TL;DR: Fragmented controls, patchworked tooling, and evolving risk across human and non-human access are shaping cloud identity as a 6-phase maturity model, with special attention to ephemeral workloads and AI agents, according to P0 Security. The useful lesson is that access strategy now has to be benchmarked as a spectrum, not a checklist, because governance failures show up differently by actor type.
NHIMG editorial — based on content published by P0 Security: Production access is a mess. Here’s how to improve your journey
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should security teams measure identity security maturity across human and machine identities?
A: Security teams should measure maturity across governance, tooling, operating model, and talent, then test whether those controls cover both human and machine identities.
Q: Why do ephemeral workloads complicate traditional IAM and access review processes?
A: Because the identity may exist for minutes or hours, while access review cycles operate on days or weeks.
Q: What do teams get wrong about cloud identity security?
A: Teams often assume that strong application security controls automatically neutralise the risk created by shared infrastructure.
Practitioner guidance
- Build a single identity maturity baseline Score human, workload, service account, and agent access against the same phases so teams can compare visibility, review, and privilege state consistently.
- Trace production access end to end Document where credentials are issued, where they are stored, how they are scoped, and who can revoke them across cloud and SaaS environments.
- Separate ephemeral from persistent access Treat short-lived workload access as a distinct governance class and verify that revocation, logging, and owner assignment still function when the identity disappears quickly.
What's in the full article
P0 Security's full field guide covers the operational maturity framework this post intentionally leaves at the strategy level:
- Phase-by-phase maturity guidance for human and non-human access programmes
- Patterns and traps that help teams benchmark where their cloud identity controls actually sit
- Practical framing for prioritising access improvements across ephemeral workloads and AI agents
- A structured model for communicating identity risk to CISOs and platform owners
👉 Read P0 Security's field guide on cloud identity maturity and access strategy →
Cloud identity maturity: where are human and non-human controls breaking down?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Cloud identity maturity is now a cross-actor governance problem, not a human IAM problem with extra machine accounts attached. The field guide is useful because it frames access as a spectrum that spans users, service accounts, workloads, and AI-enabled systems. That matters for IAM leaders because lifecycle, review, and privilege controls only hold if the same governance language applies across all actor types.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: How can security teams know if cloud identity governance is actually working?
A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review. If teams still spend days reconstructing access state, governance is not operating continuously. Effective programmes can show current MFA coverage, role scope, and credential age on demand.
👉 Read our full editorial: Cloud identity maturity is fragmenting across human and non-human access