TL;DR: Least privilege now has to operate as a continuous model, with identities, permissions, and resources unified into one searchable access graph and policy enforced in the flow of work rather than after the fact, according to Veza. That matters because fragmented visibility and manual control leave excess privilege in place long enough to expand blast radius.
NHIMG editorial — based on content published by Veza: Intelligent Access and the operating model for least privilege
By the numbers:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: How should security teams implement least privilege in dynamic environments?
A: Start by tying access to current role, task, and lifecycle state rather than to broad job titles or legacy entitlements.
Q: Why does fragmented access visibility create more risk in hybrid environments?
A: Because no one can reliably see who can do what across cloud, SaaS, data, and on-prem systems when entitlement data lives in silos.
Q: What breaks when revocation and approval live outside the access workflow?
A: Access becomes advisory instead of enforceable.
Practitioner guidance
- Build one access model across identity types Unify workforce accounts, service accounts, tokens, workloads, and AI agents into a single entitlement map so reviewers can see effective access rather than fragmented lists.
- Translate native entitlements into shared access semantics Normalise platform-specific permissions into create, read, update, and delete so approvers can compare intended access with actual access across cloud, SaaS, data, and on-prem systems.
- Automate expiration and revocation in the workflow Move temporary access, approvals, and revocations into the same path where requests are granted, then verify that revoked access truly disappears instead of lingering as a silent exception.
What's in the full article
Veza's full ebook covers the operational detail this post intentionally leaves for the source:
- A walk-through of the Access Graph model and how it traces effective permissions across cloud, SaaS, data, and on-prem estates.
- Examples of translating native permissions into plain create, read, update, and delete language for reviews and remediation.
- Practical patterns for automating requests, approvals, expirations, and verification so policy is enforced in the workflow.
- Measurement guidance on smaller blast radius, faster reviews, and fewer exceptions as indicators of programme progress.
👉 Read Veza's ebook on Intelligent Access and least privilege operating models →
Intelligent access and least privilege: what changes for IAM teams?
Explore further
Least privilege is no longer a quarterly governance exercise. The article reflects a structural truth we see across human IAM and NHI programmes: access changes faster than review cycles. When identities, systems, and rules all move continuously, the control that matters is the one that can stay current with actual state. Practitioners should treat stale permission visibility as an operating risk, not a reporting defect.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI, which helps explain why access governance is moving faster than most control programmes.
A question worth separating out:
Q: What should IAM and NHI teams measure to know whether least privilege is working?
A: They should measure reduced blast radius, faster reviews, and fewer exceptions rather than counting only the number of policies written. Those metrics show whether governance is changing actual exposure. If the same identities still have broad access after remediation, the operating model has not changed.
👉 Read our full editorial: Intelligent access reframes least privilege as an operating model