TL;DR: Enterprises now need to govern access across human, non-human, and AI identities with continuous controls as identity environments expand beyond workforce users, according to Oleria Security. The shift matters because periodic access reviews and static privilege models were never built for access that changes across service accounts, machine identities, and AI agents.
NHIMG editorial — what this means for NHI practitioners
By the numbers:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps.
Questions worth separating out
Q: How should security teams govern access across human, NHI, and AI identities?
A: Security teams should govern all three through a shared lifecycle and policy layer, but with different operating rules for each actor type.
Q: When does point-in-time access review stop being effective?
A: It stops being effective when privilege changes faster than the review cadence or when access exists across multiple actor types with different ownership models.
Q: What do teams get wrong about standing privilege in hybrid identity estates?
A: They often treat standing privilege as an administrative inconvenience instead of a structural exposure.
Practitioner guidance
- Map access by actor type Separate human users, service accounts, machine identities, and AI agents into distinct governance inventories so review and offboarding rules reflect how each identity behaves.
- Prioritise standing privilege removal Identify persistent access that remains available without active need, then remove or constrain it in the highest-risk systems first, especially where automation widens blast radius.
- Redesign access reviews for continuous evidence Shift high-risk identity reviews from periodic certification to continuous evidence gathering so entitlement changes, ownership changes, and usage changes are evaluated together.
What's in the full announcement
Oleria Security's full post covers the operational detail this post intentionally leaves for the source:
- How the partnership maps continuous governance into day-to-day identity operations across enterprise environments
- Which access review and lifecycle workflows the vendor says can be automated for mixed identity estates
- How the platform frames visibility, standing privilege removal, and governance for AI-first environments
- The partner-led positioning around cybersecurity and digital transformation implementation
👉 Read Oleria Security's partnership details on modern identity governance for AI-first enterprises →
AI-first identity governance: are your access controls keeping up?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Continuous governance is becoming the baseline because static certification cannot keep pace with modern identity change. Identity environments now shift too quickly for quarterly or monthly review cycles to remain authoritative. When access spans employees, service accounts, machine identities, and AI agents, governance has to track actual runtime privilege, not just assigned entitlement. The practitioner conclusion is simple: point-in-time certification is no longer enough to describe real risk.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: How can organisations tell whether continuous governance is working?
A: Look for shorter time between entitlement change and governance action, fewer low-value approvals sent to humans, and better alignment between assigned access and actual use. If reviewers are still overloaded or the same exceptions keep returning, the programme is automating process steps without improving control outcomes.
👉 Read our full editorial: Modern identity governance for AI-first enterprises needs continuous controls