Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should teams do when a platform can…
Governance, Ownership & Risk

What should teams do when a platform can inventory identities but not model reachability?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Treat it as a visibility tool, not a control system. Inventory is useful for scope, but it cannot prove whether a token, service account, or AI workflow can reach anything important. If the platform cannot model paths and confirm exploitability, another layer is needed before it can guide remediation.

When inventory is only visibility, what does that mean operationally?

An identity inventory tells you what exists, where it appears, and who claims ownership. It does not tell you whether the identity can actually reach a system, call an API, read data, or chain into a higher-impact workflow. That distinction matters because inventories reduce unknowns, while reachability determines whether a weakness is exploitable.

A platform that only inventories identities is most useful for scoping, hygiene, and discovery. It can help teams spot stale objects, orphaned accounts, duplicated credentials, and obvious drift. But if it cannot evaluate effective access, path conditions, or the dependencies behind a token or service account, it cannot answer the question practitioners actually care about: can this identity do something important?

That is why identity visibility products should be treated as inputs to analysis, not as the analysis itself. A complete view often needs a second layer that can model trust boundaries, authorization paths, and the practical effect of permissions in context, especially when service accounts, shared secrets, or automated workflows are involved. NHIMG’s Identity Security Maturity Model is useful here because it separates basic inventory capability from higher-order governance and control maturity.

Why reachability changes the security decision

Reachability is what turns a record in an inventory into a security-relevant asset. Two identities can look similar on paper yet have very different blast radius: one may be present but effectively inert, while another may hold a path to production data, administrative APIs, or an AI workflow that can trigger downstream actions. Without path modelling, teams often overreact to low-risk objects and miss the few that actually matter.

This is where the operational decision changes. If a platform can only show presence, it supports triage; if it can show effective access, it starts to support prioritisation. The difference is especially important in environments where tokens, service accounts, and machine or workflow identities are created faster than people can review them. NHIMG’s Identity Visibility and Intelligence Platforms (IVIP) Guide helps frame that shift from static visibility toward effective access and identity intelligence.

For teams evaluating platforms, this also means the test should be concrete: can the tool show what an identity can touch, under which conditions, and through which transitive relationships? If not, it may still be valuable, but only as a discovery layer. Reachability and exploitability need their own validation path, whether that comes from graph analysis, policy simulation, workload context, or external attack-path review. The broader Identity Convergence Guide is a useful companion when the real problem spans multiple identity types and control planes.

How teams should use inventory-first platforms without overtrusting them

The right operating model is to use inventory for completeness and separate control validation for risk. Inventory answers “what do we have?” and “where is it owned?” Control validation answers “what can it reach?” and “what would an attacker or faulty automation actually be able to do?” Mixing those questions leads to false confidence, especially when stale entitlements, inherited permissions, or hidden trust relationships are present.

That separation is also why governance teams should resist using inventory outputs as remediation closure by themselves. A finding is not resolved because the object is catalogued; it is resolved when its access is understood, reduced where necessary, and verified against the systems it can influence. NHIMG’s IGA Buyer's Guide is relevant for teams that need a stronger lifecycle and review layer alongside visibility tooling.

In practice, teams get the most value when they combine inventory with a path-aware lens: identify the identity, locate its owners, confirm its secrets or credentials, map the reachable targets, and then decide whether it needs reduction, segmentation, or removal. That is the point where a visibility tool becomes a planning aid rather than a misleading control surrogate.

Risk and Threat Considerations

The risk is that a platform with inventory but no reachability is mistaken for a control, which can leave high-impact access paths unexamined. Attackers and accidental misuse both benefit from that gap because an identity can look benign in a list while still being able to reach critical data, privileged functions, or chained automation.

Failure mechanism: Static discovery without path modelling misses transitive access, hidden dependencies, and contextual conditions that determine whether an identity can actually be abused. That creates blind spots around tokens, service accounts, shared credentials, and automated workflows that appear known but are not truly understood.

Impact: Teams may defer remediation, underestimate blast radius, or prioritise the wrong objects, allowing material exposure to persist until an incident or failed change reveals the missing reachability analysis.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-01 — Identity InventoryIdentity inventory is the starting point for scope and asset awareness.
ID.RA-01 — Risk IdentificationReachability determines whether an identity inventory issue becomes exploitable risk.
Recommendation — Inventory identities and keep the catalog current before assessing access risk. Assess whether each identity can reach critical assets before accepting remediation closure.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeReachability checks reveal whether identities have excessive effective access.
IA-5 — Authenticator ManagementTokens and service-account credentials need lifecycle control beyond inventory.
Recommendation — Reduce effective access to the minimum needed for each identity. Track, rotate, and retire credentials separately from simple discovery.
CIS Controls v8CIS-5 — Account ManagementInventory supports account management, but effective access must still be validated.
Recommendation — Maintain account inventory and verify access paths that inventory alone cannot prove.

Practitioner Guidance

What to prioritise: Treat the inventory as your source of scope, then add a separate reachability or effective-access check before you accept any remediation decision. If the platform cannot show a path, assume the risk remains unresolved rather than merely undocumented.

What to verify: Confirm whether the tool can model transitive access, inherited permissions, and actual target systems, not just object existence. If it cannot, use it for discovery and pair it with a path-analysis, policy, or review process that can answer exploitability questions.

Practitioner takeaway: Visibility is valuable, but remediation should only be driven by evidence of reachable impact, not by the mere presence of an identity record.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org