CIOs urged to rethink identity as non-human identities outnumber humans 50:1
A Saviynt executive warns that non-human identities outnumber human workers 50:1, urging CIOs to adopt new identity security measures.
The startling ratio comes from a 2025 statistic by the Non-Human Identity Management Group, which the author suggests is already outdated. With the acceleration of AI, machine learning, the Internet of Things, digital assistants, and the API economy, the number of nonhuman entities is growing exponentially. NHIs include machines, processes, service principals, virtualized workloads, and applications that are granted digital credentials, such as a helpdesk chatbot on a website.
Managing these identities is a challenge that CIOs, identity experts, and CISOs must accept, the article says. It draws a parallel to the deployment of identity access management four decades ago, noting that now the scope has expanded beyond humans. The author observes that no organization has a clear idea of who serves as the “HR chief” for nonhuman identities. When onboarding people, companies manage their permissions and embed organizational culture, risks, and security processes. Similar contextual controls are needed for nonhuman assets.
The article stresses that without such controls, leaders cannot understand where risks originate or what measures to take. A central, visible platform is necessary, but legacy IAM tools are inadequate because they focus narrowly on compliance and are static, relying on rigid criteria like six-month audits and rote permission dispensing. Rooted in the post-Sarbanes-Oxley era, traditional IAM ignores the explosion of identity types in the digital world.
To address this, the author recommends identity security posture management (ISPM) to provide dynamic inventory and continuous improvement, rather than a one-time discovery process. Holistic technology inventory must be based on CI/CD pipeline control frameworks, allowing dynamic views of who is using what and where. Practical steps include guarding against credential misuse across agents, spotting risks from non-expiring tokens, and analyzing API access just-in-time.
The article concludes by framing the challenge as an opportunity. Security and identity teams can ask what new constructs need to be added to legacy IAM, often replacing them with systems designed for the current age. By providing these controls, identity leaders can gain credibility through risk ratings based on behavioral analytics and business function.