Join our Newsletter — 33% off our NHI Course

M&A identity sprawl: what identity teams miss during integration

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Mergers, acquisitions, and divestitures create identity sprawl across human accounts, service accounts, secrets, and AI agents, leaving visibility gaps that legacy IGA and cloud identity tools cannot close, according to Veza. The core issue is not just integration speed but the loss of trustworthy permission-level control across both combined and separated environments.

Editorial analysis by NHI Mgmt Group, based on content published by Veza: “Taming the M&A Chaos: How Veza Addresses Identity Security Risks During Mergers, Acquisitions, and Divestitures”.

Key questions

Q: What breaks when identity governance is not aligned during M&A?

A: The first break is usually visibility, followed by inconsistent provisioning and delayed revocation.

Q: Why do non-human identities make M&A risk harder to control?

A: Non-human identities are harder to govern because they often have persistent permissions, limited ownership and no obvious business custodian.

Q: How should teams prove access is separated during a divestiture?

A: Teams should prove separation by testing who can still reach the systems, data and automation that belong to the other side of the transaction.

Practitioner guidance

  • Map effective permissions before integration Inventory the acquired or divested environment at permission level, not just by directory, group or role, so you can see what access actually exists before it is merged or removed.
  • Assign ownership to all non-human identities Identify service accounts, API keys, bots, cloud roles and AI agents, then attach a named owner and business purpose before they are carried into the new operating model.
  • Validate access boundaries during divestiture Use boundary-specific reviews to prove that identities from one entity cannot still reach systems, data or automation in the separated entity.

Bottom line: M&A creates identity sprawl that hides effective access, which is why directory-level visibility is not enough for either integration or separation.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 13 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20760
 

Identity sprawl is the real M&A control failure, not integration delay. When identity estates are merged or carved apart, the loss of permission-level truth is what creates security and compliance exposure. Legacy IGA can struggle with nested inheritance and role translation, so the programme cannot prove who really has access to what. The practitioner takeaway is that M&A should be governed as a control-verification event, not just a systems project.

A few things that frame the scale:

  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should IAM teams prioritise after a merger closes?

A: They should prioritise permission truth, ownership assignment and risk-based review of the identities most likely to preserve hidden access. That means focusing on effective permissions, orphaned accounts and non-human identities before consolidating directories or standardising roles.

👉 Read our full editorial: M&A identity sprawl exposes NHI and AI agent governance gaps


This post was modified 13 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.