A carve-out is the separation of a business unit, subsidiary, or asset from a parent organisation into a distinct operating environment. In identity security, it forces a rapid redesign of access, directories, privileged accounts, and governance so the new entity can function independently without inheriting unnecessary risk.
Expanded Definition
A carve-out is not just a corporate separation event; in NHI security, it is a reset of identity trust boundaries. The new operating environment must inherit only the accounts, secrets, roles, and integrations that are explicitly required. Everything else should be reissued, removed, or isolated. That distinction matters because identity sprawl often hides inside shared directories, inherited admin groups, and embedded API keys.
In practice, a carve-out touches service accounts, machine certificates, CI/CD credentials, federation trusts, and privileged workflows. No single standard governs this yet, so usage in the industry is still evolving, but the security objective is consistent: establish independent identity governance without carrying forward unnecessary parent-company access. Guidance in NIST Cybersecurity Framework 2.0 reinforces the need to identify, protect, and govern assets during organisational change.
The most common misapplication is treating a carve-out as an IT migration, which occurs when teams copy directories and credentials first and assess least privilege later.
Examples and Use Cases
Implementing a carve-out rigorously often introduces short-term disruption to authentication, privileged access, and automation, requiring organisations to weigh separation speed against operational continuity.
- A subsidiary leaves a parent tenant and receives a new identity boundary, with its own directory, admin roles, and conditional access policies.
- Shared service accounts used by deployment pipelines are replaced with new credentials and scoped permissions so the new entity does not retain parent-system reach.
- Third-party integrations are revalidated during separation, using the governance expectations described in the Ultimate Guide to NHIs to prevent inherited secrets from surviving the transition.
- Privileged access paths are rebuilt from scratch instead of cloned, aligning the carve-out with NIST Cybersecurity Framework 2.0 principles for asset control and recovery.
- API keys and certificates tied to the parent organisation are revoked and reissued, because separation is incomplete until old trust relationships are removed.
Why It Matters in NHI Security
Carve-outs are high-risk moments because inherited NHIs often remain active long after legal separation is complete. That creates a hidden dependency on the parent organisation and expands the attack surface across both entities. NHI Mgmt Group research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which makes carved-out environments especially vulnerable if credentials are duplicated instead of replaced. The Ultimate Guide to NHIs also reports that only 5.7% of organisations have full visibility into their service accounts, a gap that becomes dangerous when teams must rapidly inventory what should stay, what should move, and what must be revoked.
From a governance perspective, carve-outs force decisions about ownership, rotation, offboarding, and emergency access. They are also a stress test for Zero Trust thinking: if trust is assumed because an account existed before the separation, the new entity may begin life with excessive privilege. Organisations typically encounter the impact only after an audit, incident, or post-close breach review, at which point carve-out identity cleanup becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Carve-outs often expose inherited NHI sprawl and unowned credentials that this control is meant to surface. |
| NIST CSF 2.0 | PR.AA | Identity and authentication governance are required to rebuild trust boundaries after organisational separation. |
| NIST Zero Trust (SP 800-207) | SA-5 | Zero Trust requires explicit trust boundaries, which carve-outs must redefine instead of inheriting. |
| NIST SP 800-63 | IAL2 | Assurance principles help validate who can administer identities when org boundaries change. |
Inventory every non-human identity during separation and eliminate or reissue anything not explicitly needed.
Related resources from NHI Mgmt Group
- How should organisations rebuild identity governance after a carve-out or similar infrastructure separation?
- What breaks when identity and access management is rebuilt too slowly after an infrastructure carve-out?
- Carve-Out Identity Governance
- How should security teams phase out password-based authentication without disrupting operations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org