TL;DR: Identity security posture is deteriorating because identity platforms are not keeping pace with enterprise growth, incomplete data, and expanding non-human identities, according to Saviynt. The core problem is that identity governance assumes coverage, ownership, and auditability remain stable, but AI agents and machine identities are multiplying faster than programmes can classify and control them.
NHIMG editorial — based on content published by Saviynt: Fixing Organizations’ Identity Security Posture
By the numbers:
- Last year, 90% of breaches were related to identity.
- More than 60% of entitlements in an average identity platform implementation have poor descriptions or no description at all.
- 90% of entitlements either have the incorrect owner, owner or are missing a defined owner.
Questions worth separating out
Q: How should security teams improve identity posture when data quality is poor?
A: Start by treating identity metadata as control data.
Q: Why do ungoverned NHIs weaken IAM programmes?
A: Because ungoverned NHIs create access paths that are outside certification, monitoring, and lifecycle control.
Q: How do you know if an identity security programme is actually keeping up?
A: Look for evidence that coverage, ownership quality, and audit readiness are improving at the same pace as application growth.
Practitioner guidance
- Audit identity metadata quality at the entitlement level Review ownership, descriptions, tags, and classification fields for every high-risk application and access package.
- Measure governance coverage across all identity types Separate governed from ungoverned applications, service accounts, tokens, and AI agents, then track onboarding backlog as a risk metric.
- Reduce manual certification load with better decision context Precompute ownership, entitlement intent, and risk signals before review campaigns so approvers are not forced to guess.
What's in the full article
Saviynt's full blog covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of the four identity posture warning signs and how the vendor maps them to platform maturity.
- Example data-quality checks for ownership, entitlement naming, and audit readiness across large identity estates.
- Operational guidance for onboarding external identities, machine identities, and AI agents into the identity platform.
- Discussion of how modern identity security posture management is positioned inside a broader identity programme.
👉 Read Saviynt's analysis of identity security posture and NHI coverage gaps →
NHI sprawl and stale governance: is your identity posture keeping up?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity posture fails first at the metadata layer. When ownership, descriptions, and classifications are incomplete, the governance model loses the context it needs to make correct access decisions. That is not a visibility problem in the abstract. It is a decision-quality problem that contaminates recertification, audit readiness, and privilege cleanup. Practitioners should treat metadata hygiene as a core control surface, not an admin function.
A few things that frame the scale:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, which is why stale machine access remains a lifecycle problem rather than a one-time cleanup.
A question worth separating out:
Q: Who is accountable when an identity governance programme fails?
A: Accountability sits with the operating model owner, not just the product owner. If control requirements, deployment architecture, and human review processes are not aligned, the programme can look compliant while still allowing exposure to build. Governance needs an explicit owner for the control outcome, not only for the platform.
👉 Read our full editorial: Identity security posture is lagging as NHIs and AI agents grow