Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Production identity behavior after login: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: 91% of active production identities are non-human and most security tools still stop at authentication, leaving post-login behavior largely invisible, according to ClearVector's Identity Intelligence Report. That gap matters because AI agents, service accounts, and third-party access now drive production activity, and the real risk is what an authenticated identity does next, not just whether it logged in.

NHIMG editorial — based on content published by ClearVector: Research Identity behavior after authentication in production

By the numbers:

Questions worth separating out

Q: How should security teams detect risky behaviour after authentication in production?

A: Security teams should combine authentication logs with runtime identity telemetry so they can see what the session did after login.

Q: Why do service accounts and workload identities create so much least-privilege risk?

A: They usually outnumber human accounts, change more often, and are frequently granted broad access for convenience.

Q: What do security teams get wrong about post-authentication monitoring?

A: They often assume authentication, endpoint monitoring, or configuration scanning is enough to capture identity risk.

Practitioner guidance

  • Map runtime identity attribution gaps Inventory which production systems can tie actions back to the originating identity at the moment they occur.
  • Build per-identity behaviour baselines Derive normal activity from each identity's own pattern of life, including time of day, resource scope, role assumptions, and action sequence.
  • Separate inherited access from human intent Identify where AI agents, automation, or vendors operate under borrowed human credentials.

What's in the full article

ClearVector's full report covers the operational detail this post intentionally leaves for the source:

  • The production identity composition breakdown across AWS and GCP environments, including the split between non-human, third-party, and human identities.
  • The event-stream and sensor model used to build per-identity pattern-of-life baselines from live production activity.
  • The runtime detection and isolation workflow for investigation, triage, and identity containment.
  • The article's examples of post-authentication blind spots in EDR, IdP, and CSPM tooling.

👉 Read ClearVector's Identity Intelligence Report on post-authentication production identity behaviour →

Production identity behavior after login: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

Post-authentication visibility is now an identity governance problem, not a tooling gap. Authentication controls answer who entered, but production governance has to answer what the identity did after entry. Once service accounts, vendors, and AI agents begin operating inside live environments, the real control plane becomes behavioural, not simply declarative. IAM teams should treat runtime identity activity as a first-class governance domain.

A few things that frame the scale:

  • 91% of active production identities are non-human, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which is why runtime attribution matters more than static inventory.

A question worth separating out:

Q: How should organisations respond when an authenticated identity starts behaving outside its baseline?

A: They should isolate the session and contain the identity path, not just the resource the identity touched. If the activity is attributed to a service account, vendor, or AI agent, the response should include revoking the session, cutting off delegated access, and preserving the full action timeline for investigation.

👉 Read our full editorial: Production identity behavior after authentication exposes the blind spot



   
ReplyQuote
Share: