$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
🤖 Platform · NHI

Service accounts and AI agents —
finally owned.

Every machine identity gets a type, an owner, a risk score and a review cycle. Unowned NHIs are a finding, not a fact of life — ownership coverage is a top-line KPI from day one.

Typed, owned, asserted

A reason to exist, not a guessed one.

Service accounts, system accounts, applications, IoT devices and AI agents each get a lifecycle driver — change-driven, runtime-driven, asset-bound, or purpose-driven — asserted by a person at registration, never guessed from the identity type. A component nobody looked at reads identically to one somebody vouched for, until asserting the reason becomes the difference.

  • Four lifecycle drivers, asserted not derived — only a genuine assertion can quiet a finding, a suggested value never does
  • What it needs is declared at registration too: entitlements submitted as a real access request, never granted directly, and an account linked or requested right then
  • Ownership coverage (% of NHIs with a named owner) as a KPI. The owner role behind that number is derived, not handed out: own something and you have it, own nothing and you do not. Nothing else grants it, and the API refuses a manual add — so the coverage figure cannot be inflated by a role assignment nobody can trace to a possession
  • Named risk drivers — no owner, stale credentials, a privileged account — plus a per-identity blast radius: what this NHI could reach if compromised

When an owner leaves, their pending decisions become one finding with a one-click reassign — not a queue that quietly stops moving. Becoming an owner is audible: the product tells you what you now own and what that means, the first time and every time it changes. A claim routed to you lands in your inbox — accept it, redirect it, or escalate it yourself, without an admin in the loop. And the service-account owner has a workbench of their own: orphans, claims, coverage — reachable from the navigation, not a deep link somebody has to send you.

AI agents get a deeper page of their own — the agent register, credential hygiene and the kill-switch: AI-agent governance →

app.rapidvalue.eu/nhi
the NHI estate — classification, credential rotation, risk and owner per machine identity
the NHI estate — classification, credential rotation, risk and owner per machine identity

Machine-tuned governance

Cron jobs aren't leavers.

Dormancy thresholds are tuned for machine behaviour, a yearly ownership attestation ships seeded out of the box, and NHIs are excluded from human peer-group statistics so neither picture gets distorted.

  • Dormancy windows for machines (longer than humans, deliberately)
  • Yearly NHI ownership attestation — seeded, on by default
  • API keys count as machine identities: scoped, ownable, reviewable on the same machinery, and flagged when they go dormant or hold scopes they never use
  • NHIs excluded from human peer-group baselines
…/nhi · ownership
the orphan inbox — every NHI without a named owner, ready to assign or claim
the orphan inbox — every NHI without a named owner, ready to assign or claim

See your NHIs governed on your own data.

A 30-minute kickoff connects your HR feed and one system — working POC the same day.

Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.