This is one of those posts where I started with the title and let it guide the writing.
Last week, I decided that I needed to reset my focus on two of my goals for this year: IAM metrics and non-human identities.
I have done a decent job establishing a starting point for IAM metrics. I will share more about that work once it is further along and I have something useful—not merely theoretical—to offer.
Non-human identities, however, have been a different story.
I realized that I had been actively avoiding them.
Welcome to Adolescence
When I think about the current maturity of non-human identity management, it feels like we have reached the teenage years.
Everything is dramatic. Every new development feels critically important for about 30 seconds. Whenever an authority tells us what we should be doing, we roll our eyes because we either already know it or believe their proposed approach is completely unrealistic.
Then AI agents enter the conversation, and suddenly NHIs seem determined to grow up before they are ready. We are adding autonomy, delegated authority, and increasingly complex access patterns while many organizations are still trying to answer much more basic questions:
- How many non-human identities do we have?
- Where are they located?
- Who owns them?
- What are they allowed to do?
- How are their credentials protected?
- How will we know when they are no longer needed?
If you listen carefully, you can almost hear NHI management sighing, stomping upstairs, slamming the bedroom door, and mumbling that we couldn’t possibly understand what it’s going through.
And it may be right.
Watching the Discipline Develop
This is the first time in my career that I’ve been fully aware of—and actively watching—an area of identity management this important take shape in front of me.
That is both exciting and uncomfortable.
With mature IAM disciplines, we can draw from years of established practices, operating models, vendor capabilities, and hard-earned lessons. With NHIs, many of those practices are still being debated, adapted, or invented. Even when the desired outcome seems obvious, the path to achieving it often isn’t.
My instinct is similar to what many parents try to do during adolescence: slow things down, reason through the consequences, establish guardrails, and pay attention to potentially risky influences.
We need to understand what our NHIs are interacting with, what privileges they’ve accumulated, and how much damage they could cause if they were misused or compromised. We also need to accept that we can’t prevent every mistake. What we can do is create enough visibility, accountability, and structure to reduce the likelihood that one mistake becomes an organizational crisis.
That means moving beyond simply finding service accounts and rotating passwords. It means treating each NHI as an identity with a purpose, an owner, a lifecycle, and a measurable level of risk.
My NHI Learning Journey
Enough with the analogy—for now.
I’m going to spend more time studying NHIs and documenting my journey here. I don’t intend to present myself as the person who already has all the answers. The goal is to work through the problem openly, challenge my assumptions, and develop something that can actually be applied in an enterprise environment.
I want this series to produce at least one of three outcomes:
- A strong starting point for a standard operating procedure describing how I would manage non-human identities.
- A useful collection of questions that IAM and security practitioners can ask within their own organizations.
- My next Identiverse presentation topic for 2027.
Ideally, it will produce all three.
Starting with the Lifecycle
I’m going to use the NHI Lifecycle Management Guide from the Non-Human Identity Management Group as my starting point:
The guide covers areas such as provisioning and decommissioning, discovery and inventory, classification, posture management, monitoring, and incident response. I expect to spend more time in some sections than others—and, thankfully for me, most of the areas where I need the greatest development appear near the beginning.
Discovery and inventory will likely be my first major stop. Before an organization can govern NHIs, it first needs to understand what actually exists. From there, the harder questions begin:
- Who is accountable for each NHI?
- What information should be recorded?
- What triggers a review?
- What evidence proves the identity is still needed?
- How do we retire it without disrupting the business process it supports?



Leave a Reply