TL;DR: Privileged access management is shifting from isolated credential vaulting to an embedded identity fabric as cloud, DevOps, NHIs, and AI agents expand the access surface, according to SSH Communications Security's Customer Advisory Board presentation with KuppingerCole analyst Alejandro Leal. Access review and static privilege models assume stable, human-paced administration, but that assumption breaks when ephemeral workloads and autonomous systems move faster than review cycles.
Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “From Vaulting to Vision: A Front-Row Look at the Future of PAM”.
Key questions
Q: How should teams govern privileged access when NHIs and AI agents share production systems?
A: Treat privileged access as a runtime governance problem, not a vault problem.
Q: Why do static PAM and access review models fail for ephemeral workloads and AI agents?
A: They assume access persists long enough to be observed, certified, and removed on a human schedule.
Q: What breaks when PAM is treated as separate from IAM?
A: Governance breaks first.
Practitioner guidance
- Map privileged access across the identity fabric Identify where IAM, IGA, PAM, and CIEM each hold policy, entitlement, logging, and response responsibility so machine and human access is governed coherently.
- Reclassify NHIs and AI agents as governed privileged identities Inventory APIs, containers, bots, ephemeral workloads, and AI agents that can reach protected systems, then assign explicit ownership and access scope for each.
- Move reviews from standing access to issuance and session context Use runtime telemetry, approval context, and short-lived entitlements to decide access at the point of use rather than relying on delayed certification cycles.
Bottom line: PAM is moving from isolated credential handling to a runtime control layer for NHIs, workloads, and AI agents.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
PAM is becoming runtime identity infrastructure, not a vault service. The article reflects a structural shift in how privileged access is governed across cloud, automation, and machine identities. Once access is created and consumed by NHIs, bots, and AI agents, the control value moves from storing secrets to enforcing entitlement, telemetry, and response at runtime. Practitioners should treat PAM as part of the access control fabric, not an isolated control.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should organisations balance crypto-agility with privileged access governance?
A: Treat them as linked controls. Crypto-agility reduces the cost of replacing cryptographic primitives, while privileged access governance reduces the lifespan of the credentials those primitives protect. Organisations that combine both can narrow the window in which harvested material stays useful and lower the operational burden of transition.
👉 Read our full editorial: PAM is becoming identity infrastructure for NHIs and AI agents