Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the first thing teams should do…
Governance, Ownership & Risk

What is the first thing teams should do when they have no NHI governance program?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Start with discovery. You cannot reduce risk in service accounts, API keys, OAuth tokens, and AI agent credentials until you can inventory them, assign ownership, and identify which ones touch production systems or sensitive data. The first pass should prioritize the identities most likely to persist unnoticed after projects, integrations, or pilots end.

Why discovery comes before governance in NHI programmes

If there is no nhi governance program yet, the first job is not policy writing, tooling, or cleanup. Teams need a live inventory of non-human access points before they can decide what is owned, what is still needed, and what should be retired. Discovery turns a vague exposure problem into a bounded set of identities, credentials, and systems that can be managed.

That inventory should include the full spread of service accounts, API keys, OAuth tokens, certificates, workload identities, and AI agent credentials. The goal is to understand where they exist, what they touch, and whether they are tied to production systems or sensitive data. Without that baseline, every later control is partly guesswork.

Discovery also changes the conversation from abstract governance to operational reality. Teams usually find that the largest risk is not the newest integration, but the oldest credential that kept working after the project ended. That is why the first pass should focus on identities most likely to persist unnoticed after pilots, proofs of concept, decommissioned apps, or abandoned automation.

What good discovery actually needs to answer

A useful first-pass inventory is not a spreadsheet of names alone. It should answer four questions for each item: who owns it, what it authenticates to, whether it reaches production or sensitive data, and how long it has existed without review. A discovered identity that cannot be tied to an owner or business purpose should be treated as a governance gap, not just a documentation issue.

Priority should go to high-blast-radius credentials first. That means identities with broad permissions, shared use, long-lived access, or access to critical platforms. In practice, a small number of unmanaged non-human credentials often account for a disproportionate share of exposure because they combine invisibility, privilege, and persistence.

Once teams can see the population, they can begin separating active from stale, business-critical from orphaned, and tightly scoped from overprivileged. That distinction is what makes later governance decisions meaningful, because not every discovered identity deserves the same treatment. Some need immediate rotation or owner assignment, while others only need a cleanup decision or retirement path.

How to start without waiting for a perfect program

The first workable move is to scan the environments where non-human access is most likely to accumulate: cloud IAM, SaaS integrations, source control, CI/CD systems, application secrets stores, and agent or automation platforms. From there, trace each item back to an owner, dependency, and system of record where possible. This is often enough to reveal where the governance program should begin.

A practical first wave is to look for identities that are both hard to see and hard to replace. Shared service accounts, dormant API keys, tokens used by external integrations, and credentials embedded in scripts or pipelines should rise to the top. Those are the places where discovery immediately informs risk reduction because removal, rotation, or reassignment can follow quickly.

For teams setting the foundation, it helps to read the problem as both an inventory and ownership exercise. NHIMG’s Ultimate Guide to NHIs, Key Challenges and Risks is useful here because it frames discovery alongside visibility, sprawl, and unmanaged credentials. For a more direct ownership lens, the NHI Ownership and Accountability Guide helps teams separate identities they can govern from those they cannot yet explain.

Risk and Threat Considerations

Discovery is the point where hidden access becomes measurable. Until teams know which non-human identities exist, adversaries, former vendors, abandoned integrations, and forgotten automation can all keep using credentials that nobody is actively watching.

Failure mechanism: Orphaned or untracked service accounts, API keys, and tokens remain valid after projects end, owners leave, or integrations are forgotten, which preserves access paths that bypass normal review and offboarding.

Impact: Those unseen identities can become an easy persistence mechanism, a lateral movement path, or a production compromise point, especially when they hold broad permissions or reach sensitive data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingDiscovery is needed to find abandoned non-human identities before offboarding can happen.
NHI-02 — Secret LeakageThe question centers on finding exposed credentials before governance can reduce risk.
NHI-05 — Overprivileged NHIDiscovery must surface which NHIs have excessive access before rights can be trimmed.
Recommendation — Inventory dormant NHIs and remove access before credentials outlive the business need. Locate leaked secrets and rotate or revoke them as soon as they are found. Map privileges on discovered NHIs and reduce access to the minimum needed.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementInventories of API keys, tokens, and certificates are part of authenticator lifecycle control.
AC-2 — Account ManagementDiscovery identifies accounts and service identities that need ownership and lifecycle control.
IA-9 — Service Identification and AuthenticationService accounts, APIs, and workload identities are central to the discovery problem.
Recommendation — Track credential issuance, rotation, revocation, and expiration for all authenticators. Maintain an authoritative account inventory and disable accounts that are no longer justified. Inventory service-to-service identities and verify how each one authenticates.
NIST CSF 2.0ID.AM-01 — Identity Asset InventoryThe question asks for the first step, which is to inventory the identity population.
ID.AM-02 — Software, Data, and Information InventoryDiscovery must map non-human access to the data and systems it can reach.
ID.RA-01 — Asset Vulnerabilities Are Identified and DocumentedUnknown or orphaned non-human identities are an exposure that must be identified first.
Recommendation — Build and maintain a current inventory of identities and the systems they access. Document which discovered identities can access critical applications and sensitive data. Identify unmanaged credentials and record their exposure before deciding remediation.

Practitioner Guidance

What to prioritise: Start with identities that can reach production, touch sensitive data, or authenticate across multiple systems. Those are the ones most likely to create immediate exposure if they are stale, shared, or overprivileged.

What to verify: For every discovered item, verify ownership, business purpose, last known use, and whether rotation or removal is operationally safe. If those details cannot be established, treat the identity as a remediation candidate, not a managed asset.

Practitioner takeaway: A governance program cannot begin with control design alone; it begins with making non-human access visible enough that teams can decide what deserves protection, what deserves retirement, and what should never have been left active.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org