Your Company Has More Identities Than Employees. Most of Them Aren’t People.
Updated: 2 hours ago

Ask a CISO how many identities their organization manages and the first answer is usually a headcount: employees, contractors, maybe partners. That answer is off by one or two orders of magnitude.
Every automated process in a business runs as someone. The nightly job that moves payroll data to a benefits provider authenticates with a credential. So does the pipeline that pushes code to production, the integration that syncs your CRM with your marketing platform, and the AI assistant that reads a shared mailbox to draft replies. Each one carries a set of permissions and counts as an identity, even though none of them is a person.
What counts as a non-human identity
OWASP defines non-human identities (NHIs) as the identities used to authenticate and authorize software, such as applications, workloads, APIs, bots and automated systems, to reach protected resources. In practice they include:
Service and application accounts that run enterprise apps, background jobs and integrations
API keys, tokens, certificates and SSH keys used for system-to-system access
Cloud workload identities such as IAM roles, service principals and managed identities
Automation identities behind CI/CD pipelines, RPA bots and scheduled scripts
AI agents that connect to databases, files, applications and APIs using credentials
What they share is that no one logs in as them, and the controls built around human users (MFA, HR-driven offboarding, a manager who approves access) mostly don’t apply.
How many are there?
It depends on who is counting. The range is wide because each study defines and measures NHIs differently:
Rubrik Zero Labs puts the typical enterprise at about 45 NHIs per human.
Palo Alto Networks’ 2026 Identity Security Landscape, a survey of 2,930 security decision-makers, reports 109 machine identities per human, up from 82 a year earlier.
Entro Labs, analyzing more than 27 million NHIs in customer environments, measured 144 per human in the first half of 2025.
No one should anchor on a single number. What matters is that every study points the same way: machine identities are the majority population in the enterprise, and they are growing faster than headcount.
AI agents are the fastest-growing slice
The newest category is also the fastest-growing. Respondents to the Palo Alto Networks survey expect AI agent identities to grow 85 percent over the next twelve months. The same survey found that nine in ten organizations had experienced a successful identity-related breach in the previous year.
AI agents change the character of the NHI population, not just its size. A traditional service account runs the same code every time. An agent decides at runtime what to do, which tools to call and which data to touch. Later posts in this series cover why that matters.
Agents also multiply identities of their own. An agent connected to email, a CRM and a file store may hold several credentials at once, each with its own scope, and each one is another entry that belongs in the inventory.
The credentials don’t expire on their own
Growth would be manageable if these identities were well controlled. The evidence says they aren’t.
GitGuardian’s State of Secrets Sprawl 2026 report found 28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34 percent increase over the prior year. It also found 24,008 unique secrets exposed in configuration files for the Model Context Protocol, the standard many AI agents use to connect to tools, in that protocol’s first year.
The more telling number is how long leaked credentials stay live. Of the secrets GitGuardian confirmed as valid in 2022, 64 percent were still valid when retested in January 2026. Unless someone revokes it, a leaked key keeps working for years.
Why this is a governance problem
Identity programs were designed around people. People have managers. They join, change roles and leave, and each of those events triggers a process. They also answer access reviews and carry a second factor.
Non-human identities do none of this. Nobody hires them, so nothing records their creation. Nobody fires them, so nothing triggers their removal. They accumulate privilege because broad access is the fastest way to make an integration work, and nobody comes back to trim it.
The result is that most organizations govern their human minority carefully and their machine majority barely at all.
Where to start
The first step is knowing what exists. Before any policy can apply, an organization needs an inventory of its non-human identities: what they are, where their credentials live, what they can reach and who is responsible for them.
That inventory has to reach beyond the identity provider. Credentials live in code repositories, CI/CD logs, ticketing systems and chat tools as well as in vaults. Entro Labs found that 43 percent of exposed secrets sat outside code repositories entirely.
The Bottom Line
You can't govern what you can't see. Every service account, API key, pipeline credential, and AI agent in your environment is an identity with real access, and most of them have no owner, no expiry, and no review. Before any policy, tool, or control can work, you need an accurate inventory of what exists, where its credentials live, what it can reach, and who is accountable for it.
That's the work IDMEXPRESS does. As an identity security company, we help organizations discover non-human identities across their code, cloud, CI/CD, and collaboration tools, bring them under the same governance that already protects their people, and keep that control in place as AI agents multiply the count.
Not sure how many non-human identities your organization has? Start there.
Schedule an NHI Assessment to see what's out there, or book a demo to see how IDMEXPRESS finds, governs, and secures them.
Sources
1.OWASP Foundation, OWASP Non-Human Identities Top 10 (2025).
2.Rubrik Zero Labs, as reported in “The Non-Human Identity Crisis,” The Hacker News, May 2026.
3.Palo Alto Networks, 2026 Identity Security Landscape.
4.Entro Labs, NHI & Secrets Risk Report, H1 2025.
5.GitGuardian, The State of Secrets Sprawl 2026.

Comments