Organisations should centralise identity governance so they can control who and what has access across cloud and multi-tenant environments. The goal is to keep access aligned to business need, reduce standing privilege, and maintain visibility as more suppliers, systems, and users enter the environment. Without that governance, operational speed increases while risk, sprawl, and audit complexity rise.
Why This Matters for Security Teams
Multi-tenant and cloud environments compress identity risk into a smaller blast radius problem: one over-broad account, one stale token, or one mis-scoped service principal can cross application, tenant, and workload boundaries faster than a traditional perimeter control can react. That is why governance has to focus on identity lifecycle, privilege scope, and continuous review, not just on onboarding and periodic recertification. NHI Management Group’s research on the 2024 Non-Human Identity Security Report shows how uneven NHI maturity still is across hybrid and multi-cloud estates.
Security teams often underestimate how quickly cloud sprawl turns into access sprawl. A single supplier integration, temporary migration account, or tenant-to-tenant service connection can leave standing privilege in places no one revisits until an audit or incident forces the issue. Current guidance from NIST Cybersecurity Framework 2.0 reinforces that identity governance must be treated as an ongoing risk function, not a one-time control setup. In practice, many security teams encounter multi-tenant access drift only after a privilege review, audit finding, or breach has already exposed the gap.
How It Works in Practice
Effective governance starts with a complete inventory of identities, not just users. That inventory needs to cover workforce accounts, partners, service accounts, application identities, cloud roles, API keys, and any NHI that can authenticate or act across tenants. From there, organisations should classify each identity by owner, purpose, business criticality, and tenancy scope so access can be tied to a real control objective rather than a generic role name.
The operational pattern is straightforward, but execution is usually fragmented:
- Centralise policy decisions so entitlement changes are reviewed against one governance model, even if enforcement happens in multiple clouds.
- Apply least privilege and remove standing access wherever possible, especially for admin roles and cross-tenant integrations.
- Use short-lived credentials and scoped tokens for workloads that do not need durable access.
- Require approvals and recertification for high-risk entitlements, but automate low-risk renewals where evidence is strong.
- Log identity events in a way that links the principal, tenant, workload, and transaction context for audit and forensics.
That approach aligns with the lifecycle and audit guidance in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs and Ultimate Guide to NHIs — Regulatory and Audit Perspectives. It also matches the direction of current standards work in NIST Cybersecurity Framework 2.0, which emphasises continuous risk management across identity and access. These controls tend to break down when each cloud team runs its own exceptions process, because access decisions become inconsistent across tenants and cannot be reconciled cleanly during incident response.
Common Variations and Edge Cases
Tighter identity governance often increases operational overhead, requiring organisations to balance control quality against deployment speed, especially during migrations and partner onboarding. That tradeoff is real in multi-tenant environments where business teams want rapid access and platform teams need defensible guardrails. Best practice is evolving, but there is no universal standard for how much centralisation is enough; the right model depends on regulatory exposure, tenant separation requirements, and how much automation the organisation can support.
Edge cases usually appear where trust boundaries are unclear. Shared service accounts, cross-account cloud roles, delegated admin privileges, and third-party automation can all look legitimate in design reviews while still creating hidden persistence paths. The same is true for secrets that are stored centrally but distributed widely. NHI Management Group has highlighted how quickly these patterns can lead to escalation in examples such as the Azure Key Vault privilege escalation exposure and the JetBrains GitHub plugin token exposure.
Where organisations are still early in maturity, a pragmatic model is to standardise identity ownership, enforce scoped access, and raise approval thresholds only for cross-tenant or high-impact roles. That keeps governance workable without pretending every cloud environment can be managed identically. The hardest problems usually surface when teams inherit legacy exceptions, because the access model was never designed for today’s multi-tenant operating reality.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity inventory and ownership are core to non-human identity governance. |
| CSA MAESTRO | Covers governance patterns for autonomous and cloud-native identities. | |
| NIST CSF 2.0 | PR.AA-01 | Supports identity proofing, access governance, and continuous review. |
| NIST SP 800-63 | 5.1.2 | Identity lifecycle and assurance concepts inform stronger access governance. |
| NIST AI RMF | GOVERN | AI governance principles apply when cloud automation uses autonomous identities. |
Maintain a complete inventory of NHIs and assign clear owners before granting or reviewing access.
Related resources from NHI Mgmt Group
- How should security teams govern non-human identities in cloud environments?
- Why does cloud authentication become harder to govern as organisations move more workloads into hybrid and multi-cloud environments?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams govern non-human identities at scale?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org