TL;DR: Non-human identities now outnumber human identities by 10 to 50 times, and the article argues that traditional IAM, PAM, and secret management tools were built for human-centric identity models that cannot keep up, according to Oasis Security. The real issue is not just scale but a governance model that cannot see ownership, usage, permissions, and lifecycle together.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “What's Broken with Identity Management?”.
Key questions
A: The control model breaks at ownership, review, and offboarding.
Q: Why do highly privileged NHIs create more risk than simple account counts suggest?
A: Because privilege density determines blast radius.
Q: How can organisations tell whether their NHI controls are actually working?
A: Look for reduced secret sprawl, fewer long-lived credentials, clear ownership records, and rapid offboarding when workloads are retired.
Practitioner guidance
- Map the full NHI estate Inventory service accounts, roles, tokens, keys, and other non-human identities across cloud and enterprise systems, then classify them by ownership, privilege, and business function.
- Link every NHI to an owner and purpose Require each machine identity to have a named owner, an explicit workload or application purpose, and a recorded dependency path so it can be reviewed or retired without guesswork.
- Reduce overprivileged machine access Review highly privileged NHIs first, focusing on accounts that can reach sensitive systems or combine permissions into toxic combinations that widen blast radius.
Bottom line: NHI sprawl exposes a governance gap because human-centric IAM models do not fully describe machine identities, their ownership, or their lifecycle.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Human-centric identity management no longer matches the identity estate. The dominant failure is architectural: IAM programmes still organise control around people, while modern infrastructure is increasingly driven by machine identities. That mismatch means the programme can be operationally busy and still blind to the majority of access-bearing entities. The implication is that identity governance must be reset around the actual actor mix, not the historical default of human users.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations rely on secret managers alone to govern NHIs?
A: No. Secret managers are useful for vaulting and rotation, but they do not provide identity context, lifecycle status, or dependency mapping. Without those elements, organisations can protect a credential while still leaving the underlying machine identity overprivileged, unowned, or impossible to retire safely.
👉 Read our full editorial: What's broken with identity management for NHI sprawl