TL;DR: Identity governance built for people is no longer sufficient for modern enterprises, Linx Security says, with service accounts, APIs, workloads, and AI agents now creating the larger share of access risk, while Sophos reports 71% of organisations had at least one identity-related incident in the past year. The shift to identity-centric IAM extends ownership, least privilege, lifecycle management, and access review to every identity type, but it also exposes the limits of governance models that still assume humans are the primary unit of control.
NHIMG editorial — based on content published by Linx Security: Why Identity-Centric Security Is Replacing Human-Centric IAM
By the numbers:
- 71% of organizations experienced at least one identity-related security incident over the past year, with affected organizations averaging three incidents each.
Questions worth separating out
Q: How should security teams govern non-human identities alongside human accounts?
A: Security teams should govern non-human identities as a separate lifecycle category with their own inventory, ownership, rotation, and offboarding controls.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect.
Q: What breaks when identity governance stays focused only on employees?
A: Blind spots open up around identities that are not tied to a person, including APIs, workloads, certificates, and agents.
Practitioner guidance
- Build a single inventory of all identity types Map employees, contractors, service accounts, API credentials, workload identities, and AI agents into one governed estate so ownership and exposure are visible in the same system.
- Assign explicit owners to every non-human identity Require a named business or engineering owner for each service account, workload identity, API credential, and AI agent.
- Replace standing access with task-scoped permissions Reduce always-on permissions wherever the workload or agent can operate with short-lived access.
What's in the full article
Linx Security's full article covers the operational detail this post intentionally leaves for the source:
- The full identity-centric IAM operating model for workforce, service accounts, APIs, workloads, and AI agents.
- The governance questions the vendor uses to map ownership, review, and retirement across identity classes.
- The practical relationship between just-in-time access and continuous access review in the vendor's implementation context.
- The product framing for AI Access Control and how the vendor positions it within identity governance workflows.
👉 Read Linx Security's analysis of identity-centric IAM for human and non-human identities →
Identity-centric IAM: what changes for NHI and AI agent teams?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity-centric IAM is the governance model the enterprise already needs. The article is right to frame this as an expansion of IAM rather than a replacement. Human-centric controls still matter, but they are no longer sufficient when machine identities and AI agents can access the same business systems as employees. The practical conclusion is that governance has to follow the identity, not the job title.
A few things that frame the scale:
- 88.5% of organizations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which shows how wide the assurance gap remains.
A question worth separating out:
Q: How do organisations know if identity security posture management is working?
A: It is working if posture findings lead to measurable entitlement reduction, fewer stale accounts, and shorter remediation cycles. Dashboards alone are not enough. The signal is whether over-scoped access is being removed, reviewed, and tied back to accountable owners before it becomes an audit or breach issue.
👉 Read our full editorial: Identity-centric IAM is replacing human-centric governance