TL;DR: Non-human identities now outnumber humans by 50 times, and rotation, revocation, and lifecycle control require full contextual visibility, according to Oasis Security. The core issue is not just secret sprawl, but the governance gap created when identity lifecycles outgrow human-centric access models.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Oasis Security Emerges from Stealth”.
Key questions
Q: What breaks when non-human identities are managed with human joiner-mover-leaver processes?
A: Human lifecycle models assume a person has a start date, role changes, and an offboarding event.
Q: Why do non-human identities increase data leakage risk?
A: Non-human identities increase leakage risk because they often have broad machine-to-machine reach, long-lived or reused credentials, and limited human review.
Q: When should security teams remove or rotate NHI credentials?
A: Remove or rotate credentials when the workflow changes, the owner changes, the identity is no longer needed, or the access cannot be justified.
Practitioner guidance
- Map NHI ownership to lifecycle state Create a governed inventory that links each service account, API key, secret, or token to an owner, purpose, environment, and retirement trigger.
- Separate rotation from retirement decisions Treat credential rotation as only one step in a broader decision path that also determines whether the identity still has a valid business purpose.
- Prioritise identities with broad data reach Review the credentials that can touch sensitive data across multiple systems first, because they create the largest blast radius if left in place.
Bottom line: The central risk is not only that non-human identities exist, but that they outlive the business purpose that created them.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
NHI lifecycle, not credential inventory, is the missing governance layer: The article is right to move the discussion beyond discovery. Visibility tells teams what exists, but lifecycle governance determines whether an identity should still exist, who owns it, and when it must be retired. That is the discipline gap exposed by NHI growth, and practitioners should treat lifecycle state as the primary control plane.
A question worth separating out:
Q: When does secrets management become an NHI governance problem?
A: Secrets management becomes an NHI governance problem when a credential can be used by a service, bot, or workload to obtain persistent access. At that point, the key question is not where the secret is stored but who owns it, when it expires, how it is rotated, and how it is revoked. That is lifecycle governance, not storage hygiene.
👉 Read our full editorial: Oasis Security’s stealth exit frames the NHI lifecycle gap