An unconference is a meeting format where participants shape the agenda during the event rather than following a fixed programme. Attendees propose topics, lead discussions, and steer the conversation in real time. This format is useful for collaboration, peer learning, and surfacing practical issues that do not fit a standard presentation structure.
Expanded Definition
An unconference is a participant-driven meeting format that replaces a fixed agenda with topics proposed and refined by attendees during the event. In NHI and IAM contexts, the format is especially useful when teams need rapid cross-functional input on issues like secret sprawl, service account ownership, or agent approval workflows that are still evolving across the organisation.
Definitions vary across vendors and event communities, but the core idea remains the same: discussion topics are selected in real time, and participants help determine which conversations matter most. That makes an unconference different from a workshop, which usually has a facilitator-controlled structure, and from a conference track, which is scheduled in advance. For governance-heavy topics, this flexibility can surface operational friction that would otherwise be missed in polished presentations.
For organisations using NIST Cybersecurity Framework 2.0, the unconference format can support discovery, risk framing, and cross-team alignment when formal controls are not yet fully mature. The most common misapplication is treating an unconference like an unmoderated brainstorming session, which occurs when no one sets topic boundaries, decision rules, or capture methods.
Examples and Use Cases
Implementing an unconference rigorously often introduces facilitation overhead and outcome ambiguity, requiring organisations to weigh breadth of participation against the need for clear decisions and documented follow-up.
- An IAM team runs an unconference to gather pain points on service account ownership, then uses the session to identify where approvals, rotation, and revocation processes are breaking down.
- A product security group uses an unconference to compare approaches to agent tool access, allowing engineers and governance leads to surface practical constraints before policy language is finalised.
- A cross-functional NHI review session uses a topic board to prioritise discussions on secrets management, vault misconfiguration, and offboarding gaps, instead of presenting a fixed slide deck.
- A security community event applies the format to compare operational lessons learned from API key leaks and third-party exposure, drawing on the Ultimate Guide to NHIs as a shared reference point.
- A governance workshop uses the unconference model to debate whether proposed controls align better with the NIST Cybersecurity Framework 2.0 than with a purely policy-first operating model.
Why It Matters in NHI Security
Unconference-style sessions matter because NHI security failures are often rooted in fragmented ownership, hidden dependencies, and weak operational visibility rather than a single policy gap. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, which means many teams are already making decisions with incomplete context. An unconference can help expose those blind spots faster than a formal presentation format, especially when teams need to compare real-world practices across engineering, identity, and security operations.
This format is also valuable when discussing problems that cross control boundaries, such as secrets stored outside approved systems, delayed revocation, or inconsistent third-party access. The Ultimate Guide to NHIs notes that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which reinforces how often the operational failure is discovered only after impact. By the time teams are responding to a leak, access review backlog, or service outage, the need for candid discussion becomes immediate. Organisations typically encounter the need for this format only after a security incident or audit failure exposes who really owns the problem, at which point unconference-style coordination becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.1 | Supports governance discussions that clarify roles, risk, and decision ownership. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Relevant where unconference topics expose visibility and inventory weaknesses. |
| NIST Zero Trust (SP 800-207) | GC.PO-01 | Zero Trust adoption depends on practical alignment across identity, access, and policy decisions. |
| NIST AI RMF | Unconference sessions can support shared understanding of AI and agent risk tradeoffs. | |
| CSA MAESTRO | Agentic AI governance often needs open discussion across security, platform, and product teams. |
Use the format to align stakeholders on tool access, oversight, and operational boundaries for agents.
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org