Join our Newsletter — 33% off our NHI Course
Home Glossary Agentic AI & Autonomous Identity Relationship Score
Agentic AI & Autonomous Identity

Relationship Score

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Agentic AI & Autonomous Identity

A relationship score is a derived signal that estimates the strength of a person’s connection to another contact or account. It can help teams decide who should make an introduction without revealing the underlying conversation. Used carefully, it supports collaboration while preserving the confidentiality of the original source data.

Expanded Definition

A relationship score is a derived signal used to estimate the strength of one identity’s connection to another contact or account, often by combining interaction frequency, recency, trust context, and directional influence. In NHI and agentic systems, the score is best understood as a decision aid, not as proof of identity, authority, or consent. Its value depends on how the underlying data is sourced, whether it is privacy-preserving, and whether it is used to rank introductions rather than to infer hidden content. This distinction matters because relationship scoring sits near both collaboration analytics and identity governance, so definitions vary across vendors and no single standard governs this yet. For governance purposes, it should be treated as a derived attribute that must be explainable, access-controlled, and limited to the purpose for which it was calculated. That framing aligns with the control intent behind the NIST Cybersecurity Framework 2.0 and the broader confidentiality expectations in NHI programs. The most common misapplication is treating a high score as permission to disclose source relationships, which occurs when analytics teams expose the score beyond its intended workflow.

Examples and Use Cases

Implementing relationship scoring rigorously often introduces a privacy and explainability tradeoff, requiring organisations to weigh better routing decisions against tighter limits on what the model can reveal.

  • A sales platform ranks which colleague should receive a customer introduction, using relationship score to suggest the most relevant connector while keeping the original thread private.
  • A support system uses the score to identify a likely internal owner for a service request, reducing handoff time without exposing historic message content.
  • An NHI governance workflow uses derived relationship signals to flag unusual service-account dependencies, then validates them against the practices described in the Ultimate Guide to NHIs.
  • A directory-integrated collaboration tool applies the score only to metadata and not to message bodies, limiting exposure while still improving introduction recommendations.
  • An AI agent uses relationship score to select a human approver for a sensitive action, but the final approval path still follows documented access policy and review criteria.

Why It Matters in NHI Security

Relationship score becomes important in NHI security when derived signals start influencing access, routing, delegation, or escalation decisions. If the score is opaque, over-shared, or reused outside its original context, it can leak sensitive collaboration patterns and create a false sense of trust around identities that should still be verified independently. That risk is especially relevant where service accounts, API keys, and agentic workflows intersect with human approval paths. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, which means many teams are already operating with incomplete identity context while relying on secondary signals to make decisions. In practice, this makes relationship scoring useful only when paired with least privilege, purpose limitation, and strict access boundaries, consistent with the NIST Cybersecurity Framework 2.0 and the governance lessons in the Ultimate Guide to NHIs. Organisations typically encounter misuse after a sensitive introduction, escalation, or agent action has already exposed the wrong relationship path, at which point relationship score becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-06Derived relationship signals can expose sensitive NHI context if over-shared or weakly governed.
NIST CSF 2.0PR.AC-4Relationship scores influence access and routing decisions tied to least privilege.
NIST Zero Trust (SP 800-207)3.1Zero Trust requires explicit verification, not trust inferred from social or system relationships.
NIST AI RMFMAPRelationship scoring is an AI-derived signal that needs purpose, context, and risk mapping.
OWASP Agentic AI Top 10AGENT-04Agentic workflows may use relationship scores to choose approvers or contacts.

Limit who can access relationship-derived signals and verify they are not reused beyond their approved purpose.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org