TL;DR: Security operations now depend on effective permissions, not just authentication, according to Veza. That shift matters because containment fails when teams cannot map blast radius fast enough or prove least-privilege changes with audit evidence, and Veza positions its Access Graph, Access AI, VQL, and Actions as the operational layer for finding, interrogating, and changing access across human and non-human identities.
NHIMG editorial — based on content published by Veza: Security Operations with Access Graph, Access AI, VQL, and Actions
By the numbers:
- The ratio of non-human to human identities now exceeds 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
Questions worth separating out
Q: How should security teams contain a compromised identity without losing control evidence?
A: Teams should first map the identity’s effective permissions, then scope access changes through approved workflows that record who authorised the action and what changed.
Q: Why do non-human identities increase identity blast radius?
A: Non-human identities often run continuously, hold broad permissions, and connect multiple services at machine speed.
Q: What breaks when access review is disconnected from incident response?
A: Access review becomes a compliance exercise instead of a control.
Practitioner guidance
- Map effective permissions before containment Build incident workflows that resolve identities, groups, roles, ACLs, and inherited rights to the objects they can actually reach.
- Prioritise high-risk service accounts and tokens Inventory non-human identities with production reach, recent use, and broad write or delete rights.
- Route remediation through governed change paths Tie access reduction to ITSM, SOAR, or approval workflows so every containment step produces an audit trail and an accountable owner.
What's in the full article
Veza's full analysis covers the operational detail this post intentionally leaves for the source:
- Access Graph workflow examples that show how identities, roles, policies, ACLs, and resource metadata are resolved into effective permissions
- Access AI and VQL use cases for path-aware hunts across inherited rights, service accounts, and sensitive data objects
- Actions examples showing how containment changes move through ITSM, SOAR, IdP, and chatops with approval evidence
- Proof and measurables for time to know, time to contain, entitlement reduction, and NHI hygiene tracking
👉 Read Veza’s analysis of identity-led security operations and Access Graph workflows →
Access graphs and identity-led containment: are your controls keeping up?
Explore further
Access graphs are becoming the operational truth layer for identity security. Spreadsheet-centric access review cannot keep pace with inherited rights, nested groups, and machine identities that outnumber humans by orders of magnitude. The field is moving toward permission intelligence because containment and audit both depend on effective access, not theoretical entitlements. Practitioners should treat graph visibility as a core control surface, not a reporting convenience.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own permission reduction decisions during a security incident?
A: Ownership should sit with the security operation that can correlate identity, data impact, and business risk, but every change should still route through the system owner and access approver. The best model is shared accountability with a single operational record, because identity changes affect both security and production stability.
👉 Read our full editorial: Veza’s secops model reframes identity security as a live control plane