Dark matter identity is NHIMG shorthand for identity activity that exists and acts but is not visible to central IAM governance. These identities may be service accounts, embedded secrets, local application users, or AI agent credentials that operate outside the governed inventory and therefore escape normal review cycles.
Expanded Definition
Dark matter identity refers to identity activity that performs work but remains outside central IAM governance. In practice, it includes service accounts, embedded secrets, local application users, automation credentials, and AI agent identities that are not fully inventoried, reviewed, or tied to a consistent ownership model.
The term is useful because traditional identity programs often focus on human users first, while machine and agent identities multiply across code, pipelines, and distributed services. NHI Management Group uses this shorthand to describe the governance gap where identity exists operationally but not administratively. This is not a formal standards term, and usage in the industry is still evolving, but it maps closely to the visibility, lifecycle, and least-privilege expectations reflected in the NIST Cybersecurity Framework 2.0. The central issue is not whether the identity exists, but whether security teams can see it, prove who owns it, and revoke it when needed.
The most common misapplication is treating any account with low human interaction as harmless, which occurs when service and automation identities are created faster than governance can track them.
Examples and Use Cases
Implementing dark matter identity controls rigorously often introduces operational friction, requiring organisations to weigh faster deployment and automation against the cost of inventory, ownership, and rotation discipline.
- A CI/CD pipeline stores deploy tokens in scripts or environment files, so the credential works even though no approved identity record points to it. See NHI risk patterns in the Ultimate Guide to NHIs.
- An application creates local service users during installation, but those users never enter the enterprise IAM catalog or access review cycle.
- An AI agent uses an embedded API key to call external tools, yet the key is shared across systems and not tied to a named owner or lifecycle policy. The broader exposure pattern is visible in the JetBrains Marketplace AI Plugin Campaign.
- A legacy integration account keeps working after the application is retired, leaving an orphaned credential active in production.
- A third-party connector authenticates with a certificate that is renewed automatically, but the security team cannot trace where it is deployed or who approved it.
These cases often appear first in incident reviews, not in routine IAM dashboards. For a breach-driven view of the same problem space, NHI Management Group’s 52 NHI Breaches Analysis shows how hidden identities repeatedly become entry points.
Why It Matters in NHI Security
Dark matter identity matters because unseen credentials defeat governance by default. If an identity is absent from inventory, it cannot be meaningfully reviewed for privilege, rotation, offboarding, or revocation. That creates a direct path from shadow deployment to persistent access, especially in systems where secrets are copied into code, configs, or automation tools.
The risk is not theoretical. NHI Management Group reports that only 5.7% of organisations have full visibility into their service accounts, which means most environments are already operating with substantial identity blind spots. The same visibility gap undermines least privilege, incident response, and zero trust enforcement. It also explains why many teams discover exposure only after credentials are abused, leaked, or retained long after a service should have been decommissioned. Related control expectations appear across the NIST Cybersecurity Framework 2.0 and NHI governance guidance in the Ultimate Guide to NHIs.
Organisations typically encounter credential abuse, unauthorized tool access, or failed revocation only after an incident exposes the hidden account, at which point dark matter identity becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Covers hidden or unmanaged non-human identities that escape inventory and governance. |
| NIST CSF 2.0 | ID.AM-1 | Asset management includes identity-bearing systems and credentials that must be discoverable. |
| NIST Zero Trust (SP 800-207) | Zero Trust depends on continuously known and verified identities, including non-human ones. | |
| NIST SP 800-63 | AAL2 | Assurance concepts help assess whether non-human credentials are strong enough for their use. |
| OWASP Agentic AI Top 10 | A2 | Agentic systems create autonomous identities and tool access paths that can become invisible. |
Inventory every machine and agent identity, then require an owner, purpose, and lifecycle state before use.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on July 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org