continuous, context-aware authorization, according to EnforceAuth. The structural failure is no longer credentialing alone; it is the broken assumption that static IAM can govern runtime decisions.
Editorial analysis by NHI Mgmt Group, based on content published by EnforceAuth: “The Authorization Gap: A Reference Architecture for Continuous, Policy-as-Code Authorization”.
By the numbers:
- Non-human identities now outnumber human identities by a wide and accelerating margin, commonly cited industry figures range from 45:1 to 92:1 with a weighted enterprise average around 82:1.
Key questions
Q: What breaks when access is reviewed only on a schedule for NHIs and agents?
A: Scheduled reviews miss the moment when authorization is actually consumed.
Q: Why do static IAM roles create risk for agentic AI?
A: Static IAM roles create risk because they assume the identity's purpose is known in advance and will not change mid-session.
Q: How do security teams know whether continuous authorisation is actually working?
A: Teams know it is working when sensitive actions are blocked or stepped up based on context, not just login state.
Practitioner guidance
- Implement continuous authorization for non-human identities Evaluate each request against live context, including subject type, task state, resource sensitivity, and provenance, rather than relying on static entitlements or periodic reviews.
- Enforce policy at the tool-call boundary Place a decision point in front of every agent tool invocation so the system can permit, deny, or narrow access before an action executes.
- Map effective access across all policy surfaces Inventory where authority is actually expressed, including cloud IAM, database rules, application logic, and service permissions, then compare that to intended scope.
Bottom line: The article argues that the enterprise access model still assumes stable identities and infrequent decisions, which no longer fits NHI and agentic AI environments.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
The authorization gap is a governance failure, not a tooling gap. Enterprises did not simply miss a feature. They built their access model around stable identities, infrequent decisions, and role-based inference, then applied it to systems that decide continuously. That mismatch is now visible across NHIs and agentic AI, where runtime behavior matters more than the credential itself. Practitioners need to treat authorization as a control plane, not an entitlement afterthought.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
A: Organisations should create a single policy decision point for authorization so access rules are applied consistently across applications and channels. The practical goal is to reduce ad hoc rules, improve governance, and make access decisions easier to audit. Policy-based control works best when business owners define policies, while identity and security teams enforce guardrails and oversight.
👉 Read our full editorial: The authorization gap is widening across NHI and agentic AI