← Back to roshantrivedi.co.in
RT · Identity Security
Emerging Practice · Non-Human Identity

Machines outnumber people 50 to 1 — and almost none of them have an owner.

A privacy-safe case study on turning an invisible sprawl of service accounts, API keys, workload identities and AI agents into a governable, risk-ranked program — plus a live sandbox that runs the same scoring logic.

My Role
Credential Management Platform Owner & PAM Product Owner
Challenge
Service accounts, API keys, workload identities and now AI agents accumulate faster than any team can govern them. Ownership gets lost at handoff, credentials outlive the systems that issued them, and audits default to belief instead of evidence.
Public-Safe Outcome
Built a non-human identity inventory and risk-scoring model that turned thousands of untracked machine identities into a ranked, ownable backlog — surfacing the small fraction driving most of the exposure.
APPROACH

Three moves, in order

The same sequence the sandbox below simulates: see everything, rank what matters, then turn the top of the list into a standing control instead of a one-time cleanup.

01

Discover

Correlate identities across vault, IAM, cloud IAM and CI/CD into one inventory — every service account, API key and workload identity, regardless of where it was created.

02

Score

Rank each identity by blast radius, staleness and ownership gap, so a flat list of thousands becomes a short list of what actually matters this week.

03

Remediate & Govern

Route the highest-risk identities into rotation, ownership assignment or retirement — then keep the score current as a standing control, not a one-time audit finding.

Non-human identity Secrets governance Risk scoring Zero Standing Privilege
THE PIPELINE

From sprawl to a ranked, governable list

The same three-stage pipeline the sandbox below simulates, end to end.

01 · DISCOVER Inventory everything Vault, IAM, cloud IAM, CI/CD — one identity list 02 · SCORE Rank by risk Blast radius, staleness, ownership gap 03 · REMEDIATE & GOVERN Fix, then keep it fixed Rotation, ownership, standing control
FIELD NOTE · FROM THE COMMENTS

Ownership is the bottleneck, not the scoring

When this case study went out on LinkedIn, Gelson Monteiro raised the point that matters most: Zero Standing Privilege only holds up once ownership is actually enforced — otherwise you're just time-boxing access nobody remembers approving. His read: most orgs discover non-human identities faster than they can find a human willing to be accountable for one, so the fleet keeps outgrowing ownership.

Ownership is probably the hardest part here. Finding NHIs is getting easier — finding the right person willing to own and be accountable for one is a different challenge, and there's real risk in taking that on. Without ownership, ZSP alone won't fix it. For me, ownership, rotation and offboarding have to work together, or we're just shrinking the access window without fixing the lifecycle problem underneath it.

— Roshan, replying in the thread
TRY IT

Non-Human Identity Risk Visualizer

A synthetic fleet of machine identities, scored live in your browser. Apply governance controls below and watch the risk surface shrink.

⚠️ Synthetic sandbox — no real infrastructure, credentials or company data. Every identity below is randomly generated in your browser to demonstrate the scoring model described above.
0
Total Identities
0
High Risk
0
Orphaned
0
Avg Risk Score
Identity
Age
Last Rotated
Privilege
Owner
Risk

Related reading: One Key, Every Agent — three real 2025-2026 breaches traced back to shared AI agent credentials.