Accountability should sit with the identity and access governance function, because the real issue is not the hardware token alone but the policy that defines where it is valid, who approves it, and how it is recovered. That model should be reviewed alongside privileged access and certificate governance.
Why This Matters for Security Teams
Device-bound passkeys can look simple on the surface, but accountability becomes difficult the moment the same credential is allowed on both shared and personal devices. The core question is not which device holds the key material. It is who owns the policy for enrolment, approval, recovery, and exception handling when device context changes. That ownership must be explicit because passkey validity often intersects with privilege, endpoint trust, and identity lifecycle controls. NHI Mgmt Group notes that many organisations still struggle to fully address identity risk, and the same governance gap shows up when passkeys are used without clear operating rules.
Security teams commonly misplace this issue under endpoint management alone, even though identity governance, PAM, and recovery controls determine whether a passkey is acceptable on a shared laptop, a managed phone, or a personal device. Current guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls points practitioners toward accountable access control and lifecycle management, not device convenience. In practice, many security teams encounter passkey disputes only after an account is recovered from an unvetted device, rather than through intentional governance design.
How It Works in Practice
Accountability should rest with the identity and access governance function because that team can define where a device-bound passkey is valid, who may approve registration, and what happens when the device is lost, shared, or repurposed. In mature environments, the passkey itself is treated as one factor in a broader trust decision, not as a blanket approval to authenticate anywhere. The policy should distinguish managed corporate devices from personal devices, and both from truly shared endpoints such as kiosks or hot desks.
Practitioners usually need four controls working together:
- Device enrollment rules that define which endpoints may register a passkey.
- Identity proofing and approval workflows for initial binding and re-binding.
- Recovery and revocation procedures for lost devices, shared-device use, and employee offboarding.
- Audit trails that show who approved the binding, where it was used, and whether exceptions were granted.
That policy should be reviewed alongside privileged access and certificate governance because passkeys may be used to unlock highly sensitive accounts. The broader NHI governance model described in Ultimate Guide to NHIs is useful here: when identity ownership, lifecycle, and revocation are weak, access controls fail even when the authentication method is modern. Device-bound passkeys do not remove accountability; they make it more visible by tying identity decisions to endpoint trust. These controls tend to break down in BYOD-heavy environments because shared device use blurs ownership, recovery, and revocation responsibilities.
Common Variations and Edge Cases
Tighter passkey policy often increases help desk load and onboarding friction, requiring organisations to balance stronger assurance against user support overhead. That tradeoff becomes most visible when a workforce mixes corporate laptops, personal phones, contractors, and shared terminals. There is no universal standard for this yet, so current guidance suggests treating high-risk use cases differently rather than applying one enrollment rule everywhere.
Shared devices are the hardest case. A passkey bound to a personal device may be acceptable for low-risk access, but it should not automatically extend to admin roles, regulated data, or break-glass accounts. For those scenarios, organisations often pair passkeys with step-up verification, session limits, or separate privileged enrollment paths. Where certificate-based login is already in place, the governance model should align passkey policy with certificate issuance and revocation so recovery decisions remain consistent across authentication methods.
For a broader identity control baseline, the same lifecycle discipline described in Ultimate Guide to NHIs applies: define ownership, reduce standing trust, and make revocation fast. In practice, the weakest point is usually not the passkey itself, but the exception path when a shared device is temporarily trusted and then forgotten.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-03 | Identity proofing and credential binding drive passkey accountability. |
| NIST SP 800-63 | Digital identity guidance helps distinguish authenticators, binding, and recovery. | |
| OWASP Non-Human Identity Top 10 | NHI-05 | Passkey governance mirrors lifecycle control and revocation expectations for identities. |
| NIST AI RMF | Accountability depends on governance and lifecycle oversight, not only authentication mechanics. | |
| NIST Zero Trust (SP 800-207) | SC-2 | Device context and continuous trust decisions align with zero trust access principles. |
Assign clear governance ownership for binding, recovery, and exception handling under the AI RMF GOVERN function.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org