TL;DR: Inventory, rotation, and ownership tracking do not close non-human identity risk when AI agents and machine accounts can still act far beyond their intended scope at runtime, according to EnforceAuth research. Authorization, not authentication hygiene, is the control boundary that decides whether NHIs can touch the right data and actions.
Editorial analysis by NHI Mgmt Group, based on content published by EnforceAuth: “You Authenticated Your Machine Identities. You Forgot to Authorize Them.”.
By the numbers:
- 45:1 is the ratio of non-human identities to humans in the enterprise, according to EnforceAuth.
- 60% of NHI credentials are either stale or carry more privilege than the workload requires, according to EnforceAuth.
- around 31% of breaches involve stolen credentials, according to EnforceAuth.
Key questions
Q: What breaks when NHI governance relies on inventory alone?
A: Inventory alone tells you what credentials exist, but not whether they are active, over-scoped, shared, or being used by an agent at runtime.
Q: Why do unmanaged non-human identities increase incident impact so quickly?
A: Because no real person is continuously watching the identity, compromise can continue until monitoring catches it or an outage exposes it.
Q: How do security teams know if NHI authorization is actually working?
A: Look for consistent allow and deny decisions at runtime, complete audit logs for each request, and fewer services that need code-level permission checks.
Practitioner guidance
- Define action-level authorization for NHIs Map each service account, API key, machine credential, and AI agent token to the specific actions, data classes, and workflows it may touch.
- Move enforcement to the decision point Require a policy check at runtime before any non-human identity can read, write, invoke, or chain a sensitive action.
- Separate discovery from governance metrics Track not only how many NHIs exist, but how many have explicit denied actions, scoped datasets, and auditable runtime decisions.
Bottom line: The article argues that non-human identity programmes fail when they stop at discovery and credential hygiene, because neither control answers what the identity may do at runtime.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authorization is the missing control plane for non-human identities: discovery and rotation solve inventory and credential freshness, but they do not govern what an authenticated machine identity may do at runtime. That gap becomes the operational failure point when service accounts, API keys, and AI agents are allowed to act without a policy decision on the actual request. The implication is that NHI governance must be measured by enforced authorisation, not by asset count alone.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should teams govern AI agent access to production data?
A: Treat agent actions as runtime events that need policy checks at execution time, not just pre-approved credentials. High-risk reads, writes, and deletes should be bounded by context, session limits, and approval gates that apply before the command completes.
👉 Read our full editorial: Non-human identity governance fails when authorization is missing