TL;DR: Machine identities now outnumber human identities by roughly 82 to 1, and CyberArk reports that 42 percent of them hold privileged access while 61 percent of organisations lack workload identity controls. Aembit frames workload IAM as the discipline that replaces static credentials with runtime identity checks, policy evaluation, and ephemeral access for workloads, containers, pipelines, and AI agents.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Workload Identity and Access Management: The Definitive Guide”.
By the numbers:
- For every human identity your IAM program governs, there are roughly 82 machine identities operating outside it.
- 42 percent of machine identities carry privileged access, according to CyberArk research cited by Aembit.
- 61 percent of organizations lack identity security controls for cloud workloads, according to CyberArk research cited by Aembit.
Key questions
Q: What breaks when workloads still rely on static credentials for service-to-service access?
A: Static credentials break down when workloads are ephemeral, distributed across multiple environments, or expected to authenticate without preconfigured secrets.
Q: Why do workload identities create a different risk profile from human accounts?
A: Workload identities authenticate without human presence, often use long-lived credentials, and are frequently delegated across teams and pipelines.
Q: How do you know workload identity controls are actually working?
A: You should be able to show that access is issued without static secrets, that every workload has a clear owner, and that audit logs reconstruct identity, policy, and destination for each transaction.
Practitioner guidance
- Map every workload that still uses static credentials Inventory service accounts, API keys, OAuth tokens and certificates used by workloads, pipelines and integrations, then identify where access is still granted outside runtime policy.
- Replace reusable secrets with ephemeral access Use platform-managed identities, federation or brokered tokens so the workload receives short-lived credentials only when policy approves the request.
- Enforce context-aware workload policies Require identity plus environment, posture and resource sensitivity before access is issued, especially for cloud-to-cloud and SaaS-to-SaaS traffic.
Bottom line: Workload IAM addresses a governance gap that traditional human IAM does not cover well, because workloads authenticate and consume access at runtime rather than through human sessions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Workload identity management is now a distinct governance discipline, not a feature of secrets management. The article draws a clear line between storing credentials and governing access at runtime. That distinction matters because a vault can secure storage while still leaving provisioning, delivery and eligibility unresolved. Practitioners should treat workload IAM as the control plane for non-human access, not as an add-on to secrets tooling.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- 69% of organisations still authenticate machine identities with long-lived API keys, according to the 2026 State of AI Agent Identity Security Report.
A question worth separating out:
Q: What should security teams do when AI agents and workloads share the same environment?
A: Security teams should treat AI agents as part of the attack surface and apply the same visibility and containment discipline used for workloads and users. That means tracking their traffic, understanding what they can reach, and limiting access to only the connections they truly need. If agents are unmonitored, they can become silent paths for data exposure or lateral movement.
👉 Read our full editorial: Workload IAM closes the gap between human and machine identity