Vaulting protects the secret that unlocks access, while ZSP removes the standing entitlement that makes the secret useful at all times. Vaulting can coexist with persistent privilege, but ZSP changes the authorisation model itself. Teams need both where appropriate, but they should not confuse secret custody with privilege elimination.
How ZSP and vaulting solve different problems
ZSP and vaulting both reduce NHI risk, but they operate at different layers. Vaulting controls access to the secret itself, usually by storing credentials centrally and releasing them on demand. ZSP removes the standing permission to use that secret continuously, so even a valid credential is not permanently usable. Privileged Access Management Guide is useful background here because it frames vaulting and ZSP as separate controls rather than substitutes.
That distinction matters in practice because a vaulted secret can still unlock always-on access if the underlying entitlement never expires. ZSP changes the authorisation model, typically by making access time-bound, approval-based, or just-in-time. Vaulting answers "who can retrieve the secret?", while ZSP answers "when may the identity use privilege at all?" Just-in-Time Access and Zero Standing Privilege Guide and NHI Authentication Guide both help separate authentication mechanics from privilege design.
Because they solve different failure modes, the strongest posture is often layered. Vaulting reduces secret exposure, rotation burden, and leakage risk, while ZSP reduces the blast radius of a stolen or overused credential by ensuring access is only active when needed. For machine and service identities, that usually means combining secret custody, short-lived access, and explicit privilege review. Service Account Security Guide and NHI Lifecycle Management Guide both address the operational side of making that combination sustainable.
Why vaulting alone is not zero standing privilege
Vaulting is often misunderstood as a complete access-control strategy because it hides secrets and centralises checkout. In reality, it can still leave a standing entitlement in place, such as a persistent role, token scope, or administrative grant that remains usable whenever the secret is obtained. In that model, the secret is protected, but the privilege remains continuously available. Ultimate Guide to NHIs — Static vs Dynamic Secrets is a good reference point for the difference between secret handling and privilege duration.
ZSP changes the risk profile more directly because it reduces the time window in which privilege exists. A credential may still be issued, vaulted, or rotated, but the key security property is that the identity does not retain standing access between tasks. That is why ZSP is a privilege model, not just a secret-management pattern. It is especially relevant where human or automated operators should only have transient elevation for a bounded task, rather than a permanently valid route to production systems. Privileged Access Management Guide and Just-in-Time Access and Zero Standing Privilege Guide cover that control pattern directly.
In other words, vaulting can protect access material, but it does not by itself eliminate privilege. ZSP can eliminate standing privilege, but it does not by itself solve weak secret custody. Practitioners usually need both controls where an NHI must authenticate and also hold sensitive authority.
How to choose the right control for the job
The deciding question is whether the main weakness is secret exposure, privilege persistence, or both. If the problem is that credentials are hard to protect, hard to rotate, or widely copied, vaulting is the first control to improve. If the problem is that the NHI remains eligible to act at all times, ZSP is the control that changes the access model.
For many environments, the right sequence is to vault the secret first, then remove standing privilege on top of that. That sequencing matters because a secure secret with persistent privilege still creates a large blast radius, while ZSP without good secret hygiene can still leave too much exposure through leaked or reused credentials. The control choice should be based on whether the organisation is trying to secure the secret, constrain the authority, or both.
Decision rule: if the secret can be stolen but the identity should not be continuously usable, ZSP is the higher-value control; if the secret is broadly exposed or difficult to govern, vaulting is the immediate containment step.
What to verify: confirm whether the vaulted credential still maps to a standing role, token scope, or admin entitlement. If yes, the environment has secret protection but not zero standing privilege.
Common mistake: treating password vaulting, key storage, or secret checkout as proof that privilege has been eliminated. That shortcut confuses custody with authorisation and leaves the core access path intact.
Practitioner takeaway: vaulting reduces who can obtain the secret, while ZSP reduces when the identity is allowed to wield power. If you need real blast-radius reduction, measure both the secrecy of the credential and the persistence of the entitlement.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers secret lifecycle and protected handling for NHI credentials. |
| AC-6 — Least Privilege | Directly supports removing standing entitlement from NHIs. | |
| IA-9 — Service Identification and Authentication | Applies to non-human identities authenticating to systems through managed secrets or tokens. | |
| Recommendation — Enforce IA-5 to manage issuance, storage, rotation, and revocation of NHI authenticators. Apply AC-6 to limit NHI permissions to the minimum needed for each task. Use IA-9 to control how services and workloads authenticate before granting access. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Vaulting addresses the secret-exposure side of NHI access. |
| NHI-05 — Overprivileged NHI | ZSP directly counters persistent excessive privilege for NHIs. | |
| Recommendation — Reduce NHI secret leakage by centralising storage and limiting secret exposure paths. Eliminate overprivileged NHI access by removing standing entitlement and using just-in-time elevation. | ||
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between human IAM controls and NHI governance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org