They misstate the real control boundary. Human review cadences, onboarding workflows and compliance checks do not govern service accounts, secrets or agent credentials unless those identities are explicitly in scope, so risk stays hidden while the maturity score improves on paper.
Where identity maturity models stop telling the truth
Identity maturity only works when the model matches the population being governed. If the rubric is built around employees, contractors, onboarding queues and periodic reviews, it can look disciplined while leaving service accounts, API keys, workload identities and agent credentials unmanaged. The result is a maturity score that tracks process completeness for people, not control over the identities that actually move data and actions.
That gap matters because NHIs and AI agents do not follow HR workflows. They are created by code, inherit access through pipelines, accumulate privileges quietly and often outlive the project or system that introduced them. If the model does not explicitly include those identities, the organisation may optimise the wrong operating rhythm and miss the assets that most need lifecycle control.
Identity maturity frameworks become misleading when they treat human governance as a proxy for all identity governance. A model can record strong joiner, mover, leaver discipline and still miss long-lived secrets, shared service credentials or agent permissions that were never designed into the review cycle.
That is why the control boundary has to be stated in terms of who or what can authenticate, what it can access, and how it is retired. Human vs Non-Human Identity is useful here because it shows where human and machine governance diverge, and why a single maturity ladder cannot safely flatten them into one set of processes.
Why the score improves while the risk stays hidden
A maturity model can improve on paper when the organisation checks more boxes around policy, approvals and periodic review, even though the true exposure is unchanged. If the rubric omits non-human actors, the team may celebrate coverage of onboarding and recertification while the actual attack surface expands through new integrations, automation and agents.
The practical failure is substitution. Human-centric controls are easiest to measure, so they become the proxy for control health even when they do not apply to machine or agent access. That creates a false sense of progress: better evidence collection, cleaner audit trails and more repeatable compliance reporting, but no corresponding reduction in secret sprawl, overprivilege or dormant access paths.
Top 10 NHI Issues captures the kinds of failure that the human-only model misses, especially ownership gaps, credential lifecycle drift and excessive permissions. Those are not edge cases, they are the mechanisms that turn a polished maturity narrative into real exposure.
This is also where AI agents make the problem sharper. An agent can appear “managed” because its project is approved and its prompts are reviewed, while its actual credentials, tool access and delegated authority are left outside the model. A maturity framework that does not distinguish approval of the project from control of the identity will overstate governance.
What a complete maturity model must include
A usable maturity model should ask whether each identity class has a clear owner, a defined lifecycle, bounded privilege and evidence of retirement. For NHIs and AI agents, that means the model needs to track secrets, tokens, certificates, service principals, delegated access and the process that revokes them when the workload changes.
It also needs separate control questions for creation, authentication, authorization, rotation and offboarding. Those steps are often automated, but automation is not a substitute for scope. If the model cannot tell you how an identity is issued, what it can reach, how long it lives and how it is removed, then the maturity score is measuring documentation quality more than actual control.
For agent-based systems, AI Agent Authorisation Guide is a good reminder that access should be task-scoped and decisioned per action, not granted as a generic project entitlement. Agentic AI Identity Guide adds the lifecycle view, including registration, delegation and retirement, which is exactly where human-only maturity models tend to go blind.
At the framework level, the right question is whether the model can separate governance for people from governance for non-human actors and agents. If it cannot, it will keep rewarding process completeness while leaving the highest-frequency machine access paths under-assessed.
Risk and Threat Considerations
When NHI and agent identities are excluded, the organisation creates a blind spot that adversaries can exploit through secrets, tokens, overprivileged service accounts and delegated agent access. The risk is not just a weaker scorecard, it is misplaced confidence that delays containment, rotation and privilege reduction.
Failure mechanism: Human review cadences, approvals and recertification cycles do not automatically apply to non-human credentials, so unmanaged machine access persists outside the maturity model and can be abused without triggering the expected governance checks.
Impact: Attack paths remain open, blast radius increases and the business may believe identity controls are improving even while its real authentication and authorization surface is getting larger.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack surface, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Excluding NHIs leaves non-human credentials active beyond their useful life. |
| NHI-05 — Overprivileged NHI | Human-only maturity models miss excessive machine privileges and access scope. | |
| NHI-07 — Long-Lived Secrets | Identity models that ignore NHIs often fail to measure secret lifetime risk. | |
| Recommendation — Track NHI offboarding and revoke credentials when the workload or agent is retired. Limit NHI permissions to the minimum access required for each workload or agent. Rotate long-lived secrets and replace them with shorter-lived credentials where possible. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | AI agents excluded from maturity models can retain ungoverned delegated access. |
| Recommendation — Constrain agent identity and privilege so each action is explicitly authorised. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The question centers on lifecycle control of credentials and secrets. |
| IA-9 — Service Identification and Authentication | NHIs and agents authenticate as services, workloads, or APIs outside human workflows. | |
| AC-6 — Least Privilege | Excluded NHIs and agents can accumulate excessive access that the maturity model misses. | |
| Recommendation — Manage credential issuance, rotation, and revocation for both human and non-human identities. Use service authentication controls for machine and workload identities, not human processes. Review and restrict non-human access so each identity has only the permissions it needs. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | The question is about whether the model captures the real control boundary and risk exposure. |
| ID.AM-01 — Physical Devices and Systems Inventoried | A maturity model cannot govern identities it does not inventory or distinguish. | |
| Recommendation — Define risk ownership and scope so identity maturity includes every governed identity class. Inventory all identity-bearing assets and keep human and non-human populations separate. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The topic is fundamentally about who gets access and how that access is governed. |
| Recommendation — Apply access-control policy to every identity type that can reach production resources. | ||
Practitioner Guidance
What to verify: Check whether the maturity model explicitly inventories NHIs and AI agents, or only measures human identity operations. If the model cannot show ownership, rotation and offboarding for machine credentials, it is not describing true identity maturity.
Decision rule: If an identity can authenticate without a person in the loop, treat it as a first-class scope item in the model and require a separate control path for creation, privilege assignment and retirement.
What good looks like: The maturity assessment should produce different evidence for people, service identities and agents, with separate metrics for lifecycle completeness, privileged access and secret hygiene. A single “covered” score should never hide that one population has no real governance.
Practitioner takeaway: A mature identity programme is not the one with the best human workflow, it is the one that measures every actor that can obtain and use access, then proves it can bound and remove that access on time.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org