TL;DR: Forrester’s Q4 2025 Workforce Identity Security Platforms Landscape frames NHIs, service accounts, workloads, APIs, and AI agents as a primary market challenge, while positioning workforce identity platforms around governance, posture, and lifecycle controls across humans and machines, according to Linx Security. Traditional IAM assumptions are no longer sufficient when identity sprawl and agentic access become the norm.
NHIMG editorial — based on content published by Linx Security: Linx listed in Forrester’s Workforce Identity Security Platforms Landscape
Questions worth separating out
Q: How should security teams govern service accounts, workloads, and AI agents together?
A: Treat them as governed identities with owners, lifecycles, and review requirements, not as infrastructure exceptions.
Q: Why do non-human identities create more identity risk than many IAM programmes expect?
A: Because they multiply faster than human accounts and often accumulate access without strong lifecycle controls.
Q: What do teams get wrong about identity security posture management?
A: They treat posture as reporting instead of decision-making.
Practitioner guidance
- Map every non-human identity to an owner and lifecycle Build an inventory that includes service accounts, workloads, APIs, and AI agents, then assign accountable owners, review cadences, and offboarding triggers for each identity class.
- Prioritise toxic access paths over raw entitlement counts Use graph-based visibility to identify privilege chains, lateral movement paths, and excessive access that materially increase breach impact, then rank remediation by exposure.
- Fold NHI review into existing governance workflows Add machine and AI agent identities to access certifications, exception handling, and remediation queues so they are not excluded from the same control loops used for human access.
What's in the full analysis
Linx Security's full article covers the operational detail this post intentionally leaves for the source:
- How Linx maps its platform into Forrester’s core and extended use case categories
- The specific identity governance, posture, and machine identity capabilities the vendor says it is focusing on
- The vendor’s walkthrough of why AI-assisted access reviews and graph-based visibility matter in practice
- The report reference and the positioning context behind Linx’s inclusion
👉 Read Linx Security's summary of Forrester’s workforce identity security landscape →
Workforce identity security platforms: what the Forrester landscape means?
Explore further
Identity governance is becoming the control plane for workforce identity security. The article reflects a market shift away from standalone IAM thinking toward unified governance across humans and non-humans. That is the right direction because access, lifecycle, and auditability now depend on whether teams can see the whole identity estate, not just employee accounts. For practitioners, the important conclusion is that governance programmes must be built to absorb machine identity at scale.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: What should organisations re-evaluate as AI agents become part of the workforce identity stack?
A: They should re-evaluate whether their current governance model assumes stable, reviewable access that belongs to a person. AI agents change the problem because they can expand reach across systems while remaining outside human-centric processes. A mature programme needs ownership, lifecycle handling, and enforcement mechanisms that apply to agent identities as well as people.
👉 Read our full editorial: Forrester’s workforce identity landscape spotlights NHI and AI agent risk