TL;DR: Identity context, least privilege, and access governance are moving into the center of AI-era security operations as ServiceNow’s acquisition of Veza signals, according to Veza; the market is now treating human, non-human, and agentic identities as one control problem, and static access models are no longer enough for modern enterprise risk.
NHIMG editorial — based on content published by Veza covering ServiceNow’s acquisition of Veza: identity-first security for the agentic enterprise
Questions worth separating out
Q: Should organisations merge human IAM and NHI governance after a major acquisition?
A: They should align the operating model, but not collapse the controls into one undifferentiated process.
Q: Why does identity context matter more when AI agents enter the enterprise?
A: Because agentic systems can scale access decisions, tool use, and data reach much faster than manual governance can track.
Q: What breaks when least privilege is applied only at review time?
A: Least privilege becomes a snapshot rather than a control.
Practitioner guidance
- Map identity context to privilege risk Inventory which identities have accountable owners, dormant access, sensitive-data reach, and lateral movement potential.
- Separate human review from machine-speed control Keep periodic access reviews for governance evidence, but add automated policy enforcement for service accounts, API keys, and agentic workflows that can change faster than review cycles.
- Classify agent permissions as NHI scope decisions Treat AI agents as non-human identities until the environment proves a higher autonomy model is needed.
What's in the full analysis
Veza's full analysis covers the operational detail this post intentionally leaves for the source:
- The Access Graph model for correlating permissions across SaaS, cloud, data systems, and custom applications
- Examples of the identity context fields used to assess privilege risk, dormant access, and lateral movement potential
- How the platform frames least privilege for agentic workflows and machine identities in practice
- The vendor's explanation of how identity, workflow automation, and access governance are expected to converge
👉 Read Veza’s analysis of ServiceNow’s acquisition and identity governance implications →
ServiceNow and Veza: what this acquisition means for IAM teams?
Explore further
Identity context is becoming the control plane for AI-era access governance. The article points to a real shift: the question is no longer whether an identity exists, but whether its effective privilege, ownership, and blast radius are visible enough to govern. That aligns with OWASP-NHI and zero trust thinking, where access decisions depend on context rather than static assignment. Practitioners should treat context as the operating layer for both NHI and emerging agentic workflows.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which is exactly the kind of blind spot that turns identity context into a governance requirement.
A question worth separating out:
Q: Who should own AI agent access decisions and lifecycle controls?
A: AI agent access decisions should be owned by the team that deploys and operates the agent, with identity governance and security functions enforcing policy and review. Ownership must be explicit because autonomous behaviour creates accountability gaps if nobody is responsible for the agent's permissions, monitoring, and offboarding.
👉 Read our full editorial: ServiceNow acquires Veza: implications for identity governance