TL;DR: Privileged inventory grows without clear decisions on what should be vaulted, made ephemeral, or retired, according to Hydden, and its identity data layer helps CyberIAM enrich each account with usage, ownership, and rotation context before control decisions are enforced. The core issue is not tool coverage alone but turning PAM findings into repeatable governance decisions.
NHIMG editorial — based on content published by Hydden: the use of identity data to decide which privileged accounts should be vaulted, made ephemeral, or retired
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How do teams know when a privileged account should be deprovisioned instead of vaulted?
A: An account should move toward deprovisioning when nothing depends on it, when usage is absent or obsolete, or when the service it supported has been replaced.
Q: Why do privileged account inventories keep growing even when PAM tools are in place?
A: Because discovery and enforcement are not the same thing.
Q: What signals show that a PAM programme is actually reducing risk?
A: Look for fewer unmanaged accounts, more accounts retired after review, tighter alignment between account behaviour and control path, and clearer ownership for every privileged identity.
Practitioner guidance
- Define a privileged account decision taxonomy Classify each discovered account into vault, JIT, ephemeral, secret-managed, or retire before any enforcement project begins.
- Separate scheduled work from standing privilege Treat accounts that support automated jobs, production tasks, or service integrations differently from interactive admin accounts.
- Continuously reconcile PAM findings with reality Recheck whether an account is still active, still owned, and still needed after onboarding.
What's in the full article
Hydden's full post covers the operational detail this analysis intentionally leaves for the source:
- The specific identity data fields used to classify each account before control assignment
- How CyberIAM maps discovered accounts into Idira vaulting, JIT, and Secrets Manager workflows
- The operating model for moving from discovery findings to enforced PAM policy
- Implementation detail on how the identity data layer supports decisioning across legacy and cloud environments
👉 Read Hydden's analysis of identity data for PAM decisioning →
PAM inventory decisions: what changes when identity data is the layer?
Explore further
Privilege governance fails when inventory growth is not matched by control decisioning. The problem is not that teams cannot find privileged accounts, but that they cannot reliably decide what each account should become. When discovery outpaces classification, the estate expands faster than policy can absorb it. The result is a programme that looks busy but does not reduce exposure in a measurable way. Practitioners should treat decision quality as a core PAM control, not an administrative afterthought.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own the decision to move an account from standing privilege to JIT or secret management?
A: Identity and PAM governance should own the policy, but the system owner and service owner must validate operational impact. The point is to make the decision from evidence and then enforce it through the platform, not to leave routing choices to ad hoc project teams.
👉 Read our full editorial: Hydden and Idira show how PAM decisions become enforceable