Identity security maturity is uneven in most organisations. Workforce SSO may be excellent while service accounts go unmanaged; privileged access may be vaulted while AI agents run on developers' tokens. A single maturity model that covers every identity type helps leaders see where they are strong, where they are exposed and what to prioritise. This model spans workforce, privileged, customer, non-human and AI agent identities across eight capability areas and five levels. It complements our specialised Machine-to-Machine Identity Maturity Model and Agentic AI Identity Maturity Model.
Key takeaways
- Assess eight capability areas separately for each identity type: visibility, ownership and lifecycle, authentication, authorisation and privilege, governance, secrets and credentials, detection and response, and programme management.
- Your effective maturity is set by your weakest identity type, often non-human or AI agent identities.
- Use the model to prioritise and communicate, not to chase Level 5 everywhere.
The five levels
| Level | Name | Description |
|---|---|---|
| 1 | Initial | Ad hoc, manual, dependent on individuals; little visibility |
| 2 | Developing | Basic tools and policies exist for some identity types; significant gaps |
| 3 | Defined | Standard processes across identity types; inventory and ownership in place; key controls enforced |
| 4 | Managed | Automated, measured and risk-based; short-lived credentials and just-in-time privilege common |
| 5 | Optimised | Continuous, adaptive controls; unified visibility and detection; controls evidenced automatically |
Capability areas
| Area | Level 1 | Level 3 | Level 5 |
|---|---|---|---|
| Visibility | No reliable inventory | Inventory of human, non-human and agent identities with owners | Continuous, correlated identity graph across all systems |
| Ownership and lifecycle | Manual onboarding and offboarding; NHIs unowned | HR-driven JML; NHI and agent ownership and decommissioning processes | Fully automated lifecycle; ownership changes follow organisational change automatically |
| Authentication | Passwords; inconsistent MFA; static secrets for machines | MFA everywhere; phishing-resistant for admins; platform identity for many workloads | Phishing-resistant for all; secretless workloads; continuous session evaluation |
| Authorisation and privilege | Broad standing privilege | Least-privilege roles; JIT for admins; privileged NHIs reduced | Zero standing privilege; per-action, context-aware decisions for people, workloads and agents |
| Governance | Occasional, spreadsheet reviews | Regular, risk-based reviews including NHIs; SoD rules | Continuous, event-driven governance with automated remediation |
| Secrets and credentials | Secrets in code and configuration | Secrets centralised, scanned and rotated | Dynamic and short-lived credentials by default |
| Detection and response | Little identity-specific detection | ITDR for key identity systems; revocation playbooks | Correlated detection across all identity types; automated containment |
| Programme management | Separate projects, no owner | Identity programme with operating model, roadmap and metrics | Integrated with enterprise risk; outcome-based reporting to the board |
Levels 2 and 4 sit between the descriptions shown.
Assessing by identity type
Score each capability area for each identity type. A typical result might look like this:
| Capability | Workforce | Privileged | Customer | Non-human | AI agents |
|---|---|---|---|---|---|
| Visibility | 4 | 3 | 3 | 2 | 1 |
| Authentication | 3 | 3 | 3 | 2 | 1 |
| Authorisation and privilege | 3 | 3 | 3 | 2 | 1 |
This example is illustrative, not survey data. A pattern like it shows that investment in workforce identity will add little compared with bringing non-human and agent identity to Level 3.
Self-assessment questions
- Visibility: Can you list every identity, human and non-human, with access to your crown-jewel systems?
- Ownership: What percentage of service accounts, API keys and AI agents have a current owner?
- Authentication: How many administrators can still sign in with phishable methods? How many workloads use static secrets?
- Privilege: How many identities hold standing admin rights, and how many are non-human?
- Governance: Do access reviews remove access, and do they include NHIs and agents?
- Secrets: How many live secrets are outside approved managers?
- Detection: Would you detect a stolen session token or a service account used from a new host?
- Programme: Who is accountable for identity security across all identity types?
Using the results
- Identify the lowest-scoring identity types and capabilities that protect your most important systems.
- Set a realistic 12-month target, typically Level 3 across all identity types.
- Build the roadmap and business case. See the Programme Guide and Business Case Guide.
- Track progress with metrics. See the Metrics Guide.
- Reassess every six to twelve months.
How NHI Mgmt Group can help
We run independent identity, NHI and agentic AI maturity risk assessments and turn them into prioritised roadmaps and business cases. Contact us or see our services.
Related NHI Mgmt Group resources: Machine-to-Machine Identity Maturity Model · Agentic AI Identity Maturity Model · Identity Convergence Guide · The Ultimate Guide to NHIs