Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Should organisations focus more on user intent or…
Governance, Ownership & Risk

Should organisations focus more on user intent or on activity detection?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 6, 2026 Domain: Governance, Ownership & Risk

They need both, but activity detection should come first because it creates the evidence trail. Intent is inferred from patterns, not read directly from logs, so organisations should build telemetry, correlation, and case review around real behaviour. Without that evidence base, intent-based decisions become guesswork and can undermine trust in the programme.

Why This Matters for Security Teams

Security teams cannot rely on declared purpose alone, because intent is not directly observable in logs. Activity detection creates the factual basis for decisions by showing what actually happened, while intent analysis comes later as a judgment about patterns, context, and deviation from expected behaviour. That distinction matters most where access can be reused, scripted, or chained across systems, because apparently benign actions can still create material exposure.

For organisations governing non-human identities and automated access, the issue is especially acute: a token, service account, or agent may perform actions that look routine until telemetry shows scale, timing, or destination anomalies. NHI Management Group’s research notes that only 5.7% of organisations have full visibility into their service accounts, which helps explain why many programmes struggle to separate normal operation from abuse. In practice, teams often discover intent questions only after weak telemetry has already made the evidence ambiguous.

For a deeper view of how visibility, lifecycle, and control gaps compound around machine access, see Ultimate Guide to NHIs — Key Challenges and Risks.

How It Works in Practice

The practical sequence is to instrument activity first, then infer intent from the resulting evidence. That means collecting authenticated identity, source, destination, command, API, and timing data, and then correlating those events against baselines, approvals, and peer behaviour. Intent becomes useful when it explains a pattern such as unusual tool use, atypical data access, or unexpected cross-environment movement. Without that sequence, intent-based review often becomes a subjective debate rather than an investigatory process.

In mature environments, this usually means security operations, IAM, and platform teams share the same evidence chain. Activity detection should answer questions such as: what was accessed, from where, under what privilege, and in what sequence? Intent review then asks whether those actions match the stated purpose of the workload or user, and whether the behaviour is consistent with the role, policy, and recent history. That is why telemetry quality matters more than label quality. If the event trail is incomplete, intent analysis can overfit to assumptions or miss low-and-slow misuse.

A practical control set usually includes:

  • high-fidelity logging for authentication, authorisation, and sensitive actions
  • correlation rules that join identity, session, and workload events
  • case review thresholds for anomaly clusters rather than single events
  • clear ownership for deciding when behaviour is suspicious versus authorised

Current guidance suggests that intent should be treated as an interpretation layer over observable behaviour, not as a replacement for monitoring. The NIST Cybersecurity Framework 2.0 aligns with this order by emphasising governance, detection, and response around measurable risk signals. These controls tend to break down when identity data is fragmented across SaaS, cloud, and automation platforms because the same action then appears unrelated in each log source.

Common Variations and Edge Cases

Tighter intent review often increases operational overhead, so organisations have to balance investigative depth against speed and analyst capacity. In low-risk workflows, simple detection of policy violations may be enough; in high-impact workflows, especially privileged automation, intent review becomes more important but still depends on trustworthy telemetry.

One common edge case is legitimate automation that looks suspicious because it acts faster, at larger scale, or from more consistent infrastructure than a human operator. Another is delegated access, where the user looks approved but the real risk lies in what the session can trigger downstream. In both cases, the question is not whether behaviour is “good” or “bad” in the abstract, but whether the observed pattern fits the expected operating model.

There is no universal standard for this yet, but current practice is moving toward behaviour-first detection with context-aware interpretation layered on top. For teams managing machine access, that often means combining activity review with lifecycle controls, because stale credentials, excessive privilege, and weak offboarding all distort the intent picture. NHIMG research shows that 91.6% of secrets remain valid five days after notification, which is a reminder that delayed remediation can keep suspicious access paths alive long after a policy decision has been made.

Risk and Threat Considerations

The material risk is overtrusting inferred intent when the evidence trail is incomplete. That creates both governance risk and threat exposure: insiders, compromised accounts, and automated agents can all perform actions that appear defensible unless behaviour is measured against strong telemetry and baselines.

Failure mechanism: intent is often inferred from partial context, but attackers and abusive insiders exploit that ambiguity by using normal identities, approved tools, and low-and-slow behaviour. Where logging is sparse, correlation weak, or ownership unclear, malicious activity can blend into routine operations and avoid escalation until after data access, privilege misuse, or persistence is established.

Impact: organisations may miss compromise, misclassify legitimate abuse, or block valid activity without evidence. The result is weaker detection, poor trust in alerts, and decision-making that depends on assumptions instead of verifiable behaviour.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and MITRE-ATTACK set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Intent decisions depend on visible machine and service activity, not assumed purpose.
Recommendation: Maintain actionable visibility into NHI activity so behaviour can be assessed from evidence.
NIST CSF 2.0DE.CMThe question is about detecting real activity before inferring intent.
Recommendation: Continuously monitor and correlate events to support trustworthy behavioural assessment.
CIS Controls v88Activity detection relies on complete logs and usable event trails.
Recommendation: Collect and retain logs that make suspicious behaviour reconstructable and reviewable.
OWASP Agentic AI Top 10A4For autonomous workloads, behaviour evidence is needed before judging intent.
Recommendation: Instrument agent actions so decisions are based on observed behaviour, not inference alone.
MITRE-ATTACKTA0009The concern is identifying observed activity patterns that indicate misuse or compromise.
Recommendation: Map collected activity to adversary behaviour to distinguish routine from malicious patterns.

Practitioner Guidance

What to prioritise: establish activity telemetry and correlation before trying to formalise intent-based decisions. If the evidence trail is weak, intent reviews will be inconsistent and difficult to defend.

Decision rule: if you cannot reconstruct who acted, what was touched, and how privilege was used, treat the case as a telemetry gap first and an intent question second. That ordering prevents analysts from rationalising missing evidence as benign behaviour.

What to verify: confirm that logs cover authentication, authorisation, session context, and sensitive actions across all major execution surfaces, including automation and service accounts. The control is only as strong as the least visible path.

Practitioner takeaway: the safest operating model is not “detect intent better,” but “detect behaviour well enough that intent can be argued from evidence rather than assumed from appearance.”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org