Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Certificate lifetimes and AI agents: what IAM teams need to change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 6131
Topic starter  

TL;DR: Shorter certificate lifetimes, rising automation demands, and the spread of agentic AI are pushing machine identity governance beyond manual renewal models, according to SPHERE Technology Solutions' podcast highlights. The real issue is that identity programmes built on human-paced review cycles cannot reliably manage fast-changing certificate and key lifecycles.

NHIMG editorial — based on content published by SPHERE Technology Solutions: podcast highlights from Smells Like Identity Hygiene on certificates, automation, and agentic AI

By the numbers:

Questions worth separating out

Q: How should security teams handle certificate renewals as lifetimes get shorter?

A: Security teams should treat certificate renewal as a lifecycle control, not a ticketing exercise.

Q: Why do short-lived certificates increase governance risk?

A: Short-lived certificates increase governance risk because they compress the time available for manual review, approval, and replacement.

Q: What do security teams get wrong about machine identity management?

A: Security teams often treat certificates, keys, and tokens as infrastructure details instead of governed identities.

Practitioner guidance

  • Inventory every certificate and key Create a complete register that ties each certificate to an owner, renewal method, expiry date, and dependent application.
  • Automate renewals for high-volume infrastructure Start with load balancers, API gateways, and cloud key stores where one workflow can cover many certificates.
  • Extend NHI governance to AI credentials Add agentic AI systems to the same lifecycle process used for service accounts and tokens.

What's in the full article

SPHERE Technology Solutions' full podcast recap covers the operational detail this post intentionally leaves for the source:

  • The episode discussion of CA/B Forum timing and what 47-day certificate lifetimes mean for renewal operations.
  • Practical commentary on where automation should start in infrastructure estates such as gateways and key stores.
  • The conversation about agentic AI as a new class of machine identity and why shadow AI complicates ownership.
  • The full exchange on why human approval gates can become the bottleneck in certificate security.

👉 Read SPHERE Technology Solutions' podcast highlights on certificates, automation, and agentic AI identity →

Certificate lifetimes and AI agents: what IAM teams need to change?

Explore further

View Full Forum →  |  NHI Foundation Course →


This topic was modified 4 hours ago by Mr NHI

   
Quote
(@mr-nhi)
Member Moderator
Joined: 1 month ago
Posts: 5624
 

Certificate security is now a non-human identity governance problem. The article shows that certificate expiry, renewal, and ownership cannot be treated as isolated infrastructure tasks once lifetimes compress and renewal frequency rises. Machine identities behave like NHIs because they are credentials with lifecycle obligations, not just technical artifacts. Practitioners should treat certificate governance as part of the same control plane used for service accounts, keys, and tokens.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • Only 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: How should organisations govern AI systems that need credentials?

A: Organisations should place AI systems inside the non-human identity inventory and assign each one a clear owner, scope, and offboarding path. If an AI feature can authenticate, call tools, or hold tokens, it needs lifecycle governance. Without that, hidden access paths can outlive visibility and accountability.

👉 Read our full editorial: Certificate security and agentic AI expose the limits of identity hygiene



   
ReplyQuote
Share: