TL;DR: Identity security has evolved in reverse compared with endpoint, network, and cloud: detection and posture arrived before continuous identity recordkeeping, leaving teams with current-state views but no historical system of record, according to Hydden. That gap undermines audit evidence, incident reconstruction, and access review accuracy because identity programmes still cannot answer what changed, when, and why.
NHIMG editorial — based on content published by Hydden: Identity security needed a system of record first, not another detector
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: What breaks when identity teams rely only on current-state visibility?
A: Current-state visibility cannot prove how long access existed, who changed it, or whether a risky state already survived previous reviews.
Q: Why do identity programmes need historical recordkeeping as well as detection?
A: Detection needs context to rank anomalies, and context comes from history.
Q: What do security teams get wrong about identity visibility in modern environments?
A: They often treat directory completeness as the same thing as identity visibility.
Practitioner guidance
- Establish a historical identity record layer Capture identity changes continuously across directories, SaaS, cloud roles, local accounts, and privileged systems so you can answer what changed and when.
- Link accounts to one identity subject Reconcile employee records, service accounts, roles, and local identities into one lineage model so ownership and accountability survive system boundaries.
- Rank alerts using identity history Feed detection workflows with entitlement history, ownership, and change timestamps so anomalies are scored against context rather than treated as equal.
What's in the full article
Hydden's full article covers the operational detail this post intentionally leaves for the source:
- The identity system-of-record architecture the vendor says it is building for historical change capture.
- How identity records are reconciled across directories, SaaS, local accounts, and privileged systems.
- How access reviews, privileged cleanup, and alert context change when every identity state is preserved.
- What problems the vendor believes a record solves that point tools and exports do not.
👉 Read Hydden's analysis of why identity security needs a system of record →
Identity system of record: why visibility still leaves gaps?
Explore further
The identity market is solving the wrong layer first. Detection, posture, and visibility are useful, but they all sit above the missing base layer: the record of what happened to identity over time. That inversion explains why programs keep buying point tools while still struggling with audit evidence and access cleanup. The practitioner conclusion is simple: treat historical identity recordkeeping as the prerequisite, not the finishing touch.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Another finding from the same research shows that 71% of NHIs are not rotated within recommended time frames, which helps explain why identity history matters so much.
A question worth separating out:
Q: How should organisations build a usable system of record for identity?
A: They should collect identity changes from the systems that grant access, normalise accounts to a single subject, and preserve every change instead of overwriting the last known state. That gives IAM and PAM teams a durable basis for recertification, cleanup, and incident analysis.
👉 Read our full editorial: Identity security needed a system of record first, not another detector