Identity security programmes are often measured by activity: number of applications onboarded, reviews completed, tickets closed. Those numbers show effort, not risk reduction. Leadership needs to know whether the organisation is harder to breach through identity than it was last quarter, and teams need metrics that point to where to act next. This guide sets out a practical set of identity security metrics and KPIs covering human, non-human and AI agent identities, how to calculate them and how to report them.
Key takeaways
- Prefer outcome metrics (privileged access removed, credentials made short-lived, time to deprovision) over activity metrics.
- Track coverage (how much of the estate a control reaches) and exposure (how much risk remains).
- Include non-human identities and AI agents; they are often the largest and least measured population.
- Report a small set of headline metrics to leadership, with trends, targets and owners.
Principles for good identity metrics
- Risk-linked: each metric connects to a way attackers get in or move.
- Measurable from data: calculated from systems, not surveys.
- Actionable: a change in the metric points to a specific team or action.
- Trended: shown over time against a target.
- Segmented: broken down by business unit, platform or identity type to find where to act.
Metrics by area
Authentication
- Percentage of workforce users with MFA enforced.
- Percentage of administrators using phishing-resistant MFA (target: 100%).
- Percentage of all users with phishing-resistant authenticators registered.
- Number of accounts able to use legacy authentication.
Privileged access
- Number of standing privileged assignments (trend down), split by human and NHI.
- Percentage of privileged access granted just in time.
- Number of tier-zero administrators.
- Percentage of privileged sessions brokered and recorded.
Lifecycle and governance
- Median and 95th-percentile time from HR leave date to full deprovisioning.
- Number of active accounts belonging to leavers found in reconciliation.
- Percentage of access removed in review campaigns (a healthy campaign removes something).
- Percentage of applications covered by automated provisioning and reviews.
- Number of open segregation of duties conflicts without mitigation.
Non-human identities
- Total NHIs discovered, by type and platform.
- Percentage of NHIs with a valid, current owner. See the NHI Ownership Guide.
- Percentage of NHI credentials that are short-lived or platform-issued rather than static.
- Number of static secrets older than the rotation policy.
- Number of live secrets found outside secrets managers, and median time to remediate.
- Number of NHIs with administrative or wildcard permissions.
- Number of third-party OAuth apps with high-risk scopes.
AI agents
- Number of agents discovered versus registered.
- Percentage of agents running on their own identity (not human or shared credentials).
- Percentage of agents with a named owner.
- Number of agents with administrative access.
- Percentage of high-impact agent actions covered by enforced approval.
- Tested time to stop an agent and revoke its access.
Detection and response
- Mean time to detect and contain identity-based incidents.
- Percentage of identity systems sending logs to detection tooling.
- Number of high-severity identity posture findings open beyond target.
A headline dashboard for leadership
| Metric | Why it matters | Example target |
|---|---|---|
| Admins with phishing-resistant MFA | Blocks the most common takeover route for privileged accounts | 100% |
| Standing privileged assignments | Shrinks the attack window | Downward trend each quarter |
| Time to deprovision leavers | Closes insider and orphaned access risk | Same day for privileged users |
| NHIs with a valid owner | Enables every other NHI control | Above 90%, 100% for privileged |
| Static credentials remaining | Measures progress to short-lived secrets | Downward trend |
| AI agents registered with own identity | Measures control of the newest identity type | 100% of production agents |
| Open high-severity identity findings | Shows remaining exposure | Downward trend; none past deadline |
Targets are examples; set your own based on risk appetite and baseline.
Reporting tips
- Show trends, not snapshots; explain movements.
- Pair each metric with an owner and next action.
- Translate to business impact where possible, for example "privileged accounts exposed to phishing reduced from 120 to 12".
- Avoid vanity metrics such as number of policies written.
Practitioner checklist
- Select metrics across authentication, privilege, lifecycle, NHI, AI agents and detection.
- Automate data collection from identity systems.
- Baseline, set targets and assign owners.
- Report a small headline set to leadership with trends.
- Review metrics annually as the programme matures.
Standards and references
- NIST Cybersecurity Framework 2.0
- NIST SP 800-55: Measurement Guide for Information Security
- CIS Controls v8
Related NHI Mgmt Group resources: Identity Security Programme Guide · Business Case Guide · Board and CISO Briefing · Identity Security Maturity Model