Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Veza and the enterprise agent identity control plane: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: A broader identity shift is putting control-plane strain on IAM, as 96,000 entitlements per worker, 38% dormant IdP accounts, and only 55% of permissions are safe and compliant show, according to Veza. The practical lesson is that entitlement sprawl, dormant accounts, and unsafe permissions now need to be governed as one lifecycle problem, not separate IAM tasks.

NHIMG editorial — based on content published by Veza: AI Veza Product Updates - April 2026 and related access control plane commentary

By the numbers:

Questions worth separating out

Q: How should security teams handle dormant accounts without leaving downstream access behind?

A: Treat the dormant account as the starting point, not the finish line.

Q: Why do AI agents complicate traditional IAM controls?

A: AI agents complicate traditional IAM controls because they do not behave like human users with short, predictable sessions.

Q: What breaks when permissions are reviewed without a graph of relationships?

A: Reviewing permissions in isolation misses inherited access, shared dependencies, and downstream entitlements that survive role changes or offboarding.

Practitioner guidance

  • Map entitlement relationships in one control plane Inventory how human accounts, service accounts, and agent identities relate to applications, data stores, and delegated permissions.
  • Re-certify dormant identities with downstream cleanup Do not stop at disabling the IdP account.
  • Unify review workflows for humans and non-humans Run access reviews from the same governance process, but segment by actor type so human, NHI, and agent permissions are evaluated with the right approval model and logging depth.

What's in the full article

Veza's full update covers the operational detail this post intentionally leaves for the source:

  • Product-level context on the April 2026 updates and how the control plane is positioned in the broader platform narrative.
  • Additional explanation of the enterprise agent identity control plane concept and how Veza connects it to access graph analysis.
  • Report framing around the 2026 State of Identity and Access findings, including how the vendor interprets entitlement sprawl and dormant accounts.
  • Broader product-update context from March and February 2026 that is not analysed here.

👉 Read Veza's April 2026 update on the enterprise agent identity control plane →

Veza and the enterprise agent identity control plane: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

The enterprise identity problem is now a control-plane problem, not an access-list problem. Once a typical worker carries 96,000 entitlements, the issue is no longer isolated over-permissioning. The issue is that governance can no longer be expressed as a simple review queue; it has to operate as a continuously updated relationship model across humans, NHIs, and agents. Practitioners should treat identity graph quality as a security control, not just an inventory feature.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which leaves most machine access outside continuous governance.

A question worth separating out:

Q: How can IAM teams prioritise cleanup when entitlement sprawl is extreme?

A: Start with high-impact paths first: production systems, privileged roles, and delegated access used by workloads or agents. Then target dormant accounts and broad entitlements that contribute to the largest blast radius. This approach reduces risk faster than trying to normalise the entire estate at once.

👉 Read our full editorial: Veza's April 2026 update spotlights the enterprise agent control plane



   
ReplyQuote
Share: