TL;DR: Frost, GigaOm, and Gartner are converging on the same answer: enterprises need a graph-backed identity control layer that can continuously explain effective access, NHI exposure, and posture drift across systems, according to Veza. That matters because static reviews cannot keep pace with the identity attack surface once NHIs, AI services, and cross-platform entitlements multiply.
NHIMG editorial — based on content published by Veza: access graph architecture and the analyst signals around NHI, ISPM, and IVIP
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should security teams govern non-human identities in cloud environments?
A: Start with complete discovery, because you cannot govern what you cannot see.
Q: Why do access graphs matter for identity governance programs?
A: Access graphs matter because they show effective access, not just directory membership.
Q: What breaks when identity reviews are based only on human-readable directories?
A: Reviews break when they ignore effective permissions created by cloud roles, policy inheritance, and machine-to-machine trust paths.
Practitioner guidance
- Stand up a single effective-access model Unify identities, entitlements, policies, and resources in one graph or equivalent decision layer so reviews and remediation run on live access rather than directory records.
- Treat NHI ownership as mandatory governance metadata Assign an accountable owner to every service principal, automation account, connector, and token so unowned machine access can be reviewed and removed on a defined cadence.
- Move identity posture into operations Track excessive privileges, dormant access, and toxic combinations continuously, then route findings into ITSM, IAM workflows, or PAM approvals so the issue becomes a change, not just a report.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- How Veza maps access graph relationships across IdPs, clouds, SaaS, and data systems for effective-permission analysis
- The patent-backed architecture behind graph normalization, risk inference, and governance workflow integration
- Specific analyst references and report names that map Frost, GigaOm, and Gartner language to the platform model
- Product-level examples of Access Intelligence, Access Monitoring, and Access AI in live environments
👉 Read Veza's analysis of access graph architecture and identity posture →
Access graphs and identity posture: what IAM teams are missing?
Explore further
Access graph architecture is becoming the control plane for identity security. The article is really describing a shift from identity inventory to identity decisioning. Once effective access spans cloud, SaaS, data, and automation, static directory views stop being enough for governance, detection, and remediation. Practitioners should treat graph-based visibility as the layer that binds IAM, IGA, PAM, and NHI controls together.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Another finding from the same research shows that 97% of NHIs carry excessive privileges, which explains why identity graphs and continuous review matter.
A question worth separating out:
Q: How do security teams know whether identity posture management is working?
A: It is working when unused permissions disappear, stale credentials are removed, and high-risk roles are reduced before they are abused. A healthy programme should show fewer orphaned identities, lower standing privilege, and faster remediation of exposed secrets across both cloud estates.
👉 Read our full editorial: Access graph architecture is becoming the identity control layer