By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. How to use this
  2. Corporate and ownership
  3. Discovery
  4. Ownership and lifecycle
  5. Remediation
  6. AI agents
  7. Audit evidence
  8. Commercial
  9. FAQ

How to use this

Send the questions, then ignore most of the written answers. Written RFP responses in this category are close to uniform because every platform claims discovery, posture, lifecycle, remediation, secrets and agents. The questions below are designed to be re-asked in a proof of concept against your own data, where the differences become visible immediately.

Three of them. Marked : are the ones we would not sign without a satisfactory answer.

Before you send an RFP at all

If you have no inventory, no ownership model and no rotation policy, an RFP is premature. A platform will produce a well-organised list of problems you are not structured to fix, at six-figure annual cost. Score yourself against the maturity model first; below level 2 the correct next step is usually internal work, not procurement.

Corporate and ownership

  1. ⚠ Who owns you today, and what changed in the last twelve months? The pure-play category consolidated between May and July 2026. Astrix is Cisco, Entro is SailPoint, Oasis is under a Cyera letter of intent.
  2. If you were acquired, is this product separately purchasable? On what terms, and for how long is that guaranteed in writing?
  3. What happens to our contract, pricing and support tier if the parent restructures the portfolio?
  4. Which parts of the roadmap are now set by the parent rather than by this team?

Discovery

  1. Run discovery on our environment. What percentage of the NHIs we already know about did you find?
  2. More importantly: what did you find that we did not know about? That number is the product.
  3. List your integrations and mark each as read-only discovery or write-capable. Per integration, not in aggregate.
  4. How do you discover identities in systems you have no integration for?
  5. What is your refresh interval per integration, and is it polling or event-driven?
  6. How do you handle an identity that exists in two systems? Do we get one record or two?
  7. What is your false-positive rate on identity classification, measured how?

Ownership and lifecycle

  1. ⚠ Show us ownership attribution on identities whose creating employee has left. This is the hardest problem in the category and it is routinely demoed on clean data.
  2. What signals do you use to infer ownership, and what is your confidence model when they conflict?
  3. When an owner leaves, what happens automatically and what requires a human?
  4. How do you represent an exception, an identity that cannot meet policy, and does it expire?
  5. Can we run an access review campaign covering non-human identities, with reviewer, decision and evidence of execution?

Remediation

  1. When you recommend a revocation and we accept it, what actually happens?
  2. Which integrations support automated revocation, and which produce a ticket?
  3. What is your rollback path if an automated remediation breaks production?
  4. Can you rotate a credential end to end, including updating the consumers of it?
  5. What is the measured time from a revocation instruction to confirmed loss of access?

AI agents

  1. ⚠ How do you treat an AI agent differently from a service account? If the answer is "it is just another NHI," the agent capability is a label.
  2. What is your delegation model? Can you represent that this agent acted for this human under this consent?
  3. Can you discover agents we did not deploy. Shadow agents and third-party copilots with access to our systems?
  4. How do you handle an agent that authenticates via MCP? See MCP security.
  5. Which of the emerging standards do you implement, and at what draft version? Compare answers against the standards tracker, a vendor claiming compliance with an unratified draft is telling you something about how they use language.

Audit evidence

  1. Produce an export an auditor would accept, not a dashboard screenshot. See what adequate evidence looks like.
  2. Can we reproduce a point-in-time view: what did this identity have access to on a given date?
  3. How long is history retained, and at what cost tier?
  4. Which of our ISO/IEC 42001 or EU AI Act evidence obligations does your export satisfy, and which does it not?

Commercial

  1. How is pricing calculated? If per identity, what happens when discovery finds three times more identities than we estimated, which is the normal outcome?
  2. What does this product not do, that we will discover in month six? The quality of this answer is the single strongest signal you will get about the vendor. A vendor who answers it specifically is telling you they expect a long relationship.

Frequently asked questions

What should you ask an NHI vendor first?

Who owns them today and what changed in the last twelve months. The pure-play non-human identity category consolidated between May and July 2026: Astrix was acquired by Cisco, Entro by SailPoint, and Oasis is under a signed letter of intent from Cyera. Any shortlist assembled before May 2026 contains companies that no longer exist independently, so ownership and contract continuity now precede product questions.

How do you test an NHI platform's discovery in a POC?

Run it against your real environment and record two numbers: what percentage of the identities you already knew about it found, and how many it found that you did not know about. The second number is the product. Discovery demos on vendor-prepared data tell you almost nothing, because the hard cases are the systems with no integration and the identities whose creator has left.

How can you tell whether a vendor's AI agent capability is real?

Ask how they treat an AI agent differently from a service account, and ask for their delegation model. If the product cannot represent that a specific agent acted for a specific human under a specific consent, it cannot answer the question auditors are beginning to ask, and the agent capability is a marketing label rather than a feature.

Should we run an RFP before building an NHI inventory?

Usually not. Below level 2 on a maturity assessment, a platform produces a well-organised list of problems you are not structured to fix, at six-figure annual cost. The sequence that works is inventory and ownership first using existing and cloud-native tooling, then procurement to scale a process that already exists.

Running an NHI vendor evaluation?

HumanAudit runs independent, vendor-neutral evaluations: requirements definition, POC design against your own data, and a scored recommendation. We take no vendor fees.