By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. Metrics to stop reporting
  2. Eight that hold up
  3. The four for a board
  4. Who sees what, how often
  5. Reporting a number that got worse
  6. FAQ

TL;DR

  • Stop reporting identities discovered and alerts raised. Both rise with tooling maturity rather than with risk reduction, and both fall when you succeed.
  • Eight measures resist gaming. All eight are computable from systems you already run.
  • A board needs four: inventory coverage, unbounded credentials, authority ratio, revocation time.
  • Report deltas and deferrals, not totals. A total is trivia; a delta with a deferral list is a decision.
  • A metric going the wrong way is only a problem if it arrives without an explanation. Bring the cause and the ask.

Metrics to stop reporting

Four appear on most NHI dashboards and none of them measures risk.

MetricWhy it misleads
Identities discoveredRises as discovery improves and falls as cleanup succeeds. The same number can mean either. On its own it tells a board nothing.
Alerts raisedMeasures detector sensitivity. Tuning a rule changes it by an order of magnitude with no change in risk.
Secrets rotatedA volume measure. Rotating a credential attached to an over-privileged unowned identity narrows the theft window and not the blast radius.
Policy compliance percentageMoves when you change the policy. If the number is uncomfortable, the cheapest fix is to soften a clause, which is exactly the wrong incentive.

The common defect is that each can be improved without reducing risk, and several improve automatically when the programme is doing badly.

Eight that hold up

  1. Inventory coverage. Proportion of non-human identities in a maintained inventory with a named owner. Stated with a measurement date and the method used, because the method is what an auditor challenges. See discovery methodology.
  2. Unbounded credentials. Count of credentials with no expiry. Absolute count, not a percentage, because the percentage flatters you as the estate grows.
  3. Authority ratio. Permissions granted against permissions exercised over ninety days. The gap is over-privilege expressed as a number you can act on.
  4. Revocation time. Measured interval from instruction to confirmed loss of access. Not an estimate. See kill paths.
  5. Ownership currency. Proportion of identities whose recorded owner is still employed and has confirmed ownership in the last twelve months. Catches the failure where the field is populated and wrong.
  6. Review execution rate. Of revocations decided in access reviews, the proportion actually executed. Frequently well under 100%, and the gap is the finding.
  7. Delegation-chain completeness. For estates with agents, the proportion of consequential actions traceable to an authorising principal. See delegation chains.
  8. Exception age. Median age of open exceptions and the count past their review date. A healthy register churns. A register where nothing expires is a parking lot.

Why these resist gaming

Each one gets worse when the programme is neglected and better only through work that reduces risk. There is no configuration change that improves the authority ratio, and no way to shorten a measured revocation time except by shortening it.

The four for a board

A board has minutes, not an hour, and is answering one question: are we exposed through machine and agent credentials, and does this team know. Four numbers answer it.

NumberWhat it tells the boardWhat good looks like
Inventory coverageWhether we know what we haveA percentage with a date and a stated method, trending up
Unbounded credentialsThe size of the worst exposure classAn absolute count, trending down, with the production-reaching subset called out
Authority ratioWhether access is proportionate to needGap narrowing, reported for the highest-risk tier rather than the whole estate
Revocation timeWhether we can stop somethingA measured figure with a date, and the date of the last drill

Alongside those, one paragraph of narrative and an explicit deferral list. The deferral list is the part most teams omit and the part that most protects them: a documented, reasoned decision not to address something is governance, while an undocumented gap is a finding waiting to happen. See the CISO guide.

Who sees what, how often

AudienceCadenceContent
Platform and IAM teamsWeeklyOperational deltas: new identities, failed rotations, expiring credentials, unowned discoveries
Security leadershipMonthlyAll eight measures with deltas, exception register movement, incidents involving machine credentials
Risk or governance forumQuarterlyThe four board numbers, deferral list, framework mapping status, upcoming regulatory dates
Board or audit committeeSemi-annualThe four numbers, trend, one narrative paragraph, the ask

The most common failure here is reporting the same dashboard to all four. A board given weekly operational detail concludes the team is busy and cannot tell whether it is winning.

Reporting a number that got worse

Metrics will move the wrong way, most often because discovery improved and the denominator grew. A number that arrives without an explanation invites the conclusion that the programme is failing. Four sentences handle it:

  1. The number, plainly. No softening. "Coverage fell from 71% to 58%."
  2. The cause. "Discovery was extended to SaaS OAuth grants and found 4,100 identities we were not previously counting."
  3. The interpretation. "Our exposure did not increase. Our measurement got more honest, and the previous figure was overstating coverage."
  4. The ask. "Closing the new gap needs two engineers for one quarter, or we accept it with a documented rationale until Q2."

A programme that reports an honest decline with a cause and an ask builds more credibility than one that only ever reports improvement. The second pattern is usually a sign that the metrics are the gameable kind listed at the top of this page.

Frequently asked questions

What metrics should you use for non-human identity governance?

Eight resist gaming: inventory coverage with a measurement date and method, the absolute count of credentials with no expiry, the authority ratio of permissions granted against permissions exercised over ninety days, measured revocation time, ownership currency, review execution rate, delegation-chain completeness where agents are in scope, and exception age. Each gets worse when the programme is neglected and improves only through work that reduces risk.

What NHI metrics should you stop reporting?

Identities discovered, alerts raised, secrets rotated, and policy compliance percentage. Each can be improved without reducing risk. Identities discovered rises as discovery improves and falls as cleanup succeeds, so the same number can mean either. Policy compliance moves when you change the policy, which means the cheapest way to improve it is to soften a clause.

What should a CISO report to the board about non-human identity?

Four numbers: inventory coverage as a percentage with a date and stated method, the absolute count of credentials with no expiry, the authority ratio for the highest-risk tier, and a measured revocation time with the date of the last drill. Alongside those, one narrative paragraph and an explicit deferral list. The deferral list is what turns an undocumented gap into a documented governance decision.

How do you report a security metric that has moved in the wrong direction?

In four sentences: the number plainly with no softening, the cause, the interpretation, and the ask. A common case is coverage falling because discovery was extended and the denominator grew, which means exposure did not increase and the previous figure was overstating. A programme that reports an honest decline with a cause builds more credibility than one that only ever reports improvement.

How often should NHI metrics be reported and to whom?

Weekly operational deltas to platform and IAM teams, monthly full measures to security leadership, quarterly board numbers plus the deferral list and regulatory dates to a risk or governance forum, and semi-annual reporting to the board or audit committee. The common failure is sending the same dashboard to all four, which leaves a board able to tell the team is busy but not whether it is winning.

Need these numbers before your next board cycle?

HumanAudit produces the baseline: measured inventory coverage, credential lifetime distribution, authority ratio and a timed revocation drill. Four numbers, evidenced, in a form a board can read.