TL;DR: Modern identity risk now spans privileged users, non-human identities, data systems, and AI agents across SaaS, cloud, and on-prem, with effective permissions only becoming governable when teams can see blast radius and inherited access, according to Veza. The real shift is away from fragmented controls toward continuous entitlement truth, because least privilege fails when access is distributed faster than reviews can follow.
Editorial analysis by NHI Mgmt Group, based on content published by Veza: “White Paper”.
Key questions
Q: How should security teams govern privileged access across cloud and legacy systems?
A: Teams should govern privileged access by resource class, not with one uniform assumption set.
Q: Why do non-human identities create a larger governance problem than human accounts?
A: Non-human identities scale faster, are used by systems rather than people, and often carry broad or persistent access.
Q: What are the signs that legacy access controls are failing in a hybrid IT environment?
A: Common warning signs include users juggling separate passwords and MFA factors, security policies that differ by application, slow onboarding and offboarding, and reliance on VPNs for routine app access.
Practitioner guidance
- Map effective permissions across the estate Build a single view of who can do what across SaaS, cloud, data and on-prem, including inherited access and cross-account role assumption.
- Assign owners to every non-human identity Require a named owner, business purpose and lifecycle state for each service account, token, pipeline and workload identity.
- Time-box delegated and impersonated access Set expiry conditions for federated roles, workload assumptions and agent permissions so access cannot persist beyond the task or business use case that justified it.
Bottom line: Modern identity programmes fail when they track accounts without tracking effective permissions across systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity graphs are becoming the control plane for effective permissions. The old access model assumed you could govern identities by system or by role, but modern environments distribute authority across SaaS, cloud, data and on-prem services. That makes inherited access the real security problem, not the visible account alone. Practitioners should treat blast radius mapping as a governance primitive, not a reporting feature.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Why do agentic AI systems need NHI-style access controls?
A: Agentic AI systems can call tools, reach data, and act repeatedly, which makes them behave like non-human actors with permissions that need scoping and revocation. If those permissions are broad or untracked, the model can cross into data exposure or workflow abuse. NHI-style controls help limit what the system can access and for how long.
👉 Read our full editorial: Veza's identity graph reframes privilege, NHI, and agentic AI