Join our Newsletter — 33% off our NHI Course
Maturity Model · NHI & AI governance

NHI & AI Governance Maturity Model

Five levels, from Ad hoc to Optimised, for governing non-human identities and the AI agents that now use them. Find where you are, see what good looks like, and know what to fix first.

By Lalit Choda (Mr. NHI), NHI Mgmt Group · Updated 1 October 2026

The five levels

The Model at a Glance

Each level covers traditional non-human identities and, below the line, what changes with agentic AI.

  1. Level 1Ad hoc
    • Weak controls
    • No visibility
    • Stale accounts
    • Secrets hardcoded

    With agentic AI
    • Agents deployed unregistered
    • Running on developer credentials
    • Agent population unknown
    See Level 1
  2. Level 2Developing
    • Policies and standards
    • Partial inventory
    • Manual controls and hygiene
    • Ad-hoc audits

    With agentic AI
    • Sanctioned agents known
    • Shadow agents invisible
    • Agents not separated from other NHIs
    See Level 2
  3. Level 3Defined
    • Governance in place
    • Inventory and ownership
    • Secrets vaulting and scanning
    • CI/CD integration

    With agentic AI
    • Agent catalogue established
    • Ownership tied to application
    • Scope documented against purpose
    • Joiner, mover, leaver covers agents
    See Level 3
  4. Level 4Managed
    • Automated provisioning
    • Lifecycle management
    • Secrets secured and cycled
    • Monitoring controls

    With agentic AI
    • Behavioural baselining
    • Orphan agent detection
    • Recertification on model update
    See Level 4
  5. Level 5Optimised
    • Preventive controls
    • Dynamic JIT credentials
    • Policy based access
    • Integrated security

    With agentic AI
    • Authorisation at point of action
    • Credentials scoped to task
    • Multi-agent trust chain policy
    • Intelligent detection, remediation & automation
    See Level 5
Click or tap any level to see what it looks like
Why it matters

Why a Maturity Model

Non-human identities (service accounts, API keys, tokens, certificates and secrets) outnumber people in most organisations, often by 50–100x. AI agents now use those same credentials to act on their own, at machine speed. Governing them is not a single project but a journey.

The NHI & AI Governance Maturity Model gives that journey a shape: five levels, each describing what good looks like for traditional non-human identities and for AI agents. Use it to benchmark where you are, agree where you need to be, and prioritise the steps in between.

  • 21%of enterprises keep a real-time registry of their AI agents
  • 28%can reliably trace an AI agent’s actions
  • 84%doubt they could pass an audit of agent behaviour or access controls

Source: Cloud Security Alliance, survey of 285 enterprises, September–October 2025.

Level 1

Ad hoc

Weak controls, no visibility, unmanaged and stale accounts, secrets hardcoded into source.

Non-Human Identities

  • No inventory of non-human identities
  • Credentials embedded in source code
  • Stale, unmanaged accounts persist

AI Agents

  • Agents deployed without registration
  • Running on credentials inherited from proof-of-concept developers
  • Agent population unknown and ungoverned

To Reach Level 2

  • Build a first inventory of NHIs and AI agents
  • Find and remove secrets hardcoded in source code
  • Give every critical account and agent an owner
↑ Back to the model
Level 2

Developing

Policies and standards exist on paper, a partial inventory has been built, and controls and hygiene are manual. Audits are ad hoc rather than continuous.

Non-Human Identities

  • Written policies and standards in place
  • Partial inventory
  • Manual controls and hygiene
  • Ad hoc audits

AI Agents

  • Sanctioned agents roughly known; shadow agents invisible
  • Agents not separated from other NHIs in the inventory
  • Autonomous agents treated like batch-job service accounts

To Reach Level 3

  • Complete the inventory across every platform
  • Tie ownership to applications, not people
  • Deploy a secrets vault and scan pipelines for secrets
  • Create a mandatory agent catalogue
↑ Back to the model
Level 3

Defined

Governance is formally in place, inventory and ownership are established, secrets vaulting is deployed and scanning is integrated into CI/CD pipelines.

