TL;DR: Ungoverned credentials, fragmented workflows, and late-stage remediation leave NHI risk baked in before teams can react, according to Oasis Security, whose NHI provisioning capability creates and governs non-human identities from the start, with policy enforcement, ownership assignment, vaulting, rotation, and deprovisioning set during request approval and applied through the lifecycle.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Introducing Oasis NHI Provisioning: Transforming NHI Security from day 1”.
Key questions
Q: What breaks when NHI provisioning happens without ownership and policy at creation time?
A: The identity enters production already outside governance.
Q: How should teams choose between credential-based and federated NHIs?
A: Use federated identity when the workload can authenticate through trust relationships instead of storing a secret.
Q: What are the signs that NHI governance is failing in an enterprise?
A: Common warning signs include unclear ownership for service accounts, secrets stored in code or configuration instead of managed vaults, infrequent rotation, and weak offboarding of API keys.
Practitioner guidance
- Define provisioning as a governance gate Require every NHI request to set ownership, credential model, vault destination, rotation policy and deprovisioning rules before the identity is created.
- Separate credentialed and federated paths Route use cases toward federated identities where trust relationships are sufficient, and reserve credential-based provisioning for cases that genuinely need stored secrets.
- Bind lifecycle policy to approval workflow Make the approval step the point where ILM rules are attached so inventory, posture checks and cleanup inherit the same policy from day one.
Bottom line: The article argues that NHI risk starts at creation when ownership and lifecycle controls are not bound to provisioning.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Provisioning-time governance is now the boundary where NHI risk is decided. When ownership, rotation and deprovisioning are deferred until after creation, the organisation has already accepted unmanaged identity state into production. That is not a minor process gap, it is a lifecycle design flaw. The implication is that identity programmes should measure control at issuance, not only at audit or cleanup time.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
A question worth separating out:
A: They should standardise the request and approval logic so every path applies the same policy decisions before identity creation. The goal is not to eliminate tooling variety, but to stop governance from varying by channel. Provisioning must produce the same ownership and lifecycle outcome regardless of entry point.
👉 Read our full editorial: Oasis NHI provisioning shifts identity governance left from day one