The math changed and the process didn't
Ten years ago, "identity" mostly meant employees and the occasional contractor. Access reviews, certification campaigns, deprovisioning workflows: all of it was built around a headcount-shaped problem. Today, every integration, every automated workflow, every CI pipeline, and increasingly every AI agent carries its own identity and its own set of permissions. Non-human identities now outnumber human ones at most mid-sized and larger organizations, often by a wide margin, and the gap is growing every quarter new automation ships.
The access governance process, in most organizations, never got the memo. Quarterly certification campaigns still list human managers reviewing human reports' access. Service accounts and agent credentials sit outside that cycle entirely, reviewed rarely if ever, because nobody built a process that assumed they'd need reviewing in the first place.
Why this blind spot is expensive
- Nobody owns the review. A human employee's access gets reviewed by their manager, an obvious owner. A service account created two years ago by someone who's since left the company has no obvious reviewer at all, so it doesn't get one.
- Permissions only accumulate. Non-human identities rarely get their access reduced, because reducing access requires someone to notice it's excessive, and noticing requires a review that isn't happening.
- They're a preferred target. Attackers increasingly go after service accounts and API credentials specifically, because they're less monitored, rarely rotated, and often carry broader access than any single human account would.
What closing the gap actually requires
This isn't solved by adding a checkbox to the existing human-focused review. It requires treating non-human identity as its own category with its own process: an inventory of every service account, API key, and agent credential; an assigned owner for each one, even the ones that predate anyone currently on staff; a review cadence that doesn't depend on a manager relationship that doesn't exist; and expiry or rotation built in by default rather than as an exception someone has to request.
Ask most access governance teams for a complete inventory of non-human identities with assigned owners and last-review dates, and you'll get a partial list at best, usually missing anything created outside a formal onboarding process. That gap is the starting point, not a footnote.
The AI agent wave makes this urgent, not new
Non-human identity has been an underserved corner of access governance for years. AI agents didn't create the problem, they're accelerating it, adding a new and fast-growing category of non-human identity on top of the service accounts and API keys that were already under-reviewed. Organizations that close this gap now, before agent identities multiply further, save themselves from re-solving the same problem twice.
Extending access governance to cover every non-human identity, not just the human ones, is core to how we structure certification and review programs.
Want to know how many non-human identities are actually running unreviewed in your environment?
Start an assessment today