Join our Newsletter — 33% off our NHI Course

Service accounts, API keys, and AI agents: the NHI governance gap

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: IGA programs still miss the identities that now carry the most operational risk: service accounts, API keys, OAuth tokens, cloud service principals, and AI agent credentials, according to Zluri. NHI governance closes that blind spot by extending discovery, ownership, lifecycle, review, and audit controls to machine identities that were never tied to HR events.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “NHI Governance: How to Bring Service Accounts, API Keys, and AI Agents Into Your IGA Program”.

By the numbers:

  • Non-human identities outnumber human identities by 40 to 1 in the typical enterprise.
  • The NHI population grew 44% year-over-year between 2024 and 2025.

Key questions

Q: What problem does ownership attribution solve for service accounts and API keys?

A: It closes the gap between exposure detection and accountable remediation.

Q: Why do non-human identities create more risk than many human accounts?

A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review.

Q: How do teams know if NHI governance is actually working?

A: Look for complete inventory coverage, clear ownership, enforced rotation, and reliable decommissioning.

Practitioner guidance

  • Map every machine identity source Inventory service accounts, API keys, OAuth apps, cloud service principals and AI agent credentials across SaaS, cloud and code repositories before setting governance policy.
  • Assign a human owner at creation Require explicit ownership for every non-human identity so a named person or team can approve access, attest need and accept revocation responsibility.
  • Tie offboarding to application retirement Trigger revocation when the workload, integration or project ends, rather than waiting for a human leaver event that will never arrive for the identity itself.

Bottom line: Non-human identities create a governance gap because they are created outside HR-centric identity workflows and therefore escape standard joiner-mover-leaver controls.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

NHI governance is now a baseline identity control, not a specialised add-on. The article is right to frame service accounts, API keys and AI agent credentials as identities that need inventory, ownership and lifecycle governance. When machine identities are created outside HR, the old assumption that identity equals employee no longer holds. Practitioners should treat machine identity governance as a core IGA requirement, not a separate hygiene project.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What is the difference between secrets detection and NHI governance?

A: Secrets detection finds exposed credentials, while NHI governance tracks how those credentials are issued, reused, rotated, and retired. Detection answers whether a secret is visible. Governance answers whether the identity behind that secret is controlled throughout its lifecycle. Mature programmes need both because exposure without lifecycle control leaves the same risk open.

👉 Read our full editorial: NHI governance for service accounts, API keys, and AI agents


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.