TL;DR: Identity governance is moving toward a control-plane model for human users, non-human identities, and AI agents, while Forrester projects IAM spending will reach about $27.5 billion by 2029 according to Veza. The real shift is that authorization, not just authentication, is becoming the hard boundary enterprises must govern.
NHIMG editorial — based on content published by Veza: ServiceNow acquires Veza and positions identity as the foundation for the agentic enterprise
Questions worth separating out
Q: What breaks when access management is separated from identity governance?
A: Teams gain the ability to grant access but lose confidence that access remains appropriate over time.
Q: Why do non-human identities complicate standard IAM reviews?
A: Because their value does not map cleanly to a human job role.
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Practitioner guidance
- Rebuild access reviews around effective permissions Shift certification from account lists to effective access paths, including nested roles, inherited entitlements, and delegated permissions that service accounts or AI agents can actually use.
- Inventory non-human and agent identities together Create a single inventory for service accounts, API keys, tokens, certificates, and AI agent identities so lifecycle owners can see where authority exists and where it was never retired.
- Tie authorization changes to ownership and offboarding Require every privileged NHI or agent identity to have a named owner, a purpose, and an offboarding condition so access does not survive the workflow it was created for.
What's in the full analysis
Veza's full article covers the operational detail this post intentionally leaves for the source:
- The access-graph approach Veza uses to answer who can take what action on what data across enterprise systems.
- The specific business case for unifying human, non-human, and AI agent governance in a single control plane.
- The article's broader market rationale for why authorization is becoming central to modern identity architecture.
- The original language around ServiceNow integration and the Enterprise Agent Identity Control Plane.
👉 Read Veza's acquisition note on identity control planes and agentic enterprise governance →
ServiceNow and Veza: what does this mean for NHI governance?
Explore further
Control-plane identity governance is becoming the category boundary. The article shows that enterprises are no longer solving identity as a login problem. They are trying to govern authorization across users, workloads, and AI agents in one place, which raises the bar for any IAM or NHI programme. The practical conclusion is that identity teams will be judged on whether they can explain effective access, not just authenticate accounts.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- The same study found that 46% confirmed a breach of non-human identities and 26% only suspected one, which shows how often visibility fails before remediation begins.
A question worth separating out:
Q: What do IAM teams get wrong about service accounts and AI agent permissions?
A: They often assume the user token or service account scope fully describes the agent’s risk. In practice, an agent can chain multiple operations within one session and operate with broader effective reach than the user intended. The control objective is not just identity binding, but action scoping.
👉 Read our full editorial: ServiceNow acquires Veza: identity control plane implications