TL;DR: Identity programmes fail first at visibility, then at least privilege, and finally at runtime governance, with NHIs now outnumbering humans 20:1 and agentic AI set to intensify the problem, according to C1.ai. The real issue is that static access models cannot govern identities that proliferate faster than review, rotation, and offboarding cycles can keep pace.
NHIMG editorial — based on content published by C1.ai: Crawl, Walk, Run: Solving Your Identity Crisis
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams implement maturity-based identity governance for NHIs?
A: Start by defining maturity stages for visibility, lifecycle control, privilege management, and audit readiness.
Q: Why do least privilege programmes break down in real environments?
A: They usually break because access is copied, inherited, or left in place after a role change.
Q: What should organisations do before they automate access decisions?
A: They should make sure the underlying identity data is accurate, complete, and owned.
Practitioner guidance
- Build a unified identity inventory Create a single source of record for users, groups, service accounts, API tokens, certificates, and cloud roles.
- Rationalise group-based access Review high-risk groups, shared roles, and copied entitlements to identify where access is inherited rather than intentionally assigned.
- Separate baseline controls from runtime controls Use access reviews, role definitions, and onboarding guardrails to establish the baseline, then apply just-in-time access and contextual policy checks only where the risk justifies it.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- The article’s end-to-end crawl, walk, run maturity framing for identity governance.
- The vendor’s specific examples of how teams should sequence visibility, baseline controls, and runtime automation.
- The product-oriented interpretation of contextual and automated governance for modern enterprise environments.
- The article’s commentary on how agentic AI changes onboarding and offboarding expectations.
👉 Read C1.ai’s blog on solving modern identity governance gaps →
Identity governance gaps: are your controls keeping up?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity visibility debt is the first governance failure. The article correctly starts with the reality that organisations cannot secure identities they cannot enumerate. That is the core identity visibility debt problem: unknown users, unknown NHIs, and unknown privilege relationships create blind spots that compound over time. In practice, this is why IAM, IGA, and NHI governance must share a single inventory baseline rather than separate tooling views.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: What problem does ownership attribution solve for service accounts and API keys?
A: It closes the gap between exposure detection and accountable remediation. Many organisations can find the secret, but not the human who introduced it, maintains it, or can safely replace it. Ownership attribution gives security teams a practical way to assign action without relying on informal knowledge that disappears during staff changes.
👉 Read our full editorial: C1.ai’s crawl, walk, run model exposes identity governance gaps