TL;DR: 69% of companies now manage more machine identities than human ones, 72% say machine identities are harder to manage, and only 38% have a real-time list of active machine identities, according to a SailPoint-sponsored Dimensional Research survey. The gap is no longer visibility alone; it is lifecycle control, auditability, and accountability.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “The silent security threat: Why machine identities are your biggest blind spot”.
By the numbers:
- 69% of companies surveyed now manage more machine identities than human ones.
- 72% of identity professionals surveyed find machine identities more difficult to manage than human identities.
- Only 38% of companies surveyed reported having a real-time list of their active machine identities.
Key questions
Q: What breaks when machine identities are tracked manually?
A: Manual tracking breaks when credential volume outpaces human oversight.
A: Machine identities create risk because they often scale faster than human oversight, while certificate lifecycles, privileges, and ownership can drift over time.
Q: How do security teams know whether machine identity governance is working?
A: They know it is working when every non-human credential has a named owner, a visible system scope, and a documented retirement path.
Practitioner guidance
- Establish machine identity ownership Assign a named owner, business purpose, and revocation authority to every service account, bot, and RPA before it is allowed to persist in production.
- Build a real-time identity inventory Maintain a continuously updated list of active and inactive machine identities so certification and incident response start from current data rather than stale records.
- Reconcile stale identities against dependencies Review machine identities that have not been used recently, verify the systems that still depend on them, and retire the ones with no current business need.
Bottom line: Machine identity governance fails most often because ownership and lifecycle state drift away from the systems that depend on the account.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Machine identity blind spots are a lifecycle problem before they are a visibility problem: Organisations do not mainly fail because they cannot count machine identities. They fail because ownership, intended purpose, and revocation state drift apart over time. That creates a governance gap where identities outlive the process that justified them, and the practical conclusion is that lifecycle controls have to precede reporting.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations prioritise machine identities before human access reviews?
A: They should prioritise both, but machine identities often deserve immediate attention because they are numerous, long-lived, and under-reviewed. If service accounts and keys are unmanaged, human access reviews alone will not close the largest exposure paths.
👉 Read our full editorial: Machine identity blind spots are widening faster than governance