TL;DR: Non-human identities outnumber human identities by 92:1 in a typical enterprise, and the article argues that compliance programmes built for people leave service accounts, API keys, tokens, and AI agents under-governed, according to Entro Security. The compliance problem is structural: discovery, ownership, rotation, and monitoring must be treated as lifecycle controls, not after-the-fact audit tasks.
Editorial analysis by NHI Mgmt Group, based on content published by Entro Security: “The Compliance Black Hole: How Non-Human Identities Break the Rules”.
Key questions
Q: What breaks when compliance frameworks are applied to NHIs as if they were human users?
A: Human-centric compliance assumes a known person, a stable employment relationship and a reviewable access path.
Q: Why do NHIs create audit and accountability gaps in identity programmes?
A: Because many machine identities are created by workflows, inherited through integrations or embedded in automation, they often lack a clear owner and business justification.
Q: How should organisations prioritise NHI inventory versus rotation and monitoring?
A: Inventory comes first because you cannot rotate, revoke or monitor what you have not found.
Practitioner guidance
- Create an authoritative NHI inventory Map every service account, token, API key, certificate and integration to an owner, purpose, system and authentication path so audits can be completed from one source of truth.
- Bind ownership to every machine identity Require explicit business or technical ownership before an NHI is allowed into production, and revoke identities that cannot be attributed within your governance process.
- Automate secret rotation and revocation Set rotation and expiry policies by credential type, then remove stale or idle NHIs instead of allowing programmatic access keys to persist indefinitely.
Bottom line: Human-centric compliance frameworks leave machine identities exposed when ownership, inventory and rotation are not built into the control model.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Compliance black holes form when machine identities are governed as exceptions. Human-centric rules expect a person, a manager, and a review cycle, but NHIs often have none of those properties. That creates a structural blind spot where discovery, ownership and revocation never become reliable evidence. The practitioner conclusion is simple: if the identity subject is a machine, the governance model must be machine-native.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How do security teams know if NHI controls are actually working?
A: Look for complete inventory coverage, clear ownership, enforced rotation, and evidence that unused credentials are removed on time. If secrets remain active after changes to applications, vendors, or pipelines, the control is not working. Monitoring should also show whether machine access stays within the expected workload scope.
👉 Read our full editorial: Non-human identities create a compliance gap that human-centric rules miss