TL;DR: Non-human identities now outnumber human identities by 45:1 to 80:1 in many cloud-native environments, and the article argues that static roles, long-lived keys, and admin-time permissions cannot keep pace with ephemeral workloads, according to Cerbos. Runtime contextual authorization becomes the decisive control because identity alone does not answer what a workload should be allowed to do in the moment.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “Securing cloud architectures in the age of non‑human identities and ephemeral services”.
By the numbers:
- Non-human identities now outnumber human identities by 45:1 to 80:1 in many cloud-native environments.
Key questions
Q: What breaks when non-human identities keep static permissions in cloud-native systems?
A: Static permissions break when the workload is short-lived, the context changes, and the credential keeps working long after the task should have ended.
Q: Why do valid service account tokens still create security risk?
A: A valid token only proves that the requester has a credential, not that the current action is appropriate.
Q: How can organisations tell whether runtime authorization is actually working?
A: Look for three signs: decisions happen fast enough to stay inline, policies use live context instead of stale claims, and every allow or deny produces an auditable record.
Practitioner guidance
- Define request-time authorization as the primary control Move high-risk service and workload decisions out of static roles and into policy checks that evaluate the request context at runtime.
- Inventory every non-human principal with an owner Track service accounts, API tokens, and CI/CD credentials as governed identities with named owners, lifecycle state, and offboarding triggers.
- Shorten credential lifetime to match workload duration Set token and secret expiry to the shortest practical interval for the job or service, then remove any credential that outlives the workload.
Bottom line: Non-human identities in cloud-native systems need request-time authorization because static roles do not track ephemeral workload context.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Static entitlement models are the wrong abstraction for ephemeral non-human identities. The article shows that workloads, CI jobs, and serverless functions now appear and disappear faster than traditional IAM assignment cycles can follow. That means role design based on durable principals no longer matches how access is actually consumed. The practitioner implication is that entitlement strategy has to shift from provisioning-time assumptions to request-time governance.
Ephemeral access only works when lifecycle controls catch up to workload churn. In many environments, the governance problem is not lack of authentication but lack of timely teardown. That is why machine identity programmes need to be built around expiry, ownership, and automated revocation rather than around static account administration.
A question worth separating out:
Q: What should teams do when CI/CD credentials outlive the pipeline?
A: They should treat that as a lifecycle failure, not an isolated secret issue. The credential should be revoked, the pipeline ownership reviewed, and future issuance tied to an automated teardown path. Persistent access after the job ends is exactly the pattern that turns build systems into hidden attack surfaces.
👉 Read our full editorial: Runtime authorization for non-human identities in cloud-native systems
Static entitlement models are the wrong abstraction for ephemeral non-human identities. The article shows that workloads, CI jobs, and serverless functions now appear and disappear faster than traditional IAM assignment cycles can follow. That means role design based on durable principals no longer matches how access is actually consumed. The practitioner implication is that entitlement strategy has to shift from provisioning-time assumptions to request-time governance.
Ephemeral access only works when lifecycle controls catch up to workload churn. In many environments, the governance problem is not lack of authentication but lack of timely teardown. That is why machine identity programmes need to be built around expiry, ownership, and automated revocation rather than around static account administration.
A question worth separating out:
Q: What should teams do when CI/CD credentials outlive the pipeline?
A: They should treat that as a lifecycle failure, not an isolated secret issue. The credential should be revoked, the pipeline ownership reviewed, and future issuance tied to an automated teardown path. Persistent access after the job ends is exactly the pattern that turns build systems into hidden attack surfaces.
👉 Read our full editorial: Runtime authorization for non-human identities in cloud-native systems
Runtime authorization is the control that cloud-native identity models were missing: the article shows that a valid credential is not the same thing as a valid action. In distributed systems, identity proves origin, while policy must prove legitimacy for the specific request. That distinction is now central to NHI governance, because static authorization collapses when workloads are ephemeral and context changes faster than provisioning cycles. Practitioners should treat request-time policy as the primary control plane for machine access.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: Should organisations use the same governance model for CI/CD identities as for service accounts?
A: Yes, because both are non-human identities performing production work under delegated privilege. The governance mechanics are nearly identical: ownership, scope, expiry, review, and revocation. The difference is that CI/CD identities are often more exposed to supply chain and log-based theft, so their controls should usually be stricter.
👉 Read our full editorial: Runtime authorization for non-human identities in cloud-native systems