Join our Newsletter — 33% off our NHI Course

Identity security maturity gaps: are NHIs and AI agents included?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Identity programmes need a shared maturity model spanning humans, non-human identities and AI agents, because most enterprises still operate in Partial maturity with fragmented visibility, manual reviews and disconnected workflows, according to Veza. The gap is that identity creation is outpacing governance, so least privilege, remediation and offboarding now depend on a unified access graph and continuous control.

Editorial analysis by NHI Mgmt Group, based on content published by Veza: “The Identity Security Maturity Model: A Roadmap to Least Privilege”.

Key questions

Q: What breaks when identity maturity models exclude NHIs and AI agents?

A: They misstate the real control boundary.

Q: Why do non-human identities make least privilege harder to enforce?

A: Because they often use persistent credentials, shared execution paths, and high-volume automation that makes manual review unrealistic.

Q: How do identity teams measure whether maturity is really improving?

A: Look at operational outcomes rather than tool adoption.

Practitioner guidance

  • Build a unified access graph Connect directories, HR, cloud and SaaS entitlements so humans, NHIs and agent access appear in one governed model.
  • Classify non-human identities as first-class subjects Inventory service accounts, API keys, secrets and AI agent credentials separately from human accounts so lifecycle and review processes can be applied correctly.
  • Wire remediation into existing workflows Route high-risk findings into SOC, ITSM and JML processes so privilege removal, ownership changes and deprovisioning happen inside normal operations.

Bottom line: The central problem is not a shortage of maturity language, but a maturity model that still leaves NHIs and AI agents outside the governing frame.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20752
 

Identity maturity is not meaningful if it excludes non-human identity. A model that measures humans, but leaves service accounts, API keys and agent access outside the governance frame, is describing only part of the risk surface. That omission is not a reporting quirk. It changes what the organisation believes it can control, and practitioners should treat any maturity score without NHI coverage as structurally incomplete.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations extend joiner, mover and leaver workflows to AI agents?

A: Yes, if the agents can hold credentials, call tools or access data independently. Offboarding and ownership transfer need to apply to those identities because access that is never lifecycle-managed becomes persistent risk, even when the system is fully automated.

👉 Read our full editorial: Identity security maturity models are missing NHI and AI agents


This post was modified 4 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.