TL;DR: Continuous governance is becoming the baseline for human, non-human, and AI identities because periodic certification leaves standing privilege and access drift unchecked, according to Oleria Security’s partnership announcement with SDG. The governance model now has to treat identity as a live control surface, not a quarterly review exercise.
NHIMG editorial — what this means for NHI practitioners
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
Questions worth separating out
Q: How should IAM teams govern human, non-human, and AI identities together?
A: Start by separating the identity types in policy, ownership, and review cadence, then define where controls can be shared and where they must remain distinct.
Q: When does periodic access certification stop working for identity governance?
A: Periodic certification stops working when identities change faster than a review cycle can observe them.
Q: What are the signs that a governance programme is failing for non-human identities?
A: The clearest signs are poor ownership, unexplained standing privilege, and access that survives long after the business task ends.
Practitioner guidance
- Map all identity classes into one governance inventory Classify employees, contractors, service accounts, machine identities, and AI agents in the same inventory so ownership and review logic are consistent across the estate.
- Prioritise standing privilege removal first Target the identities with persistent access that are hardest to monitor, especially application accounts, automation identities, and agentic workflows that keep privileges after task completion.
- Shift high-risk access reviews to continuous evaluation Replace quarterly-only certification for fast-changing identities with continuous monitoring of effective access, entitlement drift, and revocation triggers.
What's in the full announcement
Oleria Security's full announcement covers the operational detail this post intentionally leaves for the source:
- How the partnership packages advisory, implementation, integration, and managed services for identity modernisation.
- The specific ways the platform claims to automate access reviews and identity lifecycle processes across human and non-human identities.
- The product framing around continuous, AI-driven governance and how Oleria describes removal of standing privilege.
- The customer-facing messaging on compliance, cyber resilience, and support for AI agents and future digital initiatives.
👉 Read Oleria Security's announcement on continuous identity governance for AI-era estates →
AI identities and standing privilege: what should governance teams do now?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Continuous governance is becoming the only defensible model for mixed identity estates. Periodic access reviews were designed for environments where entitlements changed slowly enough to be certified after the fact. That model breaks once service accounts, machine identities, and AI agents operate inside the same control plane as humans. The implication is not just more automation. It is a different governance stance, where access must be evaluated as a live state rather than an audit event.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how identity failures compound once they are in the estate.
A question worth separating out:
Q: How can organisations reduce third-party identity risk without slowing operations?
A: By making onboarding, ownership, review, and offboarding part of one lifecycle path. That approach reduces orphaned access and gives security and compliance teams a single place to verify who is still authorised. The goal is not to block collaboration, but to keep external access accountable.
👉 Read our full editorial: AI era identity governance needs continuous visibility across every actor