← All Services

NHI Governance

Inventory and risk assessment of all non-human identities, including service accounts, API keys, OAuth grants, IAM roles, certificates, and AI agent credentials.

3 weeksNHI inventory + remediation roadmap

Overview

Most organisations have a reasonable picture of their human identities. They know who has admin access, they manage joiners and leavers, they enforce MFA. The machine identities are a different story.

Service accounts accumulate over years. API keys get created for a project and forgotten. OAuth grants pile up across SaaS platforms. IAM roles get cloned from permissive templates. And now AI agents (LLM orchestrators, MCP servers, agentic pipelines) are being deployed with credentials that call external APIs, read production data, and take actions on behalf of users, with no governance in place.

Non-human identities (NHIs) are consistently one of the most exploited vectors in cloud and SaaS breaches. They’re long-lived, over-privileged, poorly monitored, and rarely rotated. Most organisations don’t have an accurate picture of how many they have, what they can do, or who owns them.

Opcode’s NHI Governance engagement gives you that picture, and a roadmap to fix it.

What counts as a non-human identity

  • Service accounts (AWS IAM users used by applications, GCP service accounts, Azure managed identities)
  • API keys and access tokens (long-lived credentials for SaaS platforms, internal services, third-party integrations)
  • OAuth grants (applications authorised to act on behalf of users in Microsoft 365, Google Workspace, and SaaS tools)
  • IAM roles (cross-account roles, assumed roles, instance profiles)
  • Machine certificates (TLS client certs, code signing certificates, SSH keys for automation)
  • AI agent credentials (LLM orchestrators calling external APIs, MCP servers, agentic pipelines with delegated permissions, AI tools with access to production data or communication platforms)

What’s included

  • NHI discovery and inventory: Systematic identification of all non-human identities across your cloud accounts, SaaS platforms, and internal systems. The inventory becomes an ongoing asset register.
  • Privilege analysis: Assessment of what each NHI can do against what it needs to do. Identifies over-permissioned credentials, standing access that should be just-in-time, and privilege escalation paths available to machine identities.
  • Lifecycle and rotation review: Review of credential age, rotation practices, and offboarding processes. Identifies long-lived credentials, orphaned accounts, and credentials tied to departed staff.
  • AI agent identity mapping: Specific focus on credentials associated with AI tools and agentic systems, covering what they can access, what they can do, and whether that access is governed and monitored.
  • Remediation roadmap: Prioritised list of remediation actions, from quick wins (rotate aged credentials, revoke unused OAuth grants) to structural improvements (move to managed identities, implement just-in-time access).

How it works

  1. Scoping: Define which platforms and environments are in scope. Identify existing documentation and tooling.
  2. Discovery: Combination of tooling-assisted enumeration and documentation review. Access required is read-only across target platforms.
  3. Analysis: Each NHI assessed for privilege level, lifecycle status, ownership, and risk. AI agent credentials assessed separately given their distinct risk profile.
  4. Inventory and risk report: Complete NHI inventory with risk ratings, ownership gaps identified, and findings documented with evidence.
  5. Remediation roadmap: Prioritised actions with effort estimates. Debrief session to walk through findings and answer questions.

Why now

Agentic AI has created a new class of machine identity that most organisations haven’t governed. Every organisation deploying Microsoft Copilot, GitHub Copilot, Claude, or custom LangChain agents is creating identities with real permissions: permissions to read emails, access code repositories, call internal APIs, and take actions on production systems. These identities are being created faster than governance processes can keep up.

The regulatory and compliance landscape is moving to reflect this. ISO 27001:2022 expanded its scope to cover non-human identities explicitly. CISA’s identity guidance increasingly addresses machine identities. Getting ahead of this now is significantly easier than remediating it under compliance pressure.

Who this is for

  • Organisations deploying AI tools or building agentic systems who want assurance that the credentials involved are governed
  • Engineering teams who know they have service account sprawl but don’t have a clear picture of the scope
  • Security teams preparing for ISO 27001, SOC 2, or APRA CPS 234 assessments where identity governance is a key control domain
  • Organisations that have experienced a breach or near-miss involving a compromised service account or API key

Ready to strengthen your security posture?

Let's talk about what Opcode can do for your organisation. Get in touch for a no-obligation discussion about your security challenges.