Join our Newsletter — 33% off our NHI Course
Home› Guides› NHI Governance Maturity Model
Maturity Model Non-Human Identity (NHI)

NHI Governance Maturity Model

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 7 min read
On this page

Most organisations know they have a non-human identity problem; far fewer can say how mature their NHI governance actually is, or what to do next. Service accounts, API keys, tokens, certificates, workload identities and now AI agents outnumber people in almost every environment, and they are created by developers, pipelines and SaaS integrations far faster than any central team can track. This five-level NHI Governance Maturity Model, developed by NHI Mgmt Group, describes how NHI governance progresses from Ad hoc to Optimised across eight dimensions. Use it to assess where you are, agree a realistic target and build a roadmap that reduces risk at each step.

Key takeaways

  • The five levels are Ad hoc, Developing, Defined, Managed and Optimised.
  • Maturity is assessed across eight dimensions: inventory and discovery, ownership, credential management, access and privilege, lifecycle, monitoring and response, AI agents, and governance and metrics.
  • Most organisations start at Level 1 or 2. Level 3 (Defined) is a sensible first target: known, owned NHIs with defined processes.
  • Progress is uneven. Score each dimension separately and fix the weakest high-risk dimension first.
  • Maturity should show up in measurable outcomes: fewer long-lived secrets, fewer orphaned NHIs, faster revocation.

The five levels

LevelNameWhat it looks like
1Ad hocNHIs are created by whoever needs them, with no inventory, no owners and secrets scattered across code, config and chat. Problems are found through incidents.
2DevelopingThe problem is recognised. Some discovery and secrets scanning is in place, a vault exists for part of the estate, and a few high-risk NHIs have owners. Coverage is patchy and manual.
3DefinedPolicy and standards exist for creating, owning, storing, rotating and retiring NHIs. There is an inventory across the main platforms, every NHI in scope has an owner, and new NHIs follow a defined process.
4ManagedProcesses are automated and measured. Short-lived and federated credentials are the default, least privilege is enforced and reviewed, NHI behaviour is monitored, and metrics drive decisions.
5OptimisedNHI governance is continuous and largely secretless. Credentials are ephemeral, access is granted just in time and per task, anomalies trigger automated response, and AI agents are governed as first-class identities.

The eight dimensions

DimensionLevel 1 Ad hocLevel 3 DefinedLevel 5 Optimised
Inventory and discoveryNo inventoryInventory across main clouds, directories, SaaS and code, refreshed regularlyContinuous discovery across all sources, including shadow AI and third-party NHIs
Ownership and accountabilityNo ownersEvery in-scope NHI has a named human owner and a purposeOwnership assigned at creation and transferred automatically with team changes
Credential managementSecrets in code and configSecrets vaulted, scanning in place, rotation definedSecretless by default: federation, workload identity and ephemeral credentials
Access and privilegeBroad, standing permissionsLeast privilege standards; privileged NHIs identified and restrictedJust-in-time, task-scoped access with continuous right-sizing
LifecycleNHIs never retiredDefined create, rotate and decommission process; stale NHIs removedLifecycle fully automated and tied to workload and application lifecycle
Monitoring and responseNo NHI-specific monitoringNHI activity logged; leak response playbook in placeBehavioural baselines with automated containment and revocation
AI agentsAgents use shared keys or borrowed user credentialsAgents registered, owned and given their own identitiesAgents receive delegated, per-task access with human approval for high-impact actions
Governance and metricsNo policy or reportingNHI policy approved; basic metrics reportedRisk-based metrics drive investment and are reported to the board

Self-assessment questions

For each dimension, score the level that best describes you today. Be honest: a control that exists on paper but covers a fraction of the estate is Level 2, not Level 3.

  • Inventory: could you list every service account, API key and OAuth app with access to your most critical system within a day?
  • Ownership: what share of your NHIs has a named, current owner?
  • Credentials: how many long-lived static secrets are in use, and how many are older than a year?
  • Access: how many NHIs hold administrator or owner-level rights, and when were they last reviewed?
  • Lifecycle: what happens to an NHI when the application or its owner goes away?
  • Monitoring: would you notice a service account being used from a new location, or a leaked key being used?
  • AI agents: do you know which agents exist, whom they act for and what they can access?
  • Governance: is there an approved NHI policy, and who is accountable for it?

Moving up a level

From Ad hoc to Developing

  • Run discovery on your main cloud, directory and code platforms. See the NHI Lifecycle Management Guide.
  • Turn on secrets scanning and push protection in source control.
  • Stand up a vault and move the highest-risk secrets into it. See the Secrets Management Guide.
  • Assign owners to the most privileged NHIs first.

From Developing to Defined

From Defined to Managed

From Managed to Optimised

  • Make secretless patterns the default for new workloads.
  • Grant NHI and agent privileges just in time and per task. See the JIT Access Guide.
  • Automate containment: revoke or quarantine credentials automatically on high-confidence detections.
  • Report risk-based NHI metrics to leadership. See the Identity Security Metrics Guide.

Metrics that show maturity

  • Percentage of NHIs with a named owner.
  • Number and age of long-lived static secrets.
  • Percentage of workloads using federated or short-lived credentials.
  • Number of NHIs with privileged access, and time since last review.
  • Stale and orphaned NHIs found and removed.
  • Mean time to revoke a leaked credential.
  • Percentage of AI agents registered with an owner and scoped access.

How this model relates to others

The NHI Governance Maturity Model focuses on non-human identities. The Identity Security Maturity Model covers all identity types across eight capabilities, and the Agentic AI Identity Maturity Model goes deeper on AI agents. Use them together: an organisation's NHI maturity usually lags its workforce identity maturity, and agent maturity usually lags both.

Practitioner checklist

  • Score each of the eight dimensions separately, using evidence rather than policy statements.
  • Set Level 3 as the first target, with Level 4 for the highest-risk systems.
  • Prioritise the lowest-scoring dimension that affects your most critical assets.
  • Agree metrics for each dimension and baseline them now.
  • Reassess at least annually and after major platform changes.
  • Include AI agents from the start rather than treating them as a separate programme.

Standards and references

Related NHI Mgmt Group resources: Ultimate Guide to NHIs · Top 10 NHI Issues · NHI Lifecycle Management Guide · NHI Security Platform Buyer's Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org