A zombie agent is one that still runs after the work that justified it has ended. Common signs are unchanged access after a project closes, missing ownership when staff move roles or leave, and credentials that remain valid long after the task is complete. These agents often surface during audits or incidents because nobody has been actively watching them.
How to spot a zombie identity before it becomes an incident
The clearest warning sign is not activity, but persistence without purpose. When an agent keeps valid access after the workflow ends, keeps authenticating without a current owner, or continues to hold secrets that should have been rotated, you are seeing an identity that has outlived its business need. That is a lifecycle failure, and it often hides in systems that still “work.”
What matters most is whether the access path still has an accountable business sponsor. If the agent is still present in inventories, logs, or permission stores but nobody can explain why it remains active, the identity is drifting toward zombie status. That is especially true when the agent can still reach production, automation, or sensitive data long after the original task closed. NHIMG’s Ultimate Guide to NHIs is a useful reference for the lifecycle, rotation, and offboarding patterns that expose this drift.
A second sign is stale credential behaviour. A zombie identity often has secrets, tokens, certificates, or API keys that remain valid after the work is done, sometimes because rotation never happened and sometimes because revocation was never tied to offboarding. When those materials outlive the task, the identity remains technically usable even when it is operationally obsolete.
What usually causes the drift
Zombie identities are rarely created by one bad decision. They usually emerge from weak ownership, poor offboarding discipline, and automation that was built to start easily but not to stop safely. If the person or team responsible for an agent changes roles, leaves the organisation, or forgets the asset altogether, the identity can persist with no one actively reviewing its permissions or expiry conditions.
Another common cause is incomplete lifecycle coupling. The agent is provisioned for a project, integration, or experiment, but deprovisioning is never linked to project closure, role change, or sunset events. Over time, this creates a shadow population of still-authorised agents that no longer map cleanly to current work. In practice, that means access review alone is not enough if nobody can confirm the business reason the agent exists.
- Look for agents with no named owner or no current approver.
- Flag access that survives project closure, vendor change, or staff movement.
- Review whether the agent still needs the same data, tools, or environments it was first granted.
The broader problem is visibility. NHIMG’s Top 10 NHI Issues highlights that ownership gaps, rotation failures, and weak discovery are recurring drivers of identity sprawl, which is exactly the environment where zombie identities are most likely to survive.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Discovery and Inventory | Zombie identities persist when agents are not fully discovered or tracked. |
| NHI-03 — Secrets and Credential Management | Expired purpose often leaves valid secrets and tokens behind. | |
| NHI-05 — Ownership and Lifecycle Governance | Missing ownership is a core sign that an agent has become zombie-like. | |
| Recommendation — Maintain an authoritative inventory of non-human identities and remove orphaned entries promptly. Rotate and revoke agent secrets on a defined schedule and at offboarding. Assign explicit ownership and decommission criteria for every non-human identity. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Zombie identities are a lifecycle and governance risk that needs ownership. |
| PR.AA-01 — Identity Management, Authentication and Access Control | Persisting access after purpose ends is an access-control failure. | |
| Recommendation — Set governance rules that require lifecycle review and decommissioning of stale identities. Enforce timely removal of access when an identity no longer has a valid purpose. | ||
| CIS Controls v8 | 5 — Account Management | Zombie identities are exposed through unmanaged, stale, or orphaned accounts. |
| 6 — Access Control Management | Residual permissions and long-lived access are central to zombie identity risk. | |
| Recommendation — Inventory, disable, and remove accounts that no longer have a business owner. Review and revoke unnecessary access paths when work ends or ownership changes. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | A zombie identity remains attractive because valid credentials still work. |
| Recommendation — Hunt for valid-account abuse when credentials survive beyond the intended lifecycle. | ||
Practitioner Guidance
What to verify: Confirm that every live agent has a current owner, a defined business purpose, and an expiry or review condition that matches the work it performs. If you cannot trace those three things quickly, treat the identity as suspect even if no abuse is visible.
What to prioritise: Focus first on agents with production reach, broad permissions, or long-lived credentials. Those are the identities most likely to create hidden exposure because they can keep operating after the original workflow has disappeared.
Common mistake: Teams often assume that “still functioning” means “still needed.” In reality, a healthy-looking agent can be a liability if nobody can justify its continued existence or show that its secrets and permissions are still bounded to current work.
Practitioner takeaway: A zombie identity is best detected as a governance gap, not a technical failure, so the decisive question is whether access, ownership, and lifecycle controls still agree with the business reality.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org