Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What are the signs that an organisation does…
NHI Lifecycle Management

What are the signs that an organisation does not have control over its machine identity inventory?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: NHI Lifecycle Management

A clear sign is that teams cannot say how many keys and certificates exist, or where they are deployed. The article also points to fragmented tooling, ad hoc team ownership, and certificate-related outages that disrupt customers or internal users. When inventory is unclear, visibility is incomplete, and renewal, rotation, and recovery processes usually suffer.

How to Recognise Loss of Machine Identity Inventory Control

The strongest signal is not just that some identities are missing, but that no one can reliably answer basic questions about them. When inventory control is weak, teams cannot consistently state how many machine identities exist, who owns them, where they are deployed, or which systems depend on them. That uncertainty usually shows up as fragmented tracking, duplicated records, and inconsistent handoffs between teams.

Another sign is that inventory data does not translate into operational control. Teams may know a certificate exists, but still fail to connect it to a deployment, a renewal date, or a business service. In practice, that gap means visibility is only partial, and the organisation is managing artifacts in isolation rather than managing the identity population as a whole.

A mature inventory is not a spreadsheet count, it is a living map of identities, ownership, location, lifecycle state, and dependency. When that map is missing, the organisation cannot reliably answer whether an identity is active, stale, orphaned, duplicated, or exempt from policy. The result is not just poor recordkeeping, but weak decision-making around renewal, rotation, offboarding, and exception handling.

Operational Symptoms That Usually Appear Next

Once inventory control is lost, the operational symptoms become visible in surrounding work. Teams compensate with ad hoc ownership, manual lookups, and ticket-by-ticket exceptions. Different groups may manage the same certificates or keys differently, which creates inconsistent renewal practices and makes it harder to prove whether controls are actually working.

Fragmented tooling is another common indicator. If discovery happens in one tool, ownership in another, and renewal in a third, the organisation often lacks a single authoritative source of truth. That fragmentation increases the chance that some machine identities are never reviewed, some are reviewed twice, and some are simply missed until they fail.

Outages tied to certificates, keys, or renewal timing are especially telling because they expose the weakness in a way business users can feel. When renewals are missed, the issue is no longer theoretical: internal users lose access, customer-facing services break, and recovery work starts after the failure rather than before it.

What the Organisation Is Actually Failing to Control

The real problem is usually not the existence of machine identities, but the lack of governance over their lifecycle. A controlled inventory should support discovery, ownership, classification, renewal, rotation, and retirement. If any of those steps are missing, the organisation may still have tools, but it does not have control.

This is why the question is broader than certificate management alone. machine identity inventory includes keys, certificates, tokens, and related deployment context. If the organisation cannot trace those assets from issuance to retirement, then it cannot confidently manage exposure, enforce policy, or recover quickly when something fails. For a deeper treatment of lifecycle and visibility, see NHI Lifecycle Management Guide and NHI Ownership and Accountability Guide.

At the control level, this is why machine identity problems tend to cluster around discovery gaps, unmanaged exceptions, and renewal dependence on individual knowledge. If only one team member knows where a certificate is used, then the inventory is effectively personal memory, not organisational control.

Risk and Threat Considerations

Weak inventory control creates exposure because unseen machine identities are harder to rotate, revoke, monitor, or recover. That increases the chance of expired certificates, stale credentials, and unmanaged access paths persisting long after they should have been removed.

Failure mechanism: The organisation loses authoritative visibility over machine identities, so renewal, ownership, and retirement decisions are made with incomplete data.

Impact: Operational outages, delayed recovery, and a larger attack surface follow because stale or unknown identities remain usable longer than intended.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingUncontrolled inventory leaves machine identities behind after use or ownership changes.
NHI-02 — Secret LeakageUnknown keys and certificates indicate secrets are not being inventoried or governed.
NHI-07 — Long-Lived SecretsPoor inventory control lets expired or stale credentials persist beyond intended lifecycle.
Recommendation — Track and retire machine identities when owners, systems, or purposes change. Inventory exposed keys and certificates, then rotate or revoke unknown material. Enforce expiry and rotation for machine credentials with clear ownership.
NIST CSF 2.0ID.AM-01 — Physical devices and systems within the organization are inventoriedInventory control depends on knowing what machine identities and related assets exist.
PR.AA-05 — Identities and access credentials are managed throughout the lifecycleKeys and certificates must be governed from issuance through retirement.
PR.PS-05 — Unused software, hardware, and services are removed or disabledOrphaned machine identities behave like unmanaged services that should be removed.
Recommendation — Maintain an authoritative inventory of machine identity assets and dependencies. Manage machine credentials through issuance, rotation, and revocation. Remove or disable stale machine identities and unused credential paths.
CIS Controls v8CIS-1 — Inventory and Control of Enterprise AssetsMachine identity control begins with knowing all relevant assets and deployments.
CIS-5 — Account ManagementMachine identities require ownership, lifecycle, and removal discipline.
CIS-6 — Access Control ManagementUncontrolled inventories undermine renewal, revocation, and access governance.
Recommendation — Inventory machine identity assets and keep the record continuously current. Assign owners and lifecycle rules to every machine identity. Revoke or adjust access when machine identity use is no longer justified.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsKeys, certificates, and deployments must be tracked as managed assets.
Recommendation — Maintain an inventory covering machine identities and their dependent assets.

Practitioner Guidance

What to verify: The practical test is whether an owner, a deployment location, and a renewal path can be identified for every key or certificate without manual detective work. If that answer requires tribal knowledge, the inventory is not under control.

What good looks like: The organisation can reconcile inventory from discovery to ownership to lifecycle status, and it can show which identities are active, which are nearing expiry, and which have no accountable owner. Where machine identities are certificate-heavy, a dedicated lifecycle view such as Machine Identity, PKI and Certificate Lifecycle Guide is the right reference point.

Practitioner takeaway: If the inventory cannot drive renewal, rotation, and retirement without manual intervention, the organisation has visibility at best, not control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org