TL;DR: As infrastructure becomes more automated and distributed, certificates now sit at the centre of machine identity trust, but most organisations still manage them as static plumbing, leaving hidden access paths and outage risk, according to Hush Security. Runtime visibility is the difference between certificate inventory and certificate governance: without it, trust can persist long after the workload, service, or control plane should have changed.
Editorial analysis by NHI Mgmt Group, based on content published by Hush Security: “Why Runtime Insight Is the Missing Piece in Certificate Management”.
Key questions
Q: What fails when teams manage certificates only as inventory and expiry dates?
A: They lose sight of whether a certificate still binds a live workload to a valid trust relationship.
Q: Why do certificate migrations create governance risk for machine identities?
A: Because certificates are operational credentials, and migrations often create overlapping trust states where old and new certificates coexist.
Q: How do security teams know whether certificate-based access is actually working?
A: They test the failure path, not just the happy path.
Practitioner guidance
- Implement runtime certificate discovery Map certificates to the workloads, services, and pipelines that actively use them so inventory includes live trust relationships, not just issued objects.
- Flag orphaned and duplicated certificates Look for certificates still being provisioned after resource deletion, reused across unexpected hosts, or copied outside their intended service boundary.
- Tie certificate review to workload state Reconcile certificates against current application, container, and API client status so trust is revoked when the underlying identity changes.
Bottom line: Certificates become a governance problem when teams cannot see how they are used at runtime.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Certificate runtime visibility is now a machine identity control, not a monitoring nicety. Traditional certificate management assumes issuance, expiry, and key length are enough to establish trust. That assumption fails when certificates are copied, reused, or left behind after workloads change, because the binding between identity and trust can no longer be inferred from static metadata alone. The implication is that machine identity governance has to prove live usage, not just catalogue assets.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should organisations respond when a certificate is still trusted after the workload changes?
A: They should treat that as a governance failure, not just a cleanup task. The right response is to revoke or replace the certificate, reconcile dependent services, and update lifecycle controls so trust cannot remain attached to deleted or repurposed workloads.
👉 Read our full editorial: Runtime certificate visibility is now core to machine identity governance