TL;DR: Thanksgiving is used as an analogy for NHI governance: organisations must know which applications, APIs, and workloads are present, assign clear roles and policies, and clean up stale permissions, unrotated secrets, and unused credentials, according to Oasis Security. The central lesson is that identity inventory and lifecycle hygiene are the real control plane, not holiday-style coordination.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “The feast of security: what Thanksgiving can teach us about protecting Non-Human Identities”.
Key questions
Q: What breaks when organisations cannot see all of their non-human identities?
A: What breaks is governance itself.
Q: Why do stale credentials create such persistent NHI risk?
A: Because credentials often remain valid after the business need has ended, which means access continues even when accountability has already drifted.
Q: How should teams prevent permission drift in NHI environments?
A: By defining roles tightly, assigning each identity to a known function and enforcing those rules automatically.
Practitioner guidance
- Build a complete NHI inventory Discover applications, APIs and workloads, then assign each identity an owner, purpose and business service so nothing sits outside governance.
- Define explicit role boundaries Map each NHI to a narrow role and remove broad permission bundles that were created for convenience rather than function.
- Eliminate stale access residue Review stale permissions, unrotated secrets and unused credentials together so cleanup closes the lifecycle loop instead of becoming a one-off audit exercise.
Bottom line: NHI governance fails early when organisations cannot inventory the applications, APIs and workloads already in use.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity inventory is the control plane for NHI governance. If an organisation cannot enumerate its applications, APIs and workloads, it cannot govern them. Discovery establishes the boundary for ownership, policy and lifecycle decisions, which means every later control depends on this first step being accurate. The practitioner lesson is simple: inventory quality determines whether NHI governance is real or performative.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should identity teams treat credential cleanup as part of lifecycle management?
A: Yes. Cleanup is not a separate housekeeping task, it is the final stage of lifecycle control. When a workload is retired or an integration changes, permissions, secrets and unused accounts should be removed together so residual access does not outlive the service it supported.
👉 Read our full editorial: Thanksgiving shows why NHI governance starts with identity inventory