Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Non-human identity access reviews: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19696
Topic starter  

TL;DR: Access certification for non-human identities is still handled ad hoc, leaving service accounts, machine tokens, and API keys active for years without formal oversight, according to SailPoint. The governance gap is not visibility alone, but the assumption that human review processes can be applied to machine-scale access without redesign.

NHIMG editorial — based on content published by SailPoint: Bringing access reviews to your non-human identities

By the numbers:

Questions worth separating out

Q: How should security teams run access reviews for non-human identities?

A: Security teams should scope reviews by risk pattern, assign every identity to an accountable owner, and require a documented decision for each item in scope.

Q: What breaks when service accounts are excluded from access reviews?

A: You lose confidence that machine access still matches business need, and you also lose the evidence needed to prove control effectiveness.

Q: How do you know if NHI access certification is actually working?

A: A working programme reduces orphaned, idle, exposed, and over-permissioned credentials while producing clear decision logs for every case.

Practitioner guidance

  • Scope campaigns by lifecycle state Start with orphaned, idle, exposed, former-employee, non-expiring, and over-permissioned credentials.
  • Automate first-pass triage Disable idle credentials, reassign obvious ownership, and route only unresolved cases to human reviewers.
  • Require evidence-rich disposition records Capture who reviewed the credential, what decision they made, when it was made, and whether the action was automated or manual.

What's in the full article

SailPoint's full blog covers the operational detail this post intentionally leaves for the source:

  • Prebuilt campaign templates for orphaned, idle, high-risk, non-expiring, former-employee, exposed, and over-permissioned NHIs
  • The workflow for triaging credentials before owners are involved, including disablement and reassignment paths
  • How campaign admins export decision logs and track pending, in-progress, and resolved items
  • The provider-console handoff steps for cases that cannot be automated directly

👉 Read SailPoint's blog on access reviews for non-human identities →

Non-human identity access reviews: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19287
 

Human certification models do not scale to machine identity governance. Access reviews were built around a stable human subject, but NHIs are often ownerless, hidden across systems, and created outside formal provisioning paths. That means the governance unit is no longer the employee record, but the credential state and its lifecycle context. Practitioners should stop treating NHI review as a variant of user recertification and start treating it as its own control domain.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.

A question worth separating out:

Q: Who should be accountable for non-human identity governance?

A: Accountability should sit with the team that owns the workload or automation, with IAM and PAM providing the control model and enforcement. If ownership is split across DevOps, security, and IT without a single decision maker, non-human identities tend to accumulate stale access, untracked secrets, and unclear exception handling.

👉 Read our full editorial: Access reviews for non-human identities expose the governance gap



   
ReplyQuote
Share: