TL;DR: Enterprise identity governance must now cover human users, non-human service accounts, and autonomous AI agents, because periodic access reviews cannot keep pace with access that changes in real time, according to Oleria Security. The core issue is not just scale, but the collapse of assumptions behind legacy IGA when AI-driven identities widen the governance gap daily.
Editorial analysis by NHI Mgmt Group, based on content published by Oleria Security: “Oleria Names Co-Founder Jagadeesh Kunda CEO to Advance Identity Governance in the Age of AI”.
Key questions
A: Security teams should treat AI agents, service accounts, and integrations as first-class identities from the moment they appear.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect.
A: Common signs include excessive permissions, stale or orphaned accounts, outdated policies, unaccounted access points, and weak logging coverage.
Practitioner guidance
- Map governance by actor type Separate human, non-human, and AI identity workflows so review cadence, approval logic, and revocation conditions match how each actor actually uses access.
- Shift review from snapshots to runtime Add continuous checks at issuance and use time so access decisions reflect current context instead of stale certification evidence.
- Target standing privilege first Identify the highest-risk entitlements that persist between reviews and remove or constrain them before expanding broader governance automation.
Bottom line: Identity governance breaks down when review cycles cannot keep pace with access that changes continuously across human, non-human, and AI identities.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Access certification is no longer the governing control it was built to be. Periodic access review was designed for stable entitlements that could be observed at rest and then certified on a schedule. That assumption fails when AI-driven identities and machine identities alter access continuously, because the state being reviewed may no longer exist by the time the review happens. The implication is that governance must be measured at the moment of use, not treated as a retrospective audit exercise.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: What should organisations do when continuous access control and manual recertification conflict?
A: Use manual recertification for oversight, but let continuous controls make the real-time decision on whether access should remain active. If the two disagree, the runtime control should win for high-risk access because it reflects the current state. Recertification should validate policy, not act as the only enforcement point.
👉 Read our full editorial: Identity governance moves toward AI-era continuous access control