Join our Newsletter — 33% off our NHI Course
Home› Guides› Identity Security Metrics and KPIs Guide
Guide Governance, Risk & Compliance

Identity Security Metrics and KPIs Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 4 min read
On this page

Identity security programmes are often measured by activity: number of applications onboarded, reviews completed, tickets closed. Those numbers show effort, not risk reduction. Leadership needs to know whether the organisation is harder to breach through identity than it was last quarter, and teams need metrics that point to where to act next. This guide sets out a practical set of identity security metrics and KPIs covering human, non-human and AI agent identities, how to calculate them and how to report them.

Key takeaways

  • Prefer outcome metrics (privileged access removed, credentials made short-lived, time to deprovision) over activity metrics.
  • Track coverage (how much of the estate a control reaches) and exposure (how much risk remains).
  • Include non-human identities and AI agents; they are often the largest and least measured population.
  • Report a small set of headline metrics to leadership, with trends, targets and owners.

Principles for good identity metrics

  • Risk-linked: each metric connects to a way attackers get in or move.
  • Measurable from data: calculated from systems, not surveys.
  • Actionable: a change in the metric points to a specific team or action.
  • Trended: shown over time against a target.
  • Segmented: broken down by business unit, platform or identity type to find where to act.

Metrics by area

Authentication

  • Percentage of workforce users with MFA enforced.
  • Percentage of administrators using phishing-resistant MFA (target: 100%).
  • Percentage of all users with phishing-resistant authenticators registered.
  • Number of accounts able to use legacy authentication.

Privileged access

  • Number of standing privileged assignments (trend down), split by human and NHI.
  • Percentage of privileged access granted just in time.
  • Number of tier-zero administrators.
  • Percentage of privileged sessions brokered and recorded.

Lifecycle and governance

  • Median and 95th-percentile time from HR leave date to full deprovisioning.
  • Number of active accounts belonging to leavers found in reconciliation.
  • Percentage of access removed in review campaigns (a healthy campaign removes something).
  • Percentage of applications covered by automated provisioning and reviews.
  • Number of open segregation of duties conflicts without mitigation.

Non-human identities

  • Total NHIs discovered, by type and platform.
  • Percentage of NHIs with a valid, current owner. See the NHI Ownership Guide.
  • Percentage of NHI credentials that are short-lived or platform-issued rather than static.
  • Number of static secrets older than the rotation policy.
  • Number of live secrets found outside secrets managers, and median time to remediate.
  • Number of NHIs with administrative or wildcard permissions.
  • Number of third-party OAuth apps with high-risk scopes.

AI agents

  • Number of agents discovered versus registered.
  • Percentage of agents running on their own identity (not human or shared credentials).
  • Percentage of agents with a named owner.
  • Number of agents with administrative access.
  • Percentage of high-impact agent actions covered by enforced approval.
  • Tested time to stop an agent and revoke its access.

Detection and response

  • Mean time to detect and contain identity-based incidents.
  • Percentage of identity systems sending logs to detection tooling.
  • Number of high-severity identity posture findings open beyond target.

A headline dashboard for leadership

MetricWhy it mattersExample target
Admins with phishing-resistant MFABlocks the most common takeover route for privileged accounts100%
Standing privileged assignmentsShrinks the attack windowDownward trend each quarter
Time to deprovision leaversCloses insider and orphaned access riskSame day for privileged users
NHIs with a valid ownerEnables every other NHI controlAbove 90%, 100% for privileged
Static credentials remainingMeasures progress to short-lived secretsDownward trend
AI agents registered with own identityMeasures control of the newest identity type100% of production agents
Open high-severity identity findingsShows remaining exposureDownward trend; none past deadline

Targets are examples; set your own based on risk appetite and baseline.

Reporting tips

  • Show trends, not snapshots; explain movements.
  • Pair each metric with an owner and next action.
  • Translate to business impact where possible, for example "privileged accounts exposed to phishing reduced from 120 to 12".
  • Avoid vanity metrics such as number of policies written.

Practitioner checklist

  • Select metrics across authentication, privilege, lifecycle, NHI, AI agents and detection.
  • Automate data collection from identity systems.
  • Baseline, set targets and assign owners.
  • Report a small headline set to leadership with trends.
  • Review metrics annually as the programme matures.

Standards and references

Related NHI Mgmt Group resources: Identity Security Programme Guide · Business Case Guide · Board and CISO Briefing · Identity Security Maturity Model

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org