Non-human identity

BusinessSafety and governancePublished By Simon Budziak

Non-human identity is any digital identity that belongs to software rather than a person: a service account, a workload, a CI/CD pipeline, an automation bot, or an AI agent that authenticates and acts without someone driving each step. Enterprises now run far more of these than staff accounts.

Why did non-human identity become an AI problem?

Machine identities were already the larger population before agents arrived. What changed is behavior. A service account does the same thing every day, while an agent decides at runtime which tools to call and which data to read, so the blast radius of one credential is no longer fixed at the moment it is issued. That is why agent identity is treated as its own control rather than a row in an access spreadsheet.

What should a mid-sized company actually do?

Start with the count, because most organizations cannot produce one: an AI inventory that lists every agent, its owner, and what it can reach. Then narrow permissions to the task rather than the role, which is the point of least privilege for AI agents, and make each action traceable through agent authorization. An identity nobody owns is the one that survives every review, which is exactly how agent sprawl turns into an audit finding.

Frequently asked questions

How is a non-human identity different from an agent identity?

Agent identity is the narrower case: the credential and permissions a single AI agent presents. Non-human identity is the whole population of software identities in your estate, which includes service accounts and pipelines that predate any AI work.

Why do AI agents make this harder than service accounts did?

A service account has fixed permissions set once. An agent can acquire access at runtime, call external tools, and start subagents, so the set of things one credential can reach changes during a task rather than between change requests.

Summarize this page with

See this working in a system we built