The clearest sign is when teams can report how many service accounts or keys they have, but cannot say which ones reach crown-jewel assets. Another warning sign is when access reviews cover human groups while machine credentials remain outside certification, especially in hybrid and multi-cloud estates.
When identity counts hide the real governance problem
The strongest warning sign is that the programme is optimising for inventory volume instead of control coverage. If teams can report the number of service accounts, keys, or tokens, but cannot tell which ones can reach production, privileged systems, or crown-jewel assets, the governance model is too shallow to be useful. Counting identities is a starting point, not evidence of managed exposure.
A second sign is that the reporting cadence is stuck at static inventory questions such as “how many do we have?” while missing lifecycle and authority questions such as “who owns it, what does it touch, and when was it last reviewed?” That gap usually means the programme is measuring presence, not privilege, and is treating machine access as an asset register problem rather than an access governance problem.
When this happens in practice, the identity landscape often looks busy but remains poorly explained. Teams may know which platforms host NHI, but not which accounts are shared, long-lived, unowned, or able to bypass separation between environments. That is the point at which an identity programme becomes misleading, because the number can rise while the actual blast radius remains unchanged or grows.
What identity-count focused governance misses
Identity-count focused governance misses the relationships that decide risk. The material questions are not whether an identity exists, but whether it is tied to an owner, whether its permissions are still needed, whether it can authenticate without a human in the loop, and whether it is present in the review process. The difference matters most in hybrid and multi-cloud environments, where one credential can cross boundaries that a spreadsheet cannot describe cleanly.
This is why a healthy governance model tracks reach, privilege, and lifecycle state alongside inventory. A service account with low exposure and short-lived credentials is not equivalent to a dormant key that can reach multiple production APIs. Likewise, a large inventory with weak ownership coverage can be less secure than a smaller inventory with consistent recertification, rotation, and environment isolation.
Another sign of count fixation is inconsistent review scope. If human access certifications are mature while machine credentials sit outside the certification workflow, the organisation is creating an artificial control boundary. That boundary is usually a legacy process choice, not a security distinction, and it leaves the highest-risk access paths outside regular accountability.
What better NHI governance looks like
Better governance starts with control questions, not headcount. The programme should be able to answer which identities can reach sensitive assets, which are shared, which are overprivileged, which have not been used recently, and which are outside an explicit owner-and-review model. When teams can answer those questions quickly, count becomes a useful metric; when they cannot, count is mostly noise.
- Map each NHI to the systems it can reach, then separate low-risk inventory from privileged exposure.
- Attach an accountable owner to every production credential or service identity, including exceptions and legacy accounts.
- Bring machine credentials into the same certification logic as human access where they can affect production systems.
- Use rotation, expiry, and scoped permissions to reduce the number of identities that remain permanently valid.
That approach also scales better. As estates expand across SaaS, cloud, CI/CD, and application integrations, the useful unit of governance is not “how many identities exist” but “how many identities can still do material harm if compromised or misused.”
Risk and Threat Considerations
Identity-count focus creates blind spots that adversaries can exploit. A large but poorly governed inventory can hide orphaned, shared, or stale machine credentials, which are attractive because they often have broad reach and weak monitoring. In hybrid estates, those credentials can become quiet pathways into production systems long before anyone notices that the count looked healthy.
Failure mechanism: Teams over-rely on inventory totals, so credentials with real access are left outside ownership, certification, and lifecycle controls. That allows overprivileged or forgotten identities to persist until they are abused, leaked, or discovered during incident response.
Impact: The organisation may believe governance is improving while exposure remains unchanged. The result is wider blast radius, weaker accountability, and slower containment when a service account, API key, or token is compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Directly addresses the risk of identities with more access than they need. |
| NHI-01 — Improper Offboarding | Counts can hide retired or forgotten credentials that were never removed. | |
| NHI-08 — Environment Isolation | Hybrid estates make cross-environment reach a key governance concern. | |
| Recommendation — Reduce standing access and scope every NHI to the minimum permissions required. Revoke and remove stale NHIs when systems, owners, or integrations are retired. Segregate credentials and permissions so lower-trust environments cannot reach production. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The issue is excessive access, not identity volume. |
| IA-5 — Authenticator Management | Long-lived keys and unmanaged credentials are central to the governance gap. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Governance must reveal which identities can reach sensitive assets and how they are used. | |
| Recommendation — Limit every service credential to the minimum permissions needed for its task. Track, rotate, and revoke authenticators with defined ownership and expiry. Review logs and reports for privileged NHI access paths, anomalies, and stale credentials. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account inventories only matter when tied to ownership, lifecycle, and access review. |
| CIS-6 — Access Control Management | The core problem is unmanaged access, not simply too many identities. | |
| Recommendation — Maintain an authoritative account inventory with owners, purpose, and periodic review. Enforce access approval, review, and revocation for machine credentials as well as users. | ||
| NIST CSF 2.0 | GV.OC-03 — Mission and stakeholder needs are understood and communicated | Governance should define which identities matter because they touch critical assets. |
| Recommendation — Tie NHI governance reporting to business-critical systems and ownership expectations. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity governance must identify and control who or what can access important assets. |
| Recommendation — Define and maintain identity records, ownership, and lifecycle state for NHIs. | ||
Practitioner Guidance
What to verify: Test whether your reporting can link each production NHI to an owner, a target asset, and a last-review date. If it cannot, the governance model is not yet measuring control effectiveness.
Decision rule: If a metric cannot distinguish a harmless inventory item from a credential that can reach a crown-jewel system, treat that metric as informational only and do not use it as a success measure.
What to measure: Prioritise coverage of privileged reach, ownership assignment, and review inclusion over raw counts. Those signals show whether governance is actually reducing risk rather than just cataloguing it.
Practitioner takeaway: The right question is never how many non-human identities you have, it is how many of them can still reach something important without enough ownership, review, or containment.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org