What are non-human identities (NHI)?

Non-human identities (NHI) are the accounts and credentials that belong to software rather than people: service accounts, API keys, machine certificates, workload identities and, increasingly, AI agents acting with delegated permissions. In most enterprises they outnumber human identities many times over, yet they rarely receive the joiner-mover-leaver governance humans get — which makes unmanaged NHIs one of the fastest-growing identity risks.

Also known as: NHI security · machine identities · service account security · workload identity

Why NHIs outgrow governance

Humans arrive through HR, so identity systems hear about them. Service accounts arrive through a script, a deployment pipeline or a developer in a hurry — no onboarding event, no owner of record, no leaver process. Credentials get long lifetimes because rotation breaks things, permissions get broad because narrow ones cause tickets, and years later nobody can say what a given account is for — only that deleting it is scary. AI agents compound this: they act with delegated human-like permissions at machine speed.

Governing them

The controls are the same as for humans — inventory, ownership, least privilege, lifecycle, rotation — but applied at a scale manual processes cannot reach, across applications that were never designed to expose their machine accounts. That makes NHI governance an identity-operations problem: platforms like Way Security automate discovery and onboarding of accounts across the estate, including the legacy systems where the oldest and riskiest service accounts hide.

// In the Cyberdis portfolio

Way Security brings governance to the identities nobody onboarded — distributed by Cyberdis.

// FAQ

Common questions.

How many non-human identities does a typical enterprise have?

Analyst estimates commonly put machine identities at tens of times the human count once service accounts, keys, certificates and workloads are tallied — and the ratio grows with cloud adoption and automation. The precise number matters less than the pattern: most are unowned and ungoverned.

Why are service accounts dangerous?

They combine broad permissions, long-lived credentials, no MFA and no owner. Attackers prize them: compromising one yields durable, quiet access that no leaver process will ever revoke.

Are AI agents non-human identities?

Yes — the newest and fastest-growing kind. An agent holding delegated user permissions acts as an identity in every meaningful sense, and needs the same inventory, scoping and lifecycle governance, applied at machine speed.

Related explainers: What are identity operations?What is identity governance and administration (IGA)?

Weighing approaches? AI-powered IAM automation vs consulting-led implementation