Join our Newsletter — 33% off our NHI Course

Credential sprawl in AI workflows: what IAM teams need now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Credential sprawl now extends across SaaS, scripts, pipelines, browsers, and AI prompts, while 52% of employees have downloaded apps without IT approval and stolen credentials remain the most common breach entry point, according to 1Password and Verizon. The governance gap is no longer sign-in security but ownership, lifecycle, and revocation across every credential-bearing workflow.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “IAM stops at sign-in. Your credentials do not.”.

By the numbers:

  • 52% of employees have downloaded apps without IT approval, according to 1Password research cited by 1Password.
  • Breaches that start with stolen or compromised credentials take nearly 10 months to identify and contain, according to 1Password research cited by 1Password.

Key questions

Q: What breaks when credentials are created outside the identity provider?

A: A clean ownership chain breaks first.

Q: Why do AI-generated development workflows increase IAM and secrets risk?

A: Because AI assistants often need access to prompts, templates, repositories, and cloud configuration examples to be useful.

Q: How do teams know if credential sprawl is actually under control?

A: Credential sprawl is under control only when the organisation can identify every active credential, assign an owner, and prove that revocation and review are happening on a repeatable cadence.

Practitioner guidance

  • Define the full credential estate Map passwords, passkeys, API tokens, SSH keys, service accounts, environment files, shared accounts, and agent secrets to a single inventory with named owners.
  • Block ad hoc credential creation in workflows Limit where developers, admins, and AI builders can generate secrets, and remove browser notes, spreadsheets, and prompts from approved storage paths.
  • Tie every secret to a lifecycle owner Assign ownership for creation, rotation, and revocation so credentials created by automation do not outlive the workflow or team that needed them.

Bottom line: Credential sprawl is a workflow governance problem that extends beyond sign-in security into ownership, storage, and revocation.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Credential sprawl is now a governance model failure, not just an inventory problem. When credentials are created inside AI workflows, scripts, and browser-based tasking, the identity programme can no longer rely on sign-in controls as the boundary of control. That means IAM and PAM coverage must be judged by what they do not see as much as by what they authenticate. Practitioners should treat unmanaged credential creation as an access-governance defect, not an exception.

A few things that frame the scale:

  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations prioritise revocation or discovery first in credential sprawl programmes?

A: Discovery comes first, but revocation must be designed at the same time. Knowing where secrets live is useful only if the team can disable them quickly when a user, workflow, or agent changes. The practical goal is to shrink the window between finding a credential and being able to remove its access.

👉 Read our full editorial: Credential sprawl is outpacing IAM controls in AI-driven work


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.