TL;DR: Identity has moved from administrative plumbing to the enterprise control plane, with permissions metadata, authorization paths, and micro-certifications now defining where risk lives and how AI governance must scale, according to Veza. Incremental IAM, PAM, and IGA tuning is no longer enough; the governing assumption that access can be understood through directories and periodic reviews has collapsed.
NHIMG editorial — based on content published by Veza: identity as the enterprise control plane for AI governance
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams govern access when permissions and usage do not match?
A: Treat the mismatch as a risk signal, not a reporting issue.
Q: Why do periodic access reviews struggle in AI-heavy environments?
A: Because risk changes faster than the review cycle.
Q: What do IAM teams get wrong about visibility into non-human identities?
A: They often stop at discovery.
Practitioner guidance
- Build an authorization inventory, not just an account inventory Map who can do what across systems, then classify inherited, delegated, and chained permissions separately from directory objects.
- Shift recertification toward micro-certification Apply shorter, context-bound access justification to sensitive entitlements and high-blast-radius permissions.
- Use graph context to find hidden exposure Model access relationships so teams can see how one permission opens another across systems.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- How Veza frames canonical authorization data as the foundation for identity transformation
- The operational logic behind micro-certifications and why they differ from periodic access reviews
- Why graph architectures matter for exposing chained permissions and hidden risk paths
- How the article links identity governance to AI governance without reducing either to login-centric controls
👉 Read Veza's analysis of identity as the enterprise control plane for AI governance →
Identity as the control plane: are IAM teams ready for AI governance?
Explore further
Identity has become the enterprise control plane, not a support function. The article is right to reject the old assumption that identity is mainly about directories and login events. Modern risk lives in permissions metadata, authorization paths, and contextual trust decisions, which means IAM, PAM, and IGA have to operate as one control system rather than separate silos. The practitioner implication is clear: if you cannot govern authorization, you cannot claim to govern identity.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
A question worth separating out:
Q: How do PAM and IGA need to change in the agentic AI era?
A: They need a shared authorization model that treats agent access as governed entitlement, not a special-case exception. PAM should control the highest-risk paths, while IGA should certify the underlying permissions graph that makes those paths possible. Without that alignment, the controls will describe different versions of the same risk.
👉 Read our full editorial: Identity as the enterprise control plane for AI governance