TL;DR: AAA still matters for enforcing authentication, authorization, and accounting, but StrongDM’s explanation shows it was built for user access patterns, not the scale and volatility of non-human identities, service accounts, tokens, and agentic workloads. That gap makes lifecycle control, rotation, and session oversight the decisive issues, not just centralized access policy.
Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “What is AAA Security? Authentication, Authorization, and Accounting”.
Key questions
Q: What breaks when AAA is used as the only control model for non-human identities?
A: AAA can verify access and log activity, but it does not guarantee that a service account, token, or certificate is still needed.
Q: Why do distributed identity sprawl and non-human identities increase access risk?
A: Distributed identity sprawl increases risk because ownership, entitlement, and approval data become fragmented across many apps and teams.
Q: What are the signs that AAA is not enough for NHI governance?
A: The clearest signs are stale service accounts, credentials with no expiry, reused tokens across multiple systems, and audit logs that show activity but not a clear owner.
Practitioner guidance
- Map AAA to NHI lifecycle controls Review where authentication, authorization, and accounting exist today, then identify where service accounts, API keys, and tokens bypass revocation and ownership checks.
- Inventory every non-human identity Create a current inventory of service accounts, secrets, certificates, and workload identities, including owner, purpose, scope, and expiry status.
- Enforce expiration and rotation for machine credentials Set explicit lifetime limits for tokens and certificates, and require rotation when the original business purpose or system ownership changes.
Bottom line: AAA remains relevant, but it does not fully govern non-human identities that can persist, spread, and be reused across systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AAA is necessary, but it is not an NHI governance model. AAA was designed to control access events, not to govern the full lifecycle of identities that never behave like human users. That matters because service accounts, tokens, and workloads can outlive the access decision that created them. The practitioner conclusion is simple: AAA is a control layer, not a complete governance model for NHIs.
A question worth separating out:
Q: Should organisations use Zero Trust instead of AAA for machine access?
A: No. Zero Trust and AAA solve different problems. AAA structures authentication, authorization, and accounting, while Zero Trust adds continuous verification and narrower trust boundaries. For NHIs, teams need both, plus lifecycle controls that ensure credentials do not outlive the workload they were issued for.
👉 Read our full editorial: AAA security is not enough for non-human identity governance