Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Continuous identity governance across human, NHI, and AI identities


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: MTX Group and Oleria are positioning continuous, adaptive governance as the answer to access sprawl across employees, service accounts, machine identities, and AI agents in regulated environments, according to Oleria Security. The real issue is not visibility alone but whether identity governance can keep pace with changing access across human, non-human, and autonomous systems.

NHIMG editorial — what this means for NHI practitioners

Questions worth separating out

Q: How should security teams govern access across human, NHI, and AI identities?

A: Security teams should govern all three through a shared lifecycle and policy layer, but with different operating rules for each actor type.

Q: When does standing privilege become unacceptable in modern IAM programmes?

A: Standing privilege becomes unacceptable when the identity can act faster than your review cycle, especially for workloads and AI agents that move across systems autonomously.

Q: What breaks when access reviews are only run on a fixed schedule?

A: Fixed-cycle reviews encourage repetition, not judgment.

Practitioner guidance

  • Map identity ownership across mixed estates Inventory human users, service accounts, machine identities, and AI agents in one control view, and require each to have an accountable owner, purpose, and lifecycle state.
  • Shift high-risk access to continuous review triggers Trigger review and enforcement when privileges change, integrations are added, or service accounts are repurposed, rather than waiting for periodic certification cycles.
  • Eliminate standing privilege in shared and reusable identities Identify credentials that remain valid beyond the business task they support, then reduce their lifetime or scope so access cannot accumulate silently.

What's in the full announcement

Oleria Security's full post covers the operational detail this post intentionally leaves for the source:

  • How the partnership positions continuous governance across regulated public sector and healthcare environments
  • The vendor's description of automated access reviews, lifecycle management, and standing privilege removal
  • Specific language on visibility across human, non-human, and AI identities in transformation programmes
  • The quoted partner framing on digital transformation and trusted governance

👉 Read Oleria Security's update on the MTX partnership for continuous identity governance →

Continuous identity governance across human, NHI, and AI identities?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Continuous governance is becoming the baseline control for mixed identity estates. Access that changes across employees, service accounts, machine identities, and AI agents cannot be governed effectively through quarterly or annual review cycles. The control question is no longer whether organisations can certify access, but whether they can see and enforce change fast enough to matter. That makes continuous governance a structural requirement for modern IAM, not an enhancement.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when a service account or AI agent keeps access after offboarding?

A: Accountability should sit with the system owner and the identity governance owner, not just the team that requested the access. If a service account or AI agent keeps access after offboarding, that usually means the lifecycle trigger, downstream revocation, or ownership mapping was incomplete. The control failure is organisational, not just technical.

👉 Read our full editorial: MTX and Oleria partnership raises the bar for identity governance



   
ReplyQuote
Share: