TL;DR: Machine identities now outnumber human users in most enterprises, yet 72% of companies say managing them is harder because internal processes and tools are not keeping up, according to Apono. The governance gap is no longer about visibility alone, but about lifecycle, privilege, and rotation controls that conventional IAM still treats as secondary.
Editorial analysis by NHI Mgmt Group, based on content published by Apono: “Machine Identity Management: How to Discover, Manage, and Secure”.
By the numbers:
- 69% of companies now manage more machine identities than human ones.
- 72% admit that managing them is more difficult due to poor internal processes and inadequate tools.
Key questions
Q: What breaks when machine identities have no clear owner?
A: When machine identities have no clear owner, offboarding, remediation, and accountability all fail together.
Q: What problem does ownership attribution solve for service accounts and API keys?
A: It closes the gap between exposure detection and accountable remediation.
Q: How do teams know if machine identity governance is actually working?
A: Look for evidence that each service account has a current owner, a narrow purpose, a short credential lifetime, and a clear retirement path.
Practitioner guidance
- Define machine identity ownership Map every service account, API key, token, certificate, and bot to a named business or technical owner so accountability survives team and deployment changes.
- Automate lifecycle controls Enforce issuance, rotation, expiry, and revocation as one workflow so credentials do not outlive the workload or application that created them.
- Reduce standing privilege Review machine identity entitlements for broad roles, then replace persistent access with just-in-time, task-scoped permissions wherever the workload can tolerate it.
Bottom line: Machine identity risk is driven less by existence than by unmanaged lifecycle, broad permissions, and weak ownership.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Machine identity governance has moved from inventory management to access governance. Discovery matters, but the article shows that discovery alone does not reduce risk when service accounts, API keys, and tokens still carry standing privilege. The discipline now has to connect attribution, ownership, authorisation, and revocation into one operating model. That is the point at which machine identity management becomes a real control function rather than a spreadsheet exercise.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What is the difference between JIT access and static machine permissions?
A: JIT access exists only for a defined task window and then disappears, while static permissions persist until someone manually changes them. For machine identities, that difference matters because persistent access turns forgotten credentials into standing attack paths, while JIT reduces the duration of exposure.
👉 Read our full editorial: Machine identity management gaps are widening across enterprise stacks