Join our Newsletter — 33% off our NHI Course

Oasis NHI Security Cloud’s first year: what changed for IAM teams?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Non-human identities outnumber human identities by 20x on average, with visibility, rotation, ownership, and attestation now treated as core controls rather than optional hygiene, according to Oasis Security’s first-year summary. Traditional human-centric IAM models are too rigid for fragmented cloud identity perimeters and automated workload access.

Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Celebrating the first year of Oasis NHI Security Cloud”.

By the numbers:

  • NHIs outnumber human identities by a factor of 20x on average, according to Oasis Security.

Key questions

Q: What breaks when non-human identities are left out of governance?

A: When non-human identities are left out, ownership becomes unclear, credentials stay active too long, and audit cannot verify who approved the access or why it still exists.

Q: Why do unrotated secrets and overprivileged NHIs create so much risk?

A: They combine persistence with excess reach.

Q: How do security teams know if NHI ownership controls are working?

A: Ownership controls are working when every live NHI has a responsible team, a current business purpose, and a clear retirement path.

Practitioner guidance

  • Map every NHI source system Inventory where machine identities originate, including cloud providers, SaaS platforms, secrets managers, CI/CD tools, and automation scripts, then reconcile those sources against the identities your IAM team can actually see.
  • Separate privilege review from secret review Assess permission scope and credential lifespan together for service accounts, API keys, access tokens, and database users so that overprivilege and long-lived access are remediated as one control problem.
  • Assign explicit ownership for every NHI Require a named business or technical owner for each non-human identity, with attestation evidence that confirms the identity is still needed and still correctly scoped.

Bottom line: Non-human identities have outgrown human-centric IAM assumptions, and fragmented cloud and SaaS environments have made that gap operational.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21346
 

Identity perimeter fragmentation is now the governance problem, not a side effect of modern architecture. When every cloud service and SaaS platform behaves like its own identity provider, central IAM loses the clean boundary it was designed around. That shifts the burden from directory-centric administration to distributed governance across NHIs, secrets, and workload access. Practitioners should treat identity perimeter drift as a structural control issue, not an inventory issue.

A few things that frame the scale:

  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap, according to the State of Secrets in AppSec.

A question worth separating out:

Q: What is the difference between human IAM controls and NHI governance?

A: Human IAM is built around people joining, moving roles, and leaving the organisation. NHI governance is built around credentials, workloads, integrations, and software change. That means machine identities need inventory, ownership, rotation, and offboarding tied to technical events, not just HR events or periodic access reviews.

👉 Read our full editorial: Oasis Security's first year shows why NHI governance needs new controls


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.