Join our Newsletter — 33% off our NHI Course

Vaults vs workload IAM: what IAM teams need to change now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Secrets managers store and rotate credentials, but they do not decide whether a workload should have access, under what conditions, or for how long; Aembit’s analysis argues that workload IAM fills that governance gap by verifying nonhuman identity and issuing short-lived, scoped credentials. The broken assumption is that credential storage can substitute for runtime access control.

Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Secrets Management vs. Access Management: What You Need to Know”.

Key questions

Q: What breaks when secrets are used as the default for workload access?

A: Static secrets become the easiest compromise path because they can leak into code, config files, build systems, and deployment logs.

Q: Why do workload identities create new risk when used across clouds and APIs?

A: Because workload identities are transferable, their trust value can outlive the runtime conditions that made them safe.

Q: What are the signs that vault-centric NHI governance is failing?

A: Common signals include long rotation intervals, shared secrets between services, CI/CD tokens appearing in logs, and a growing number of bootstrap credentials outside the vault.

Practitioner guidance

  • Separate secret storage from access decisions Document where your current vault ends and where runtime authorisation begins, then remove any assumption that rotation alone enforces least privilege.
  • Inventory bootstrap and secret zero dependencies Find every workload that still needs a stored bootstrap credential to reach a vault, then replace the dependency with platform identity where possible.
  • Map cross-cloud access bridges Identify every AWS-to-Azure, cloud-to-SaaS, and on-premises access path that relies on shared secrets or manual federation and treat it as a governance gap.

Bottom line: Vaults manage secret custody, but they do not make the access decision that workloads now need at runtime.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Credential storage is not access governance: The industry still over-credits vaults for a problem they do not own. A secrets manager can protect a credential at rest, but it cannot decide whether a workload should be allowed to use that credential in the moment. Practitioners should stop treating secret storage as the centre of the access model and start treating it as one input into it.

A few things that frame the scale:

  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: When should teams move from secrets management to platform-native workload IAM?

A: Move when the organisation can already issue and audit access centrally, and when the main remaining problem is not storage but credential proliferation. At that point, continuing to expand secrets handling adds complexity without materially improving governance or reducing exposure.

👉 Read our full editorial: Workload IAM is replacing vault-centric access control for NHIs


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.