Many teams focus on features before they solve discovery. If you do not know where privilege exists, who uses it, and which privileges should be revoked, you cannot build an effective zero standing privilege model. The common mistake is treating PAM as a vault problem instead of an onboarding, inventory, and governance problem.
Discovery is a governance problem before it is a tooling problem
The biggest discovery failure is starting with feature selection instead of answering three basic questions: where privileged access exists, who can use it, and what should be removed or reduced. That is why discovery has to cover human and non-human privileged access path, standing permissions, and the accounts or keys that quietly accumulate authority over time. The lifecycle view of non-human identities is useful here because discovery is the intake mechanism for everything that follows.
Teams also underestimate how often the inventory is fragmented across directories, cloud consoles, CI/CD, vaults, application code, and third-party integrations. If discovery is scoped only to a single vault or PAM queue, you miss the broader set of credentials and entitlements that define actual privileged reach. The operational objective is not just to find accounts, it is to establish ownership, purpose, and revocation authority for each one.
A useful benchmark for why this matters is that only 5.7% of organisations report full visibility into their service accounts, which shows how often discovery gaps are the root problem rather than a later control failure.
What teams miss when they treat discovery as a scan
Discovery is often reduced to listing accounts or secrets, but that only creates an inventory, not control. Useful discovery has to answer whether the privilege is still needed, whether it is shared, whether it is excessive, and whether the account is tied to a legitimate owner and lifecycle. That is why a discovery process must connect visibility gaps, overprivilege, and unmanaged credentials rather than treating them as separate problems.
The same mistake shows up when teams equate “found” with “governed.” A dormant account, a long-lived API key, and an actively used production service account are all privileged objects, but they require different decisions. Discovery should therefore feed classification, ownership assignment, and recertification, not just a report.
Teams also miss that discovery quality degrades quickly when it depends on manual self-reporting. If application owners cannot identify their own service accounts or explain why a credential still exists, the issue is not a missing dashboard, it is a broken control model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Discovery and Inventory | Discovery and inventory are central to privileged access risk reduction. |
| NHI-02 — Lifecycle and Offboarding | Discovery must feed ownership, revocation, and offboarding decisions. | |
| NHI-03 — Secrets and Credential Management | Discovery often misses secrets outside the vault and code repositories. | |
| Recommendation — Inventory all privileged identities and secrets before enforcing least privilege or revocation. Tie discovered privileges to owners and remove access when purpose no longer exists. Locate exposed secrets and bring them under managed rotation and control. | ||
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems inventoried | Asset inventory is the prerequisite for understanding where privileged access exists. |
| PR.AA-01 — Identities and credentials managed | Discovery must identify privileged identities and their credentials before control can be enforced. | |
| Recommendation — Maintain a complete inventory of systems that can grant or store privileged access. Identify privileged identities and manage their credentials through a governed lifecycle. | ||
| CIS Controls v8 | 5.3 — Account Inventory and Control | Account inventory is the concrete control gap behind discovery failures. |
| 6.1 — Establish Access Control Policy | Discovery must support access policy decisions about who should retain privilege. | |
| Recommendation — Maintain an authoritative inventory of privileged accounts and remove unauthorized ones. Define and enforce access rules that limit privileged access to business need. | ||
| NIST Zero Trust (SP 800-207) | SC-7 — Policy Enforcement and Least Privilege Access | Discovery is required to enforce least privilege in a zero trust model. |
| Recommendation — Use discovery outputs to enforce least-privilege access decisions at policy enforcement points. | ||
Practitioner Guidance
What to prioritise: Start with the inventory questions that drive action, not the ones that produce the longest list. For each privileged account or secret, determine owner, system of record, business purpose, last used date, and revocation path before you discuss vaulting or rotation.
What to verify: A credible discovery process should produce a revocation-ready map, not a discovery spreadsheet. If a team cannot show how it would disable a privileged path without breaking a production dependency, the discovery work is incomplete.
Common mistake: Assuming that PAM implementation will solve undocumented privilege. Tooling can enforce policy only after the organisation knows what privilege exists and who is accountable for it. Without that, PAM becomes a control layer over unknown risk.
Practitioner takeaway: The real test of discovery is whether it reduces the organisation’s unknown privileged surface enough to make least-privilege decisions possible.
Related resources from NHI Mgmt Group
- What do teams get wrong about RBAC when they try to manage temporary access at scale?
- What do security teams get wrong when they try to manage access for ephemeral workloads?
- What do teams get wrong about access control when they adopt shared password tools?
- What do teams get wrong when they try to reduce credential risk without full visibility?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org