Join our Newsletter — 33% off our NHI Course
Home› Guides› Identity Security Maturity Model
Maturity Model Governance, Risk & Compliance

Identity Security Maturity Model

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 4 min read
On this page

Identity security maturity is uneven in most organisations. Workforce SSO may be excellent while service accounts go unmanaged; privileged access may be vaulted while AI agents run on developers' tokens. A single maturity model that covers every identity type helps leaders see where they are strong, where they are exposed and what to prioritise. This model spans workforce, privileged, customer, non-human and AI agent identities across eight capability areas and five levels. It complements our specialised Machine-to-Machine Identity Maturity Model and Agentic AI Identity Maturity Model.

Key takeaways

  • Assess eight capability areas separately for each identity type: visibility, ownership and lifecycle, authentication, authorisation and privilege, governance, secrets and credentials, detection and response, and programme management.
  • Your effective maturity is set by your weakest identity type, often non-human or AI agent identities.
  • Use the model to prioritise and communicate, not to chase Level 5 everywhere.

The five levels

LevelNameDescription
1InitialAd hoc, manual, dependent on individuals; little visibility
2DevelopingBasic tools and policies exist for some identity types; significant gaps
3DefinedStandard processes across identity types; inventory and ownership in place; key controls enforced
4ManagedAutomated, measured and risk-based; short-lived credentials and just-in-time privilege common
5OptimisedContinuous, adaptive controls; unified visibility and detection; controls evidenced automatically

Capability areas

AreaLevel 1Level 3Level 5
VisibilityNo reliable inventoryInventory of human, non-human and agent identities with ownersContinuous, correlated identity graph across all systems
Ownership and lifecycleManual onboarding and offboarding; NHIs unownedHR-driven JML; NHI and agent ownership and decommissioning processesFully automated lifecycle; ownership changes follow organisational change automatically
AuthenticationPasswords; inconsistent MFA; static secrets for machinesMFA everywhere; phishing-resistant for admins; platform identity for many workloadsPhishing-resistant for all; secretless workloads; continuous session evaluation
Authorisation and privilegeBroad standing privilegeLeast-privilege roles; JIT for admins; privileged NHIs reducedZero standing privilege; per-action, context-aware decisions for people, workloads and agents
GovernanceOccasional, spreadsheet reviewsRegular, risk-based reviews including NHIs; SoD rulesContinuous, event-driven governance with automated remediation
Secrets and credentialsSecrets in code and configurationSecrets centralised, scanned and rotatedDynamic and short-lived credentials by default
Detection and responseLittle identity-specific detectionITDR for key identity systems; revocation playbooksCorrelated detection across all identity types; automated containment
Programme managementSeparate projects, no ownerIdentity programme with operating model, roadmap and metricsIntegrated with enterprise risk; outcome-based reporting to the board

Levels 2 and 4 sit between the descriptions shown.

Assessing by identity type

Score each capability area for each identity type. A typical result might look like this:

CapabilityWorkforcePrivilegedCustomerNon-humanAI agents
Visibility43321
Authentication33321
Authorisation and privilege33321

This example is illustrative, not survey data. A pattern like it shows that investment in workforce identity will add little compared with bringing non-human and agent identity to Level 3.

Self-assessment questions

  • Visibility: Can you list every identity, human and non-human, with access to your crown-jewel systems?
  • Ownership: What percentage of service accounts, API keys and AI agents have a current owner?
  • Authentication: How many administrators can still sign in with phishable methods? How many workloads use static secrets?
  • Privilege: How many identities hold standing admin rights, and how many are non-human?
  • Governance: Do access reviews remove access, and do they include NHIs and agents?
  • Secrets: How many live secrets are outside approved managers?
  • Detection: Would you detect a stolen session token or a service account used from a new host?
  • Programme: Who is accountable for identity security across all identity types?

Using the results

  1. Identify the lowest-scoring identity types and capabilities that protect your most important systems.
  2. Set a realistic 12-month target, typically Level 3 across all identity types.
  3. Build the roadmap and business case. See the Programme Guide and Business Case Guide.
  4. Track progress with metrics. See the Metrics Guide.
  5. Reassess every six to twelve months.

How NHI Mgmt Group can help

We run independent identity, NHI and agentic AI maturity risk assessments and turn them into prioritised roadmaps and business cases. Contact us or see our services.

Related NHI Mgmt Group resources: Machine-to-Machine Identity Maturity Model · Agentic AI Identity Maturity Model · Identity Convergence Guide · The Ultimate Guide to NHIs

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org