Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

CIEM governance and NHI support: what changes for IAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 8534
Topic starter  

TL;DR: KuppingerCole named SailPoint’s Cloud Infrastructure Entitlement Management solution an overall leader in its latest Leadership Compass after evaluating 14 vendors, according to SailPoint. The governance signal is clear: CIEM is moving from a point capability to a broader identity control plane, and NHI support will raise the bar further, while noting SIEM support across 10 mainstream third-party applications and tighter integration into the SailPoint platform.

NHIMG editorial — based on content published by SailPoint: SailPoint named a leader in Cloud Infrastructure Entitlement Management

By the numbers:

Questions worth separating out

Q: How should security teams govern cloud entitlements alongside IAM and IGA?

A: They should treat cloud entitlements as part of the same identity governance lifecycle, not as a separate cloud-only review stream.

Q: Why do non-human identities complicate CIEM programmes?

A: Non-human identities complicate CIEM because service accounts, tokens, and workload identities do not follow human review patterns.

Q: What breaks when CIEM does not cover machine identities?

A: The governance model breaks at the point where cloud access reviews assume all access belongs to a person.

Practitioner guidance

  • Map CIEM into the broader identity control plane. Define where entitlement review, access certification, and privileged access workflows intersect so CIEM findings do not sit outside IAM and IGA decision-making.
  • Validate NHI coverage before treating CIEM as complete. Check whether the platform can represent service accounts, API keys, tokens, and workload identities with the same review logic used for human access.
  • Correlate entitlement findings with detection data. Use SIEM integration to test whether risky permissions are dormant, actively used, or associated with unusual cloud activity.

What's in the full article

SailPoint's full blog covers the operational detail this post intentionally leaves for the source:

  • The analyst report language quoted by SailPoint, including the exact criteria behind the leader designation.
  • The product-side context for how CIEM sits inside the SailPoint dashboard and platform workflow.
  • The roadmap note about non-human identities, which matters if you need to understand future scope rather than current capability.
  • The source article's own framing of cloud access management and entitlement governance in one place.

👉 Read SailPoint’s blog on its CIEM leader recognition and NHI roadmap →

CIEM governance and NHI support: what changes for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 1 month ago
Posts: 7990
 

CIEM is becoming an identity governance control plane, not a cloud add-on. The market is moving past narrow entitlement visibility and toward platforms that sit closer to review, risk, and access control decisions. That shift matters because cloud permissions are now part of the same governance problem as IAM, PAM, and NHI oversight. Practitioners should read this as a signal to align CIEM with the broader identity programme, not bolt it on as a separate cloud tool.

A few things that frame the scale:

  • 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to The 2026 Infrastructure Identity Survey.
  • A second finding from the same survey shows that only 13% of organisations feel extremely prepared for the reality of agentic AI, which helps explain why entitlement governance is lagging behind deployment.

A question worth separating out:

Q: When should organisations expand CIEM beyond cloud permissions alone?

A: They should expand it when entitlement risk is already being managed across multiple identity types and security teams need one decision path for review and response. If cloud access, PAM, and NHI governance are already overlapping in practice, a narrow CIEM scope will create duplicated control logic and inconsistent accountability.

👉 Read our full editorial: CIEM becomes a platform issue as SailPoint adds NHI support



   
ReplyQuote
Share: