Non-human identity governance, without the vendor pitch.
Service accounts, API keys, OAuth tokens, workload identities, and AI agents now outnumber your people by 45 to 1, and they are the attack surface behind Salesloft/Drift, Snowflake, Storm-0558, and Shai-Hulud. This is the neutral reference for understanding and governing them.
Free to read. Editorially independent. No vendor pays to be profiled.
New and recently updated
- NHI market consolidation tracker. Astrix to Cisco, Entro to SailPoint, Oasis to Cyera. The category consolidated in 12 weeks. Maintained fortnightly.
- AI agent identity standards: the 2026 landscape, every active effort mapped with its real status, and what to build now.
- Certificate lifecycle and the 47-day deadline. TLS lifetimes fall to 47 days by March 2029. Why this is an NHI problem.
- CSA Agentic Trust Framework. The first Zero Trust framework for autonomous agents, and its limits.
- NHI vendor comparison. Current ownership and the nine questions that discriminate.
- NHI and AI agent standards tracker, every standard, draft and regulation with its real status. Including what does not exist yet.
- ISO/IEC 42001 × NHI. Clause by clause, and the five ways non-human identity breaks the audit.
- Guides by role, for CISOs, internal auditors, and identity architects.
The identities nobody is watching.
Service accounts, API keys, OAuth grants, workload credentials and AI agents outnumber your people by a wide margin, and almost none of them are covered by the joiner-mover-leaver process that governs everyone else.
Three pillars. One clear job.
Every page either teaches a concept, translates a framework, or dissects a breach. No product funnels. No vendor paywalls. One conversion action on every page: run a free assessment or open the tools.
The reference library
Definitional pages written to be the neutral reference on NHI, cited, not a sales funnel. What is a non-human identity? What distinguishes it from machine identity and workload identity? How does the lifecycle work? A-Z glossary. Built to be cited, not to sell software.
Browse the library →The framework translator
OWASP NHI Top 10 with a working self-audit. SPIFFE and SPIRE explained without the vendor spin. The IETF WIMSE working group's draft architecture, read and summarised. CSA's program guide. NIS2, DORA, and EU AI Act cross-mapped to NHI controls.
See the frameworks →The breach catalog
Every anchor NHI breach, broken down to the attack chain, the root-cause NHI, the timeline, and the specific control that would have prevented it. Salesloft/Drift. Snowflake. Microsoft Storm-0558. Shai-Hulud 2.0. Okta Support. Codecov. Fewer cases, more depth.
Study the breaches →Four ways in, all free.
Every one runs in your browser, needs no signup, and gives you something you can act on. Nothing is emailed and nothing is stored.
Where the market is moving next.
Two hubs that aren't the core pillars, but are where the SEO is wide open and the buyer pain is growing fastest: agentic AI identity, and vendor-neutral buyer guidance.
Identity for AI agents, MCP servers, and agentic workloads.
The fastest-growing NHI category with the thinnest existing coverage. Microsoft Entra Agent ID. SailPoint Agent Identity Security. Model Context Protocol governance. Delegation patterns. Human-in-the-loop controls. This is where enterprise pain is growing fastest and reference-quality writing is thinnest.
Enter the hub →The neutral vendor guide that no vendor can write.
Profiles of Astrix, Oasis, Entro, CyberArk, HashiCorp Vault, and GitGuardian, without paid placement, without "strategic partner" footers, with a clear editorial policy and last-reviewed date on every profile. Compare head-to-head. More vendors added as we review them.
Open the vendor hub →Why this site can be neutral when others can't.
Most NHI reference sites list 15+ "strategic partners" in their footer. That is their business model. Ours is different. We are funded by HumanAudit Inc. consulting and ISO/IEC 42001 documentation products, and we take no vendor money.
Reading is one thing. Evidence is another.
This reference is published by HumanAudit Inc., which builds the artefacts a compliance team attaches to an audit file. If you have moved past understanding the problem and need documentation that survives an assessor tracing a control, that is the work we do.
Book a 20-minute call
Bring the questionnaire that is blocking you, or the finding you need to close. If we are not the right answer we will say so on the call.
Free, no prep → DocumentationISO/IEC 42001 toolkits
The 23 core AIMS documents with all 38 Annex A controls pre-populated, plus crosswalks to ISO 27001, NIST AI RMF and the EU AI Act.
See the tiers → Free assessmentScore your documentation
Eighteen questions, two minutes, no signup. Shows which of the required documents you hold and which gaps an auditor checks first.
Run it →Frequently asked
What is non-human identity?
A non-human identity (NHI) is any digital identity that represents a software entity rather than a person, service accounts, API keys, OAuth tokens, cloud IAM roles, Kubernetes service accounts, certificates, SSH keys, workload identities, SaaS-to-SaaS integrations, and the rapidly growing category of AI agents and MCP servers. Full definition here.
Is this the same as machine identity management?
Partially. "Machine identity" (Gartner, Venafi, CyberArk's preferred framing) centres on the machine or certificate as the identity-bearing unit. "Non-human identity" (NHIMG, Astrix, Oasis, most newer vendors) is a broader umbrella that includes SaaS-to-SaaS connections, OAuth apps, and AI agents. We use NHI as the umbrella term and break down the distinction here.
Who publishes this site?
HumanAudit Inc., a Delaware C-Corp. We also publish euaiactchecklist.com and iso42001toolkit.com, which are commercial toolkit products. This site is editorially independent, no vendor pays to be profiled. When you need audit-ready documentation or hands-on help, our commercial toolkits and advisory calls are linked where relevant. More on who we are.
Do vendors pay to appear here?
No. No vendor pays to be profiled, reviewed, compared, or mentioned on any content page. We carry no affiliate links of any kind. No vendor on this site has paid us anything, and none can. Editorial policy in full.
Is this legal advice?
No. Everything on this site is educational and informational. For compliance decisions affecting your organisation under NIS2, DORA, HIPAA, PCI DSS, or the EU AI Act, consult qualified legal counsel. See the Terms of Use.