By HumanAudit Inc. editorial teamLast reviewed 5 August 2026

The technical problem is the same for everyone. What lands on your desk is not. These six guides take the same subject from a specific starting point, and each one answers the question that role is actually accountable for.

Who owns what, and where it falls through

The recurring finding across every non-human identity programme is not a missing control. It is that the asset class sits between three functions and is fully owned by none of them. This is the ownership map we use when scoping a programme, and the last column is where the work usually stalls.

FunctionUsually ownsUsually assumes someone else owns
Identity and access managementDirectory service accounts, joiner-mover-leaver, access reviewsCloud IAM roles, CI/CD tokens, SaaS OAuth grants, agent credentials
Platform engineeringCloud IAM, Kubernetes, CI/CD credentials, secrets toolingOwnership attribution, review cadence, evidence retention
Security operationsDetection, incident response, alertingInventory completeness, credential lifetime policy, revocation testing
Application teamsThe credentials they create for their own servicesEverything after the service ships
Compliance and auditFramework mapping, evidence requests, findingsWhether the population being sampled is complete

The test that settles it

Ask each function which non-human identities they would list if an auditor asked tomorrow, then compare the lists. Where two functions each assume the other holds a category, that category is unowned, and it is almost always the one that shows up in the finding. Naming a single accountable owner is worth more than any tooling decision you will make this year.

What every role needs regardless

Four artefacts underpin all six guides. Whichever role you hold, these are what a conversation with any other function will come back to.

01

An inventory

With a named individual owner per identity and a stated method for how the list was produced.

Discovery method →
02

A lifetime policy

Expiry automatic, extension requiring justification. The default matters more than the number.

Policy template →
03

A review that executes

Reviewed against exercised permissions, complete only when revocations have actually been carried out.

Review runbook →
04

A measured kill path

Revocation time as a number from a real drill, not an estimate of what would happen.

Kill paths →