top of page

FAQs
Get answers to all your NHI and NHI assessment-related questions.
General
A Non-Human Identity, or NHI, is a digital identity used by a system, application, service, API, automation workflow, cloud workload, or AI agent to access another system or resource.Examples include service accounts, API keys, access tokens, service principals, managed identities, automation bots, CI/CD pipeline accounts, machine-to-machine connections, and AI agents.These identities are not people, but they often have access to important systems, applications, cloud resources, and data.
Assessment Scope
The NHI Assessment can review machine identities such as:* Service accounts* API keys* Access tokens* Service principals* Managed identities* Cloud IAM users* Automation bots* CI/CD pipeline identities* Machine-to-machine connections* AI agents and agentic workflowsWhat the assessment will cover depends on the organization and what it wants to achieve.
Risk Areas
An orphaned Non-Human Identity is a machine identity that does not have a clear owner.This situation can occur when something comes to an end, like a project, or when someone moves on, such as an employee leaving, or a team undergoes changes. It can also happen when an application is no longer used, but for some reason, the identity associated with it stays active.Orphaned identities are risky because no one may be responsible for reviewing access, rotating credentials, approving usage, or decommissioning the identity.
Business Value
An NHI Assessment helps support compliance by giving organizations better visibility into ownership, access, credential management, privileged access, stale identities, and remediation priorities.This can help with internal audits, access reviews, regulatory readiness, and governance discussions.This provides leaders and technical teams with a better understanding of how machine identities are vulnerable.
Deliverables
Typical deliverables may include:* Non-Human Identity Inventory Summary* Risk categorization by identity type and environment* Orphaned identity findings* Credential risk findings* Least-privilege and excessive-access findings* Stale or inactive identity findings* AI-agent identity risk observations* Compliance and governance gap summary* Prioritized remediation roadmap* Executive-level summary for leadership* Technical findings summary for IAM, cloud, DevOps, and security teamsThe goal is to help your organization understand what exists, what is risky, and what to fix first.
Miscellaneous
No. Any organization using cloud services, APIs, automation, SaaS integrations, DevOps pipelines, privileged credentials, or AI agents can benefit from an NHI Assessment.Large enterprises may have a bigger machine identity footprint, but smaller organizations can still face serious risk from unmanaged service accounts, API keys, and automation credentials.
bottom of page
