By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
Start here

The five pages that cover 80% of the field.

If you read nothing else in this library, read these five. They build on each other: definition → security frame → management frame → lifecycle → the machine-identity distinction.

For the skimmer

The one-paragraph executive summary of everything below

Non-human identities, service accounts, API keys, OAuth tokens, cloud IAM roles, Kubernetes service accounts, certificates, SSH keys, workload identities, SaaS-to-SaaS integrations, and AI agents, outnumber human identities in the average enterprise by a factor of 45 to 1, and have become the leading root cause of breach since 2023. They fail most often through three specific patterns: long-lived credentials that never get rotated, orphaned identities that never get offboarded, and over-privileged service accounts that grant lateral movement once compromised. A mature NHI programme closes these three gaps with inventory, rotation, and least-privilege enforcement, using frameworks like the OWASP NHI Top 10, tooling like specialised NHI management platforms, and architecture patterns like SPIFFE/SPIRE and workload identity federation. The library pages below take each concept in turn.

From our team at HumanAudit

From understanding NHI risk to documented compliance

This hub is free and vendor-neutral. When you need audit-ready documentation, our two commercial sister sites publish the templates compliance and security teams attach to their audit files.