TL;DR: AI agents, service accounts and workloads are colliding with legacy IGA models built mainly for users and roles, while SafePaaS was named a Representative Vendor in Gartner’s 2026 Market Guide for Identity Governance and Administration. The real issue is not recognition itself, but that access governance now has to follow identities into runtime activity, ownership and business context.
NHIMG editorial — based on content published by SafePaaS: Gartner recognition for identity governance and administration
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should teams govern service accounts and AI agents in the same IGA programme?
A: Use a single governance model for ownership, review, and offboarding, but apply it to different identity lifecycles.
Q: Why do legacy IGA tools struggle with non-human identities?
A: They were designed to certify roles and approvals for human users, not to interpret continuous machine activity, ownership or downstream business transactions.
Q: What signals show that identity governance is still too user-centric?
A: If your programme can certify access but cannot explain which workload, API, or agent executed a transaction, the model is still user-centric.
Practitioner guidance
- Map governance by actor type Separate humans, service accounts, workloads and AI agents in your governance model so each identity type has its own lifecycle, review and ownership path.
- Tie entitlements to business transactions Extend IGA controls so access can be evaluated against transaction context, not just role membership or approval history.
- Audit ownership for non-human identities Require a named owner, purpose and review trigger for every service account, workload credential and AI agent before it is allowed to persist.
What's in the full article
SafePaaS's full announcement covers the operational detail this post intentionally leaves for the source:
- The specific Gartner Market Guide context behind the Representative Vendor designation and the wording SafePaaS published around it.
- The platform claims about federated identity architecture across cloud, SaaS and on-premises environments, including how it says identities and entitlements are connected.
- The business-context governance approach SafePaaS describes for linking access to compliance, transaction monitoring and risk evaluation.
- The vendor’s own explanation of onboarding human and non-human identities into legacy IGA environments.
👉 Read SafePaaS's announcement on Gartner recognition and AI-aware IGA →
AI agents and IGA: what changes for identity governance teams?
Explore further
Legacy IGA is increasingly a human-centric control plane in a mixed-actor environment. The core governance assumption behind older IGA models is that identities can be reviewed and controlled primarily as users and roles. That assumption weakens when service accounts, workloads and AI agents become first-class access holders with distinct lifecycles and different evidence trails. The implication is that identity governance now has to be designed around actor type, not just around entitlement records.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations prioritise continuous governance over quarterly access reviews?
A: For high-risk non-human identities and AI agents, yes. Quarterly reviews still matter for accountability, but they are too slow to catch access misuse that emerges during runtime, especially in cloud and SaaS environments.
👉 Read our full editorial: Gartner recognition spotlights AI-aware identity governance gaps