TL;DR: Identity programmes need a shared maturity model spanning humans, non-human identities and AI agents, because most enterprises still operate in Partial maturity with fragmented visibility, manual reviews and disconnected workflows, according to Veza. The gap is that identity creation is outpacing governance, so least privilege, remediation and offboarding now depend on a unified access graph and continuous control.
NHIMG editorial — based on content published by Veza: Identity Security Maturity Model and the path to least privilege
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should security teams implement maturity-based identity governance for NHIs?
A: Start by defining maturity stages for visibility, lifecycle control, privilege management, and audit readiness.
Q: Why do NHIs create problems for simplified identity governance?
A: NHIs often outnumber human identities, change less visibly, and carry access that is hard to describe in a simple catalog.
Q: What breaks when access reviews are the primary identity control?
A: The control breaks because access can change, be abused, and disappear between review cycles.
Practitioner guidance
- Build a unified access graph Integrate HR systems, directories, cloud platforms, SaaS apps and critical applications into a single access graph so identity risk can be queried and prioritised consistently.
- Use risk-based prioritisation Separate dormant access, over-privileged accounts and wildcard policies by business impact and effort so remediation capacity goes to the highest-value fixes first.
- Wire remediation into existing workflows Push findings into SOC tooling, ITSM, Joiner-Leaver-Mover processes and owner notifications so access issues turn into action instead of more reporting.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- The full five-pillar maturity model with stage-by-stage examples of what Partial, Informed, Repeatable and Adaptive look like in practice.
- The access graph implementation approach, including the data sources and identity relationships needed to make remediation actionable.
- The distinction between identity security and identity governance operating lanes, and how teams divide responsibilities across them.
- The concrete next-step workflow mapping Veza uses when organisations want to move from assessment to implementation.
👉 Read Veza's identity security maturity model for human, NHI and AI agent governance →
Identity security maturity gaps: are NHIs and AI agents included?
Explore further
Identity maturity cannot be measured by tooling count alone. The article correctly treats maturity as a capability model, not a product inventory. Organisations often have scripts, reviews and scattered controls, yet still lack a shared operating model for visibility, prioritisation and remediation. That is why identity programmes stall in Partial maturity even when teams believe they are modernised.
A few things that frame the scale:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
- A separate finding shows that only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities.
A question worth separating out:
Q: How do organisations know whether identity visibility is actually improving?
A: Look for faster answers to access questions, fewer unresolved toxic combinations, better ownership coverage, and a smaller gap between what separate tools report and what the enterprise access model shows. If remediation still depends on manual reconciliation, visibility has not yet become operational intelligence.
👉 Read our full editorial: Identity security maturity models are missing NHI and AI agents