The IGA → NHI Conundrum: Ownership Without Execution Is Governance on Paper

Editorial ledger graphic with two columns, 'Ownership Debt' (who's accountable) and 'Execution Debt' (who can act), divided by an oxblood rule, under the From the CIdO masthead — inverted to black background with white masthead and typography for dark social surfaces.

By Nicholas Hunt, Chief Identity Officer — From the CIdO

Within about five weeks this summer, three of the biggest names in identity answered the same question. SailPoint closed its acquisition of Entro Security on June 29, saying non-human identities "must be tied back to human identities for accountability" (SailPoint). BeyondTrust announced an NHI Governance module on July 9 built so "every non-human identity is assigned to a person or a team… so nothing runs unowned" (BeyondTrust). Microsoft's Entra Agent ID now requires a human sponsor for every agent, with sponsorship auto-escalating to the sponsor's manager if they leave the org (Microsoft Learn).

That's not marketing language. That's three separate product teams, independently, converging on the same structural fix: give every non-human identity a human record of accountability. Call it ownership debt — the backlog of NHIs with no accountable human — and the market is paying it down fast.

There's a second kind of debt these announcements don't touch, and it's the harder one.

Ownership is a record. Execution is a capability.

Ownership debt asks "who is accountable for this identity existing?" Execution debt asks a different question: can you actually reach the system that identity lives in, connect to it, and act — provision it, review it, kill it — when governance requires you to? An NHI can have a named human owner, a quarterly review cycle, and a clean audit trail on paper, and still be unreachable in practice if the target system has no API a governance platform can call.

That's not a hypothetical gap. An RSAC 2026 vendor landscape comparison of NHI discovery platforms — Entro, Astrix, Oasis, GitGuardian, Clutch — found them uniformly strong on cloud IAM, secrets vaults, CI/CD pipelines, and version control, and uniformly thin on legacy Active Directory service accounts and on-premises systems, with Silverfort named as the lone vendor differentiating on that coverage (Cremit). Entro's own published discovery catalog — cloud vaults, GitHub/GitLab/Bitbucket, CI/CD, Kubernetes — tells the same story from the vendor's own mouth: it's comprehensive for anything with a rich API, and openly flags "forgotten service accounts… silently persisting in old configuration files" as a known, largely unaddressed risk category (Entro).

I've made this argument before about IGA generally: Omdia found that at organizations averaging roughly 1,100 applications, only about 54% are adequately integrated with identity governance — the rest sit outside formal control because they lack SAML, OIDC, or SCIM, and nobody's built the custom connector (Omdia via Dark Reading). NHI is now hitting the identical wall, one layer up. It's not a coincidence. It's the same paradigm — governance bounded by what you can connect to — showing up wherever an identity model outruns its own reach.

Delegation is even splitting into two distinct mechanics worth naming separately, because vendors are only building one of them at scale. Ownership-record delegation — Entra's sponsor field, BeyondTrust's person/team assignment — answers who's accountable. Execution-credential delegation is different: Saviynt's Agent Access Gateway routes agent tool calls through "the authenticated user's token, not a service account" (Saviynt), so the agent acts as a scoped human, not as an independently privileged machine. That's a genuinely different problem, solved by a different mechanism, and most of the current NHI product cycle is spending its energy on the first one.

The organizational reality hasn't caught up to the product cycle, either

Before anyone concludes ownership debt is solved, the numbers say otherwise. The Cloud Security Alliance's May 2026 governance whitepaper found 51% of organizations report unclear AI identity ownership, and 78% have no documented policy for managing AI identities at all (CSA). A CSA survey run with Aembit (n=228, fielded January 2026) found 68% of organizations can't reliably distinguish a human action from an agent action, and when asked who's accountable, security claimed 28%, engineering 21%, IT 19% — and IAM, the function built for exactly this job, claimed just 9% (Security Boulevard). The sponsor fields are shipping faster than the humans who are supposed to sit in them are being assigned.

Stat card: 68% of organizations can't reliably distinguish a human action from an AI agent action. Source: CSA and Aembit survey, n=228, fielded January 2026.

The fix has to close both gaps, not one

This is where the argument for a universal connectivity layer earns its place — not as a competitor to SailPoint, BeyondTrust, or Saviynt's ownership models, but as the execution layer those models assume exists once you leave cloud and CI/CD. StackBob positions itself exactly there: rather than requiring custom connectors or SCIM support per target, it uses agentic automation to learn an application and execute lifecycle operations against it directly, arguing this moves typical governed-application coverage from roughly 20% to 90% (StackBob). That's StackBob's own claim about its own product, not an independently verified industry statistic — but it's aimed precisely at the gap the neutral research confirms: ownership models that can't reach the systems they're supposed to govern.

The next 12 months of NHI vendor announcements will start pivoting from "who owns it" to "how do we reach it," because the product-side ownership question is close to solved and the execution question isn't. Assigning an owner to an identity you can't act on isn't governance. It's a spreadsheet with better branding. Before your next NHI initiative gets funded, ask which debt it's actually paying down — because right now, almost everyone is paying down the easy one.

References

LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *