Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Identity Plumbing
Governance, Ownership & Risk

Identity Plumbing

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Governance, Ownership & Risk

The underlying access, scoping, logging, and lifecycle machinery that makes identities usable in production. In AI programmes, weak plumbing shows up as manual approvals, shared accounts, and unclear revocation paths rather than as a model problem.

What Identity Plumbing Actually Covers

Identity plumbing is the operational machinery behind usable production identities, the part that makes access consistent, traceable, and revocable. It includes scoping, lifecycle handling, logging, ownership, and the connective tissue between policy and execution.

It is not a model attribute or a single control. It is the set of working parts that turns identity decisions into dependable runtime behaviour, including how permissions are granted, how changes propagate, and how revocation is actually enforced.

Why Identity Plumbing Matters in Real Systems

When the plumbing is sound, teams can answer basic questions quickly: who has access, why they have it, when it was approved, and how it will be removed. The Identity Security Programme Guide is useful here because this work only becomes durable when scope, ownership, and operating model are explicit.

Poor plumbing often shows up as drift between policy and reality, especially in AI programmes where manual approvals, shared accounts, and unclear revocation paths create hidden operational debt. That is why the Ultimate Guide to NHIs is relevant as a reference point for the broader identity machinery that underpins production use.

Core Building Blocks of Identity Plumbing

Good identity plumbing usually has four parts working together: provisioning and change control, scoping and authorization logic, logging and auditability, and deprovisioning or revocation paths. If any one of these is weak, the identity may still exist on paper, but it will not behave safely in production.

That is why lifecycle management matters so much. NHI Lifecycle Management Guide maps well to the underlying need for creation, rotation, visibility, and offboarding, while Top 10 NHI Issues highlights the common failure modes that appear when lifecycle and governance are treated as afterthoughts.

In modern platforms, plumbing also includes the identity substrate itself, such as workload, service, or application authentication paths. External standards like NIST SP 800-63 Digital Identity Guidelines and the SPIFFE workload identity specification show how identity assurance and workload identity can be made more deterministic.

How Weak Identity Plumbing Fails

Weak plumbing rarely fails in a dramatic single event. More often it creates a slow accumulation of risk: access that outlives its purpose, logs that cannot support investigation, approval chains that no longer reflect reality, and privileges that are hard to unwind once embedded in processes.

For AI and automation environments, that failure is especially visible when human operators are forced to manage identity manually or when identities are reused across systems. The OWASP Non-Human Identity Top 10 captures the same structural weaknesses from a security perspective, especially overprivilege, secret leakage, and lifecycle gaps.

Good logging is part of the plumbing, not a bolt-on. Without it, teams cannot tell whether access was exercised legitimately, whether a rotation took effect, or whether an offboarding action left behind hidden exposure.

Risk and Threat Considerations

Identity plumbing creates real security exposure when access paths are unclear, shared, or difficult to revoke. In practice, that can turn ordinary operational shortcuts into persistent privilege, weak auditability, and lateral movement opportunities.

Failure mechanism: Manual approvals, stale entitlements, shared credentials, and fragmented ownership make it easy for access to outlive its intended purpose or to be reused in ways no one can trace cleanly.

Impact: Attackers and insiders can abuse durable access paths, while defenders lose the ability to prove who had access, when it changed, and whether revocation actually succeeded.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 provides the primary governance reference for this term.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers credential lifecycle, rotation, and revocation that underpin identity plumbing.
IA-2 — Identification and Authentication (Organizational Users)Identity plumbing depends on reliable authentication for users operating the production system.
AC-2 — Account ManagementIdentity plumbing includes provisioning, review, and deprovisioning of accounts and access.
Recommendation — Enforce IA-5 to manage issuance, rotation, and revocation of credentials and tokens. Apply IA-2 to ensure organizational users are uniquely identified and authenticated. Use AC-2 to govern account creation, review, and timely removal of access.

Practitioner Guidance

Why practitioners should care: Identity plumbing is where governance becomes real. If provisioning, scoping, logging, and offboarding are not operationalised, identity policy may exist but still fail at the point of use.

What to watch for: Pay close attention to shared accounts, delayed revocation, inconsistent approval paths, and identity records that do not match runtime access. Those are usually signals that the plumbing, not the policy language, is the problem.

Practitioner takeaway: Treat identity plumbing as production infrastructure. If it cannot be observed, revoked, and audited reliably, it is not ready to support high-trust workloads.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org