Non-Human Identities

  • Formal governance framework operating
  • Inventory with ownership tied to applications and services
  • Secrets vaulting deployed
  • Secrets scanning in CI/CD pipelines

AI Agents

  • Mandatory agent catalogue
  • Every agent registered with its scope and purpose
  • Joiner, mover, leaver processes extended to agents
  • Agents without an owner do not run

To Reach Level 4

  • Automate provisioning and decommissioning
  • Rotate secrets automatically
  • Switch on monitoring and orphan-agent detection
↑ Back to the model
Level 4

Managed

Provisioning and decommissioning are automated, lifecycle management is in place, secrets are secured and cycled without manual intervention, and monitoring controls are operational.

Non-Human Identities

  • Automated provisioning and decommissioning
  • Lifecycle management in place
  • Secrets rotated without manual intervention
  • Monitoring controls operational

AI Agents

  • Behaviour baselines replace static rules
  • Continuous detection of orphaned agents
  • Recertification triggered by model updates
  • New capabilities approved before reaching production

To Reach Level 5

  • Move to just-in-time, short-lived credentials
  • Make access policy-based and context-aware
  • Automate remediation of anomalies
↑ Back to the model
Level 5

Optimised

Preventive controls operate by default, dynamic just-in-time credentials replace static ones, access is policy-based and context-aware, and security is integrated rather than bolted on.

Non-Human Identities

  • Preventive controls on by default
  • Just-in-time credentials replace static secrets
  • Policy-based, context-aware access
  • Anomalies detected and remediated automatically

AI Agents

  • Authorisation checked at the moment of action
  • Credentials scoped to a single task
  • Trust-chain policy enforced at every agent handoff
  • Drift detected and credentials revoked automatically

To Stay at Level 5

  • Keep policies and baselines tuned as agents change
  • Test revocation and kill switches regularly
  • Reassess as new identity types and platforms appear
↑ Back to the model
Two dimensions

Maturity Is Rarely the Same Everywhere

Assess your level across both dimensions. You may be Managed for certificates in the cloud and Ad hoc for API keys on-premises.

Type of Identity

CertificatesAPI keysTokensSecretsDirectory service accountsWorkload identitiesAI agents

Platform

Public cloudOn-premisesDatabasesMainframeSaaSThird-party applications
Putting it to work

How to Use the Model

  1. Map Your MaturityScore each identity type on each platform. Maturity is rarely the same everywhere.
  2. Weight by ExposureConsider level of privilege, access to sensitive data and closeness to production.
  3. Fix the Worst FirstStart where privilege is highest and maturity lowest.
  4. Reassess RegularlyAI agents change faster than traditional NHIs, so revisit your levels often.
FAQ

Common Questions

What is the NHI & AI Governance Maturity Model?

A five-level framework by Lalit Choda (Mr. NHI) of NHI Mgmt Group for governing non-human identities and AI agents. The levels run from Ad hoc to Developing, Defined, Managed and Optimised, and each describes the controls in place for traditional NHIs and for AI agents.

Can we be at different levels in different areas?

Yes, and most organisations are. Assess maturity across two dimensions, type of identity and platform, then focus first where privilege is highest and maturity lowest.

Why does the model cover AI agents?

AI agents are non-human identities that make their own decisions. They inherit every NHI weakness and add new ones, so each level describes what governing agents looks like alongside traditional NHIs.

Where should we start?

With an inventory. A population of identities you cannot list stays at Level 1, whatever other controls you have.

How do we find our level?

Take the free NHI & AI Governance Maturity Assessment. It takes about five minutes and emails you a report with your level, your top risks and next steps.

Find Your Level in Five Minutes

Take the free NHI & AI Governance Maturity Assessment for your level, your top risks and a tailored report by email.

Take the model with you. All five levels, for NHIs and AI agents, in a two-page PDF.

Download the PDF

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.