TL;DR: Gartner’s 2025 PAM Magic Quadrant now treats machine scenarios, workload identity, and secrets management as expected capabilities, reflecting a market shift that still leaves human-built PAM controls misaligned with workload access patterns, according to Aembit. The governance gap remains structural: access review, session recording, and vault checkout were designed for people, not ephemeral machine identities.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Key Takeaways on Non-Human Identity Security from Gartner’s PAM Report”.
By the numbers:
- Machine identities outnumber human identities by 82 to 1 in enterprises, according to CyberArk’s 2025 Identity Security Landscape.
- The 2025 Gartner PAM Magic Quadrant treats PAM for machines scenarios, workload identity and secrets management as expected capabilities.
- The 2024 Gartner report described PAM vendors as beginning to address nonhuman identities.
Key questions
Q: What breaks when PAM is used as the primary control for workload access?
A: PAM breaks down when it assumes a human operator, because workloads do not wait for approvals, do not need interactive sessions and often live only for seconds.
Q: When should organisations prioritise workload IAM over extending PAM?
A: Organisations should prioritise workload IAM when privileged access is driven by CI/CD, cloud workloads or AI agents that need fast, repeatable access without human interaction.
Q: What are the signs that secrets-based workload access is no longer working?
A: Warning signs include credentials embedded in code or pipelines, broad vault checkout patterns, frequent environment-specific exceptions and access decisions that are still tied to people rather than workloads.
Practitioner guidance
- Define machine privilege separately from human privilege Update your privileged identity model so service accounts, pipelines, workloads and AI agents are governed as non-human identities rather than hidden under a human-only privileged user definition.
- Prioritise attested identity for sensitive workloads Start with production databases, identity providers, payment systems and cloud control planes, then replace secret checkout with attestation-based access where the exposure risk is highest.
- Limit access to short-lived, task-scoped credentials Issue credentials at request time with a narrow scope and rapid expiry so a stolen machine credential has little reuse value across services or environments.
Bottom line: PAM still governs human privilege well, but workloads and AI agents expose a structural mismatch between interactive controls and machine-speed access.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Human PAM controls were built for accountable operators, not autonomous workloads. Vault checkout, session recording and approval routing assume a named person who can tolerate delay and be reviewed after the fact. That assumption collapses when the identity is a pipeline job, container or AI agent acting at machine speed. The implication is that access governance for non-human actors must be judged by issuance-time control fit, not by how well it imitates human administration.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should teams govern AI agents that act inside customer accounts?
A: Treat them as delegated non-human identities, not as ordinary customer sessions. Governance should require explicit consent, narrow authorization scope, token binding, and a complete audit record tying each action back to the human principal that approved it.
👉 Read our full editorial: Workload IAM is closing PAM's machine access gap