TL;DR: Identity security is no longer just about giving the right access at the right time, according to Saviynt's perspective, because attackers now exploit identity across humans, machines, and agentic AI while enterprises still organise controls around productivity-first IAM models. The governance gap is widening as machine identity, zero trust, and threat-aware decisioning become inseparable.
NHIMG editorial — based on content published by Saviynt: an analysis of identity security, machine identity, and agentic AI
By the numbers:
- NHIs now outnumber human identities by 144:1 in enterprise environments, a 44% increase year-over-year driven by AI agents, CI/CD automation, and third-party integrations.
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: What breaks when organisations manage machine identities like user accounts?
A: The programme loses visibility, ownership, and lifecycle control.
Q: Why do excessive NHI privileges increase breach impact?
A: Because attackers rarely need root access if an NHI already has more permission than its workload requires.
Q: How do teams know whether identity detection is actually reducing risk?
A: Look for fewer unresolved high-risk sessions, faster containment of suspicious privilege use, and better analyst prioritisation.
Practitioner guidance
- Define identity ownership across all machine accounts Assign explicit business and technical owners to service accounts, API keys, certificates, and integration tokens so revocation and review decisions do not fall into administrative gaps.
- Separate automation from autonomous runtime behaviour Classify workflows that follow fixed rules differently from AI agents or other runtime decision-makers, then apply governance based on whether the actor can choose actions and timing independently.
- Rebuild access reviews around identity blast radius Prioritise recertification and monitoring for identities that can reach sensitive systems, move laterally, or persist across multiple delivery pipelines and third-party integrations.
What's in the full article
Saviynt's full article covers the strategic context this post intentionally leaves at a higher level:
- The author's firsthand account of how identity, PKI, and machine identity markets evolved over time.
- The rationale behind the shift from productivity-first IAM to adversary-aware identity security.
- The specific market and organisational signals the author uses to argue that agentic AI is accelerating change.
- The leadership and market-convergence context behind Saviynt's broader identity strategy.
👉 Read Saviynt's analysis of identity security, machine identity, and agentic AI →
Identity security and agentic AI: what changes for practitioners now?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity security is becoming a threat detection problem, not just an access administration problem. The article's core argument is that modern identity programmes must answer whether an identity is trusted and whether it is behaving like an adversary. That moves identity governance closer to runtime control, where PAM, ITDR, and NHI management have to be treated as connected disciplines. Practitioners should stop treating identity as a back-office provisioning function and start treating it as a live security control plane.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should security teams choose between Zero Trust and Defense in Depth for identity governance?
A: Use Zero Trust when the main risk is stale trust, lateral movement, or identity-driven access across cloud and SaaS systems. Defense in Depth still helps with containment, but it should not be the primary governance model if identities change frequently. The deciding factor is whether your controls continuously verify identity state or only stack barriers around it.
👉 Read our full editorial: Identity security is shifting from productivity to threat-aware governance