Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Monthly Active Principals
Governance, Ownership & Risk

Monthly Active Principals

← Back to Glossary
By NHI Mgmt Group Updated August 28, 2026 Domain: Governance, Ownership & Risk

Monthly Active Principals are the unique identities that triggered authorization decisions during a month. The metric helps teams understand who or what is using the authorization layer, how demand is changing, and whether capacity or policy scope needs review. It is a usage measure, not an access entitlement measure.

Expanded Definition

Monthly Active Principals is a usage metric for the identity and authorization plane: it counts the unique principals that caused at least one authorization decision during a month. In NHI operations, a principal may be a service account, workload identity, API client, bot, or AI agent, so the metric is about observed decision traffic rather than granted permissions. That distinction matters because a principal can be active without being broadly entitled, and it can also be over-entitled while appearing lightly used. NIST guidance on access control and auditability, including NIST SP 800-53 Rev 5 Security and Privacy Controls, is relevant because the metric becomes meaningful when paired with logging, review, and least-privilege enforcement. Industry usage is still evolving, and definitions vary across vendors on whether refresh-token activity, denied checks, or machine-to-machine policy evaluations count as “active.” The most common misapplication is treating Monthly Active Principals as a proxy for entitlement scope, which occurs when teams confuse observed usage with approved access.

Examples and Use Cases

Implementing Monthly Active Principals rigorously often introduces measurement overhead, because teams must normalize identity logs across applications, brokers, and policy engines while deciding exactly what qualifies as a decision event.

  • A platform team tracks month-over-month growth in service accounts that actually hit the authorization layer, then compares that to the number of provisioned accounts to detect dormant identity sprawl.
  • A security team sees a sharp rise in active workload principals after a deployment wave and checks whether the increase reflects legitimate scaling or duplicated identities created by poor automation.
  • An IAM lead uses the metric alongside Ultimate Guide to NHIs to frame lifecycle controls for newly active API keys and service accounts that should be reviewed for rotation and offboarding.
  • A governance team correlates monthly active principals with policy-change tickets to determine whether authorization drift is being driven by new integrations or by uncontrolled access expansion.
  • An auditor uses the metric to distinguish a small set of high-frequency machine identities from a much larger population of provisioned but unused principals, then validates the sampling approach against NIST SP 800-53 Rev 5 Security and Privacy Controls.

Why It Matters in NHI Security

Monthly Active Principals matters because NHI programs often fail when teams cannot see which identities are actually exercising access. NHI Management Group reports that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs, which means active-principal tracking is often the first dependable signal that identity inventory, entitlement review, or authorization scope has drifted out of control. Used well, the metric helps reveal hidden growth in machine-to-machine traffic, redundant principals, and stale access paths that can later become breach conduits. It also complements broader governance expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls by giving reviewers a concrete monthly baseline for review, anomaly detection, and remediation prioritization. Organisations typically encounter the real cost of this metric only after an incident response or audit reveals that “inactive” identities were still callable, at which point Monthly Active Principals becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Active principals often reveal NHI inventory gaps and unmanaged identities.
NIST CSF 2.0DE.CMContinuous monitoring depends on knowing which principals are active.
NIST SP 800-63Identity assurance concepts help classify machine principals by trust level.
NIST Zero Trust (SP 800-207)AC-4Zero Trust policy evaluation creates the authorization events this metric counts.

Instrument policy enforcement points so active principals reflect real authorization decisions.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on August 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org