Join our Newsletter — 33% off our NHI Course

NHI ownership attestation: what IAM teams need to fix now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Ownership discovery and attestation are intended to keep non-human identities accurate, accountable, and compliant over time, while reducing manual review cycles, unresolved ownership, and audit friction, according to Oasis Security. The governance issue is not review cadence alone, but the fact that many NHI programmes still cannot prove who owns what, when access is no longer needed, or whether attestation decisions are timely.

Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Solving Non Human Identity Ownership with Oasis. Part 2: Ownership attestation”.

Key questions

Q: What breaks when NHI ownership is missing?

A: When NHI ownership is missing, access reviews lose context, incident response slows, and stale identities persist longer than they should.

Q: Why do periodic NHI attestation campaigns often stall?

A: They stall because the programme keeps reassembling ownership context instead of governing from a stable record.

Q: How do security teams know if NHI authorization is actually working?

A: Look for consistent allow and deny decisions at runtime, complete audit logs for each request, and fewer services that need code-level permission checks.

Practitioner guidance

  • Define ownership before attestation begins Require every NHI to have a named human owner or accountable team before it enters a review campaign.
  • Separate discovery from certification Use discovery to populate the inventory, then use attestation to confirm continued need, approved use, and correct ownership.
  • Convert review responses into lifecycle actions Make approved, not needed, and not the owner trigger different downstream outcomes such as keep, remove, or reassign.

Bottom line: NHI ownership attestation is the control that turns discovered identities into governed identities by confirming who owns them and whether they still need access.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Ownership is the missing control plane for NHI governance: discovery without accountable ownership leaves machine identities visible but not governable. The problem is not that organisations lack inventory, but that inventory does not tell you who can certify use, revoke access, or accept risk. That gap is why attestation becomes the governance bridge between visibility and action. Practitioners should treat ownership as a lifecycle control, not a directory field.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who should own NHI attestation decisions in an IAM programme?

A: Ownership should sit with the business or technical team that can validate the identity’s purpose and accept the risk of continued access, with IAM or IGA providing the control framework. If the reviewer cannot explain why the identity exists, the attestation model is too detached from operations.

👉 Read our full editorial: Non-human identity attestation closes the ownership gap in IAM


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.