TL;DR: Mergers, acquisitions, and divestitures create identity sprawl across human accounts, service accounts, secrets, and AI agents, leaving visibility gaps that legacy IGA and cloud identity tools cannot close, according to Veza. The core issue is not just integration speed but the loss of trustworthy permission-level control across both combined and separated environments.
NHIMG editorial — based on content published by Veza: identity governance in mergers, acquisitions, and divestitures
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
Questions worth separating out
Q: What breaks when identity integration is delayed in a merger?
A: When identity integration is delayed, the merged organisation inherits inconsistent authentication, uneven access policy, and manual exception handling.
Q: When should organisations prioritise permission-level visibility over broader IGA cleanup?
A: They should prioritise permission-level visibility as soon as a transaction is underway or anticipated, because access questions become time-critical during due diligence, integration, and divestiture.
Q: What do security teams get wrong about NHI governance in M&A programmes?
A: They often treat service accounts and API keys as secondary to human identities, even though those machine accounts can retain broad access across inherited systems.
Practitioner guidance
- Map effective permissions before any consolidation decision Normalise directory, app, and resource-level entitlements so transaction teams can see what identities can actually do across both organisations.
- Inventory NHI ownership during deal due diligence Create an explicit owner record for service accounts, API keys, cloud roles, automation identities, and AI agents.
- Use targeted micro-certifications for divestiture separation Run narrow access certifications against the systems, roles, and accounts that will move out of scope.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- Permission-level visibility workflows for consolidating acquired identity stores
- Micro-certification and guardrail patterns for divestiture separation
- Examples of NHI and AI agent discovery across merged environments
- Operational details on mapping effective permissions into natural-language access views
👉 Read Veza's analysis of identity governance in mergers, acquisitions, and divestitures →
M&A identity sprawl: what identity teams miss during integration?
Explore further
Identity debt is the true M&A security liability. The article is right to frame merger and divestiture risk as more than a directory-consolidation problem. What breaks first is not the login flow but the trust that identity data is complete enough to support legal, operational, and audit decisions. When effective permissions are hidden behind nested groups, inherited roles, and system-specific semantics, the organisation cannot prove separation or continuity with confidence. Practitioners should treat identity debt as a transaction-level control risk, not an implementation inconvenience.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which explains why transaction-driven access reviews so often miss inherited machine credentials.
A question worth separating out:
Q: Who is accountable for access separation when divestitures involve shared systems?
A: The acquiring and divesting organisations both remain accountable until access separation is provable, because shared systems create overlapping control obligations. Regulatory teams will expect evidence that privileged access, orphaned accounts, and residual entitlements were identified and removed without breaking the remaining business. The practical answer is to assign explicit ownership and validate each removal step.
👉 Read our full editorial: M&A identity sprawl exposes NHI and AI agent governance gaps