Identity-centred governance is an approach that uses identity systems as the source of context for access decisions across cloud and enterprise environments. It connects attributes, groups, roles, approvals, and reporting so security teams can understand how access was granted and whether it should remain in place.
Expanded Definition
Identity-centred governance treats identity records as the control plane for access, accountability, and review. Rather than relying on scattered entitlement lists or application-by-application approvals, it uses attributes, groups, roles, workflows, and reporting to explain why a human or NHI has access and whether that access still fits the business need. For NHI security, that means service accounts, API keys, OAuth apps, and machine identities are governed through the same evidence chain as human access, with stronger emphasis on ownership and lifecycle state.
Definitions vary across vendors because some platforms describe this as identity governance and administration, while others frame it as access governance, entitlement governance, or identity-first security. The practical distinction is not the label but the source of truth: governance begins with identity context and uses it to drive review, approval, and removal decisions. That aligns well with the NIST Cybersecurity Framework 2.0, which emphasizes identity management and access control as core risk-reduction functions, and with NHIMG guidance on lifecycle management in the Ultimate Guide to NHIs - Lifecycle Processes for Managing NHIs.
The most common misapplication is assuming a directory sync or role catalog is governance, which occurs when teams record identities but never verify who approved the access or whether the NHI still requires it.
Examples and Use Cases
Implementing identity-centred governance rigorously often introduces process overhead, requiring organisations to weigh faster access provisioning against stronger reviewability and tighter control over standing access.
- A cloud platform team assigns every deployment service account an owner, a purpose, and a review cadence so access recertification can remove dormant NHIs before they drift into sprawl.
- A security team uses role and group membership to explain why an API integration can read production data, then revokes the entitlement when the project ends.
- An enterprise pairs approval logs with identity attributes to prove that a machine identity inherited only the permissions required for a vendor OAuth connection, a concern highlighted in The State of Non-Human Identity Security.
- A governance program reviews privileged NHI accounts against the least-privilege concepts in the NIST Cybersecurity Framework 2.0 and removes access that lacks an approver or current business justification.
- Security operations use the 52 NHI Breaches Analysis to map common failure patterns back to missing ownership, poor visibility, and stale entitlements.
Why It Matters in NHI Security
Identity-centred governance matters because most NHI failures are not caused by a single broken control. They emerge when access is created quickly, inherited broadly, and then forgotten. The result is blind privilege, weak accountability, and approvals that cannot be traced back to a current business need. In the NHI domain, that weakness is especially dangerous because secrets, tokens, and certificates can outlive the project or workflow that created them.
NHIMG research shows that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and 47% only partial visibility, a direct warning sign for governance programs that cannot connect identity context to access exposure. That is why the Top 10 NHI Issues and the Ultimate Guide to NHIs - Regulatory and Audit Perspectives both emphasize ownership, auditability, and continuous review as practical governance requirements, not optional hygiene.
Organisations typically encounter the consequences only after a compromised token, an over-privileged integration, or a failed audit reveals that no one can justify why the identity still had access, at which point identity-centred governance becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity governance depends on clear ownership and lifecycle control for NHIs. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions should be managed and reviewed using identity context. |
| NIST Zero Trust (SP 800-207) | N/A | Zero Trust requires identity-centric access decisions based on current context. |
| NIST SP 800-63 | IAL2 | Identity proofing concepts inform how identity records are trusted and maintained. |
| OWASP Agentic AI Top 10 | A1 | Agentic systems need governed identity, authorization, and accountability. |
Assign owners, review cadence, and retirement criteria to every NHI and enforce them continuously.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org