They should measure how much material access is governed, not how many identities a platform stores. The better indicators are entitlement-level visibility, cross-entity policy coverage, time to onboard new systems and whether human and non-human identities are both inside the same review model.
Why This Matters for Security Teams
Identity scale is not a raw inventory problem. In complex enterprises, the real question is how much access is governed with consistent policy, review, and lifecycle control across humans, service accounts, APIs, and machine-to-machine flows. A platform can store millions of identities and still leave the most sensitive entitlements invisible. NIST Cybersecurity Framework 2.0 frames this as a governance and risk issue, not just a directory count problem.
The operating reality is that identity sprawl tends to hide in integrations, cloud workloads, developer tooling, and third-party connections. NHIMG research shows only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs, which means scale is often misread through incomplete telemetry. The metric that matters is whether security teams can see entitlement-level risk and enforce the same review model across identity types. In practice, many security teams discover the real size of the problem only after a sensitive system has already been overexposed, rather than through intentional measurement.
How It Works in Practice
Measuring identity scale well starts by counting governed access relationships, not just named accounts. Security teams should map the number of active entitlements, the number of systems under a common policy model, and the percentage of identities covered by automated review, rotation, and offboarding. That gives a truer picture of control coverage than a directory total ever will. The State of Non-Human Identity Security report highlights the visibility gap around third-party OAuth apps, which is a good example of where scale becomes operational risk rather than simple headcount.
A practical measurement model usually includes:
- Entitlement density per system, so teams can see where privilege accumulates fastest.
- Coverage of both human and non-human identities in the same governance workflow.
- Time to onboard a new platform into review, logging, and approval controls.
- Percentage of secrets, tokens, and service accounts under lifecycle automation.
- Policy consistency across cloud, SaaS, CI/CD, and application runtime identities.
NIST guidance on access governance supports this kind of control-based measurement, and the NIST Cybersecurity Framework 2.0 is useful for aligning identity metrics to outcomes such as access control, monitoring, and recovery. The key is to measure how much of the enterprise is actually reviewable and enforceable. These controls tend to break down when legacy systems, custom service accounts, and unmanaged third-party integrations sit outside the central identity workflow.
Common Variations and Edge Cases
Tighter identity measurement often increases program overhead, requiring organisations to balance visibility against integration effort and data quality. That tradeoff is especially sharp in enterprises with multiple clouds, acquired businesses, and application teams that issue their own service accounts. Best practice is evolving, but there is no universal standard for this yet: some teams emphasise entitlement coverage, while others track policy enforcement latency or the percentage of identities subject to the same review cadence.
Two common edge cases matter. First, a small number of identities can still represent very high risk if they hold broad admin rights or connect into sensitive pipelines. Second, large identity counts may be benign if most are ephemeral, scoped, and centrally governed. NHIMG guidance in the Top 10 NHI Issues and breach analysis such as the 52 NHI Breaches Analysis both point to the same operational lesson: scale without control is just exposure at volume. The better measure is whether identity governance keeps pace with change, not whether a database keeps growing.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity scale depends on who can access what, not just account counts. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Non-human identity sprawl is the core measurement problem in this question. |
| CSA MAESTRO | GOV-02 | Cross-entity governance is needed to measure human and machine identities together. |
| NIST AI RMF | Complex enterprises need risk-based measurement across changing identity contexts. | |
| NIST Zero Trust (SP 800-207) | 3.1 | Zero trust requires continuous evaluation of identity and entitlement scope. |
Define one governance model that covers humans, workloads, and agent identities.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org