← Back to sales hub
Executive Summary

Research shows that 75% of non-human identities (NHIs) in an average enterprise have no named owner. At the same time, NHIs grow at a ratio of 50:1 vs. human identities — service accounts, AI agents, IoT devices, application-to-application credentials. The 2024 IBM Cost of a Data Breach Report identifies "stolen credentials" as the #1 attack vector, and NHI credentials (long-lived, static, nobody's responsibility) are the most exploitable.

This whitepaper describes how RapidValue IGA's 4-tier classification model + blast-radius computation + ownership claim-flow takes you from zero to full NHI ownership coverage in 90 days.

The Problem

NHIs have historically been an afterthought in identity governance. They were created by application teams without central registration. They have standing credentials that never rotate. They often hold more rights than strictly necessary. Nobody knows who the owner is when the script breaks. After a breach, nobody can say "this NHI is authorised to perform this action."

Pain pointIndustry average
NHIs without an owner75%
Static credentials older than 1 year43%
NHIs with admin-level access18%
NHIs without any access review89%
Mean time to attribute an NHI incident3–5 days

The 4-Tier Classification Model

Inspired by Omada's NHI governance maturity model, RapidValue classifies every NHI into 4 tiers based on risk profile and operational pattern:

Tier 1

AI-Assisted (classic service accounts)

Example: backup-runner, logging-aggregator, svc-* accounts

Governance: Reuse existing IGA flow + manual approval on creation.

Tier 2

AI-Enabled (scoped system accounts)

Example: CI/CD agent that can only deploy to staging

Governance: Scoped permissions, annual review, 90-day credential rotation.

Tier 3

Autonomous (AI agents)

Example: incident-response bot that can trigger SOAR actions

Governance: JIT-only access, policy-as-code, behavioural monitoring, max 24h credentials.

Tier 4

AI-to-AI (delegation chains)

Example: customer-support agent that calls order-entry agent

Governance: Agent identity federation, delegation tokens, full audit chain per call.

Blast Radius — What Can This NHI Reach?

For every NHI, RapidValue computes a 4-level transitive reachability graph. This is graph traversal, not ML — deterministic and explainable to auditors.

4-Level Transitive Reachability

L1
Direct entitlements + accounts
L2
Systems reached via accounts
L3
Other identities sharing the same resource (co-members)
L4
Delegated agents (for Tier 3/4 NHIs)
CRITICAL ≥ 3 sensitive nodes OR ≥ 4 systems
HIGH ≥ 1 sensitive node OR ≥ 3 systems OR blast > 15
MEDIUM Blast radius > 7

The Ownership Claim-Flow

When an NHI is discovered without an owner, the following automated flow triggers:

  1. Auto-assigned to NHI-admin group — configurable per tenant
  2. NHI-admin receives it in their orphan inbox — one queue per team
  3. Admin can: assign an owner from the identity store, flag for decommission, or hand over to a management group
  4. Owner receives email — "you are owner of X — is this correct?"
  5. Owner confirms → NHI has a named owner with a full audit trail

Time-bounded replacements (vacation / leave): owners can delegate to a substitute for a defined period.

90-Day Rollout Plan

WeekActivity
1–2Quick Scan on AD + Entra → discovery of all NHIs
3–4Classification into 4-tier (default Tier 1, manual escalation for higher tiers)
5–6Bulk-assign to management groups (per application team)
7–8Per-team campaign: claim your NHIs or flag for decommission
9–10Tier 2/3/4 review with security team — advanced governance setup
11–12Credential rotation policy enforcement for Tier 2+ NHIs
13Baseline ownership coverage > 95%

After baseline: continuous discovery + automatic ownership revocation when an owner becomes a leaver.

Expected Outcomes

Based on 3 customer pilots (Q1 2026, average 8,000 NHIs per tenant):

Before: 23%
97%
NHI ownership coverage
Before: 3.5 days
< 1 hr
Mean time to attribute an NHI incident
Before: 47 findings
3
NHI-related audit findings per audit
MetricBefore RapidValueAfter 90 days
NHI ownership coverage23%97%
Static credentials > 1 year51%8%
Mean time to attribute NHI incident3.5 days< 1 hour
Tier 3/4 NHIs under JIT access0%88%
NHI-related audit findings47 per audit3 per audit

Compliance Mapping

FrameworkNHI governance addresses
DORA Art. 9Maintain mapping between ICT assets (including NHIs) and access rights; continuous monitoring
NIS2 Art. 21Identity and treatment of access anomalies; NHI credentials in scope for access policy
GDPR Art. 32Demonstrable measures for confidentiality — NHI credentials as a confidentiality risk
ISO 27001 A.9Periodic access reviews extended to non-human accounts; ownership required for compliance
EU AI ActAI agent identities (Tier 3/4) require governance, oversight mechanisms, and audit trails

Conclusion

NHI governance is no longer an optional feature. In 2026, NIS2 and DORA expect NHI credentials to receive the same governance as human accounts. RapidValue IGA's 4-tier model is built in from day 1, not sold as an add-on.

The combination of automatic discovery + blast-radius computation + ownership claim-flow takes you from "we have no idea how many there are" to "continuous attestation per NHI" in 90 days.