Step 2 of 5 · Non-human identity governance
How Do You Govern NHIs Today?
Answer for your estate as it really is — not as policy says it should be.
1 · Inventory & visibility Could you produce an inventory of your non-human identities today?
No — we could not produce one A partial list for some platforms, kept up manually An inventory across key platforms, with owners Yes — kept current automatically by discovery Real-time, continuously reconciled and risk-scored
2 · Ownership & accountability Does every non-human identity have an accountable owner?
No — most have no named owner Some are linked to individual people Every NHI is tied to an application or service with an accountable owner Ownership updates automatically when people move or leave Enforced by policy — no owner, no access
3 · Secrets management Where do your secrets, keys and tokens live?
Often hardcoded in code, config or scripts Some in a vault, many still in code, config or CI Vaulted, with secret scanning in CI/CD Vaulted, injected at runtime, scanned everywhere with automatic response Dynamic just-in-time credentials replace most static secrets
4 · Credential rotation How are NHI credentials rotated?
Rarely or never Manually, when someone remembers A defined rotation policy that is mostly followed Automated rotation without manual steps Short-lived credentials make rotation largely unnecessary
5 · Provisioning How are new non-human identities created?
Anyone creates them — no process A request process, handled manually Standard approvals and templates Automated through pipelines / infrastructure-as-code with policy checks Policy-as-code guardrails block non-compliant identities before they exist
6 · Offboarding & decommissioning What happens to NHIs when their creator leaves or the workload is retired?
They usually keep running Occasional manual clean-ups Joiner/mover/leaver process covers NHIs on owner change Automated decommissioning and stale-identity detection Unused access is revoked continuously and automatically
7 · Least privilege & access review How do you control and review what NHIs can access?
No reviews — broad privileges are common Occasional manual reviews Periodic recertification for privileged NHIs Automated right-sizing based on actual usage Policy-based, context-aware access evaluated at each request
8 · Monitoring & detection How do you detect misuse of non-human identities?
We don’t Logs exist and are reviewed after incidents Alerts on key events for important NHIs Behaviour monitoring with baselines and response playbooks Intelligent detection with automated remediation
9 · Policy & governance How mature are your NHI policies and standards?
None specific to NHIs Policies exist on paper Policies enforced on key platforms Enforced and measured across the estate Built into engineering — secure by default
10 · Audit & assurance How are NHI controls audited?
Never audited Ad-hoc audits Scheduled audits against policy Continuous control monitoring Preventive controls with automated evidence
11 · Third-party, OAuth & SaaS How do you govern OAuth grants, SaaS integrations and third-party access?
We don’t know what is connected A partial list An inventory with owners and reviewed scopes Automated discovery and revocation of unused grants Policy controls at the point of consent
12 · Coverage across platforms How consistent are your NHI controls across cloud, on-premises, databases/mainframe and SaaS?
Controls exist in one area at most Mostly in public cloud; elsewhere is unknown Defined for the main platforms, gaps elsewhere Consistent and automated across most platforms Consistent everywhere, including SaaS and third-party