The five pages that cover 80% of the field.
If you read nothing else in this library, read these five. They build on each other: definition → security frame → management frame → lifecycle → the machine-identity distinction.
What is a non-human identity?
The umbrella definition, the taxonomy (service accounts, API keys, OAuth tokens, workload identities, certificates, AI agents), the distinction from machine identity, and the 45×-to-1 ratio problem.
Read, 3,200 words →Non-human identity security
The security-oriented view: attack surface, 2025 threat landscape, OWASP NHI Top 10 at a glance, the controls that actually move the needle, and why traditional IAM tooling misses NHI.
Read, 2,800 words →Non-human identity management
How to run an NHI programme: the lifecycle, the control objectives, how it fits alongside IAM and privileged access management, and the 5-stage maturity model used across the hub.
Read, 2,900 words →The NHI lifecycle, provision, operate, offboard
The four lifecycle phases (discovery, provisioning, operation, decommissioning), the control points in each, and why offboarding is the stage that fails most often, the root cause of NHI1 in OWASP's taxonomy.
Read, 2,700 words →NHI vs. machine identity, the vocabulary argument
Why the industry uses two different umbrella terms, which vendors prefer which, and which framing fits which use case. We take a position.
Read, 2,200 words →Six more pages for specific control areas.
Once you've understood the core, these are the topical deep-dives. Read them in any order, or use them as reference when a specific decision lands on your desk.
Machine identity management
The Venafi / CyberArk framing. Certificates, keys, cryptographic identity. Where it overlaps with NHI and where it differs.
NHI security
A tighter 1,500-word primer for readers who want the core ideas before going deep. A useful "share with the team" starting point.
Service account governance
Where NHI started. Active Directory service accounts, Linux service accounts, database service accounts. Still the longest-lived NHI category in most enterprises.
Secrets management
If NHI is the who, secrets are the how. Centralised secret stores, dynamic secrets, workload identity federation, and the post-static-credential future.
NHI glossary
Every term in the field, defined. Service principal vs. service account. PAT vs. OAuth token. Workload identity vs. machine identity. SPIFFE vs. WIMSE. Updated every quarter.
Take the maturity assessment
Score your programme across 12 control areas, 4 minutes. Full per-area breakdown on screen, no email.
The one-paragraph executive summary of everything below
Non-human identities, service accounts, API keys, OAuth tokens, cloud IAM roles, Kubernetes service accounts, certificates, SSH keys, workload identities, SaaS-to-SaaS integrations, and AI agents, outnumber human identities in the average enterprise by a factor of 45 to 1, and have become the leading root cause of breach since 2023. They fail most often through three specific patterns: long-lived credentials that never get rotated, orphaned identities that never get offboarded, and over-privileged service accounts that grant lateral movement once compromised. A mature NHI programme closes these three gaps with inventory, rotation, and least-privilege enforcement, using frameworks like the OWASP NHI Top 10, tooling like specialised NHI management platforms, and architecture patterns like SPIFFE/SPIRE and workload identity federation. The library pages below take each concept in turn.
From our team at HumanAudit
From understanding NHI risk to documented compliance
This hub is free and vendor-neutral. When you need audit-ready documentation, our two commercial sister sites publish the templates compliance and security teams attach to their audit files.