Revoke or decommission it through a lifecycle process, not as an ad hoc cleanup task. The identity should be retired, its credentials invalidated, and its ownership closed out so access does not outlive the service or integration it supported.
How should a non-human identity be retired?
A non-human identity should be treated as a lifecycle object, not a cleanup item. Once the service, workload, or integration no longer needs it, teams should retire the identity, invalidate every credential or token tied to it, and close out ownership so the access path cannot linger after the business purpose has ended.
What does proper offboarding actually include?
Offboarding is more than disabling a login. It means identifying every place the identity was trusted, revoking those trusts, and confirming that dependent systems no longer rely on the same account, key, certificate, or grant. If the identity was shared across environments or applications, each dependency needs explicit removal rather than assumed expiry.
Because these identities often authenticate machine-to-machine or application-to-application traffic, retirement has to cover the full credential set, not just the primary account object. That includes API keys, OAuth grants, certificates, secret references, and any delegated permissions that would still permit access after the original owner has moved on. NHI lifecycle management is the right lens for this work.
What should teams verify before closing it out?
Teams should verify that the identity is no longer referenced in production jobs, scripts, integrations, schedulers, or infrastructure code, and that replacement credentials are in place where access must continue under a new identity. A decommissioned identity should have an auditable owner, a clear retirement date, and evidence that its credentials were invalidated rather than merely left idle.
What good looks like is a documented retirement record that ties the identity to a service or integration, shows who approved removal, and confirms that downstream dependencies were remediated. That is the difference between governed offboarding and silent drift. NHI ownership and accountability is what makes that closeout defensible.
Risk and Threat Considerations
Retiring the identity matters because stale non-human access is a common source of persistent exposure. If old credentials, tokens, or certificates remain valid after the service is gone, an attacker who finds them can still authenticate and move through systems that no longer have an active business owner watching them.
Failure mechanism: The identity is disabled in one place but its credentials, grants, or trust relationships survive elsewhere, allowing continued access through a forgotten dependency, long-lived secret, or unrevoked certificate.
Impact: Unused identities become orphaned access paths, which increases the blast radius of credential theft, privilege misuse, and accidental reuse across later projects or environments.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Retiring an unused NHI is directly about proper offboarding and revocation. |
| NHI-07 — Long-Lived Secrets | Retirement must eliminate lingering secrets that keep old access alive. | |
| Recommendation — Revoke access, invalidate secrets, and remove the NHI from all dependent systems. Shorten secret lifetime and rotate or destroy any credential that can still authenticate. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Retirement requires invalidating authenticators, keys, and tokens tied to the identity. |
| AC-2 — Account Management | Account lifecycle control covers provisioning, disabling, and removal when access ends. | |
| AC-6 — Least Privilege | Retirement is the final step in eliminating unnecessary access and lingering privilege. | |
| Recommendation — Disable and replace authenticators so retired access cannot be reused. Remove accounts through a documented lifecycle process when they are no longer needed. Eliminate any residual privilege paths once the identity is no longer required. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity management governs the lifecycle and removal of identities and access. |
| A.8.5 — Secure authentication | Retirement requires invalidating authentication material, not just disabling a label. | |
| Recommendation — Use identity lifecycle controls to retire non-human access cleanly. Invalidate authentication material when the identity is decommissioned. | ||
Practitioner Guidance
What to prioritise: Revoke the credential that still works first, then remove the identity object, then clean up any remaining references in automation or policy. If the retirement order is reversed, the access path may survive even though the account appears gone.
What to verify: Confirm that no scheduled task, secret store entry, application config, or certificate chain can still authenticate with the retired identity. The important test is not whether the account exists, but whether anything can still use it.
Practitioner takeaway: Treat decommissioning as a controlled security event, not housekeeping. The access is only truly gone when the identity, its credentials, and every dependency on it have all been explicitly retired.
Related resources from NHI Mgmt Group
- How should teams certify non-human identity access without breaking production?
- How should IAM teams respond when Office 365 identity sprawl spans human and non-human access?
- What do identity teams get wrong about non-human access governance?
- How should security teams govern API access as a non-human identity?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org