Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Cross-application risk and AI agents: what IAM teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Access risk is no longer contained within single applications because workflows, entitlements, NHIs, and AI agents now span interconnected systems, making cross-application risk the real governance problem, according to Saviynt. Traditional app-centric reviews miss combinations of benign privileges that become toxic when identity follows the process across the enterprise, per Saviynt.

NHIMG editorial — based on content published by Saviynt: What Cross-Application Risk Actually Looks Like

By the numbers:

Questions worth separating out

Q: How should security teams govern policy-based access control across multiple applications?

A: Start by inventorying every policy source, then map ownership, review cadence, and enforcement points into one control process.

Q: Why do non-human identities increase data leakage risk?

A: Non-human identities increase leakage risk because they often have broad machine-to-machine reach, long-lived or reused credentials, and limited human review.

Q: What do security teams get wrong about separation of duties?

A: They often treat SoD as a role design problem instead of an effective permissions problem.

Practitioner guidance

  • Model effective access across systems Build review workflows that evaluate what an identity can do when permissions are combined across ERP, SaaS, cloud, ticketing, and privileged tools.
  • Correlate human, NHI, and agent access Create one identity graph that ties users, service accounts, API keys, and AI agents to the applications they touch.
  • Recalculate risk continuously Move from quarterly certification to continuous risk scoring when new applications, roles, or automations are connected.

What's in the full article

Saviynt's full blog post covers the operational detail this analysis intentionally leaves for the source:

  • The specific application access governance framing and the vendor's examples of effective access across business workflows
  • The product-level way the source describes cross-application identity correlation and continuous monitoring
  • The operational model for enterprise-wide SoD analysis across human users, NHIs, and AI agents
  • The vendor's explanation of how application access governance differs from traditional IGA in day-to-day use

👉 Read Saviynt's analysis of cross-application risk and continuous identity governance →

Cross-application risk and AI agents: what IAM teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Cross-application risk is the new identity governance boundary. Traditional IGA was designed around a question that is now too small: who has access to this application? Modern enterprise risk emerges from what an identity can do across applications, infrastructure, and automated workflows. That means the real control boundary is no longer the app owner’s domain, and practitioners need enterprise-wide effective access analysis rather than isolated entitlement review.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which explains why cross-application effective access is so hard to govern.

A question worth separating out:

Q: How do organisations know whether cloud access controls are actually working?

A: They know controls are working when discovery, classification, and remediation produce consistent outcomes across sanctioned and unsanctioned apps. If teams can identify risky services but cannot change access, quarantine data, or update policy, the control is reporting on risk rather than reducing it.

👉 Read our full editorial: Cross-application risk shows why identity governance must go continuous



   
ReplyQuote
Share: