TL;DR: NHI security now depends on discovering machine identities, mapping effective permissions, and reducing standing privilege across service accounts, tokens, bots, and agentic AI, because traditional IAM and MFA were built around human access paths, according to Veza. The governance shift is from counting identities to proving who can do what right now, and what that access can reach.
NHIMG editorial — based on content published by Veza: NHI Security overview and operating model
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams govern service accounts at enterprise scale?
A: Security teams should govern service accounts through automated discovery, ownership mapping, scoped permissions, and retirement controls.
Q: Why do non-human identities create more risk than many human accounts?
A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review.
Q: What do teams get wrong about least privilege for NHIs?
A: They often apply least privilege at creation time and assume it stays valid.
Practitioner guidance
- Map effective permissions for every high-value NHI Resolve roles, groups, ACLs, and policies to actual actions on sensitive systems so you can see blast radius before an incident occurs.
- Assign one accountable owner per machine identity Do not let service accounts, tokens, or app registrations sit without an owner who can attest usage, approve change, and revoke access when the purpose ends.
- Inventory secret age and observed usage Track long-lived credentials, unused tokens, and duplicated secrets across code, CI/CD, SaaS, and vaults so stale access paths can be removed in sequence.
What's in the full article
Veza's full article covers the operational detail this post intentionally leaves for the source:
- Connector coverage across Entra ID, Okta, AWS, GCP, Kubernetes, source control, databases, and SaaS systems.
- Access Graph and Access Search workflows for resolving effective permissions to concrete actions and resources.
- Access Profiles and Access Reviews used to reduce NHI access without breaking production.
- Activity Monitoring and Access Intelligence examples for drift, escalation, and fleet-wide posture tracking.
👉 Read Veza's analysis of NHI discovery, effective permissions, and least privilege →
NHI security and authorization truth: what should teams change?
Explore further
Authorization truth is now the centre of NHI governance. Counting machine identities is useful, but it does not answer the operational question that matters: what can this identity actually do right now, and how far can that action travel? Veza’s framing reflects a broader industry shift from inventory to effective permissions, because the risk lives in inherited access, not just identity existence. Practitioners should treat permission resolution as the primary control surface.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: Who is accountable when a machine credential is abused?
A: Accountability should sit with the team that owns the workload, the identity lifecycle, and the connected business process, not with security alone. In regulated environments, that usually means engineering, platform, and IAM teams share responsibility for discovery, rotation, and offboarding while compliance verifies that the process is repeatable.
👉 Read our full editorial: NHI security shifts from inventory to authorization truth