Join our Newsletter — 33% off our NHI Course
NHI Mgmt Group Guides

NHI, IAM & Agentic AI Security Guides

Practitioner guides, buyer's guides, maturity models and briefings on non-human identity, identity and access management, and securing AI agents.

73 guides  ·  Written and reviewed by Lalit Choda
Showing 73 guides

Agentic AI Security

21
Standards Tracker Agentic AI Security
Agent Identity Standards Tracker
Where AI agent identity standards stand: MCP, A2A, OAuth and IETF drafts, OpenID AuthZEN, SPIFFE, FIDO, NIST, EU AI Act and OWASP.
8 min read Read guide →
Glossary Agentic AI Security
Agentic AI Glossary
Clear definitions of agentic AI identity and security terms: agents, MCP, A2A, delegation, prompt injection, memory poisoning and more.
7 min read Read guide →
Guide Agentic AI Security
Agentic AI Identity Guide: How AI Agents Get, Use and Lose Identities
How AI agents get, use and lose identities: identity models, delegation, registration, authentication and retirement, with a maturity path.
11 min read Read guide →
Maturity Model Agentic AI Security
Agentic AI Identity Maturity Model
A five-level maturity model for AI agent identity across seven dimensions, with self-assessment questions and a roadmap to Level 3.
8 min read Read guide →
Guide Agentic AI Security
Agentic AI Security Guide: Threats and Controls Across the Agent Stack
A layered threat model for agentic AI mapped to the OWASP Agentic Top 10, with controls for inputs, memory, tools, orchestration and identity.
9 min read Read guide →
Guide Agentic AI Security
Agentic Commerce Identity Guide: AI Agents That Buy
The identity model behind AI agent payments: agent identity, verifiable mandates, tokenised credentials, AP2, FIDO and what to do now.
5 min read Read guide →
Guide Agentic AI Security
AI Agent Authorisation Guide: Least Privilege for Non-Deterministic Actors
Apply least privilege to AI agents: task-scoped and just-in-time access, per-action policy decisions, delegated authority and human approval.
9 min read Read guide →
Buyer's Guide Agentic AI Security
AI Agent Identity Security Buyer’s Guide
A vendor-neutral guide to choosing AI agent identity and security tools: capability areas, evaluation criteria, RFP questions and PoC plan.
8 min read Read guide →
Guide Agentic AI Security
AI Agent Memory Security Guide
Protect AI agent memory from poisoning and cross-user leakage: isolation, write controls, no secrets in memory, logging and retention.
4 min read Read guide →
Guide Agentic AI Security
AI Agent Observability, Audit and Incident Response Guide
What to log for AI agents, how to attribute actions, which signals show an agent has gone wrong, and how to build a tested kill switch.
8 min read Read guide →
Guide Agentic AI Security
AI Agents vs Agentic AI: What’s the Difference and Why It Matters for Identity
AI agents vs agentic AI explained: a spectrum from chatbot to multi-agent system, and how identity, access and risk change at each level.
10 min read Read guide →
Guide Agentic AI Security
AI Coding Agents Security Guide: Protecting Secrets, Code and Pipelines
Secure AI coding assistants and agents in the IDE, terminal and CI/CD: secrets in context, over-scoped tokens, supply chain risk and sandboxing.
8 min read Read guide →
Guide Agentic AI Security
Browser and Computer-Use Agent Security Guide
Identity risks of agents that drive browsers and desktops using your sessions, and controls for isolation, site scope and confirmation.
4 min read Read guide →
Guide Agentic AI Security
Low-Code Agent Platform Security Guide
Govern AI agents built on low-code platforms: maker credentials, connector policies, sharing limits, ownership and monitoring.
4 min read Read guide →
Guide Agentic AI Security
MCP Security Guide: Securing the Model Context Protocol
Practical MCP security: the OAuth-based authorisation model, token passthrough, tool poisoning, local server credentials, gateways and a checklist.
10 min read Read guide →
Guide Agentic AI Security
Red Teaming AI Agents for Identity Abuse
How to red team AI agents for privilege escalation, credential misuse, delegation abuse and exfiltration, and fix findings with identity.
4 min read Read guide →
Guide Agentic AI Security
Securing Multi-Agent Systems and Agent-to-Agent (A2A) Trust
How to secure multi-agent systems and the A2A protocol: agent authentication, signed Agent Cards, multi-hop delegation and containment.
9 min read Read guide →
Guide Agentic AI Security
Shadow AI and AI Agent Discovery Guide: Finding the AI You Don’t Know About
Find shadow AI and unmanaged agents through OAuth grants, API keys, cloud, endpoint and network signals, then bring them under governance.
7 min read Read guide →
Guide Agentic AI Security
Threat Modelling AI Agents: A Practical Workshop Guide
A step-by-step method for threat modelling AI agents using CSA MAESTRO and OWASP Agentic Top 10, with an identity map and worked example.
8 min read Read guide →
Top 10 Agentic AI Security
Top 10 Agentic AI Identity Issues
The ten most important AI agent identity issues, why each matters, what to do and how they map to the OWASP Agentic and NHI Top 10s.
5 min read Read guide →
Guide Agentic AI Security
Zero Trust for AI Agents: Applying NIST SP 800-207 to Autonomous Actors
Apply zero trust to AI agents: verify the agent, principal and request, remove standing privilege, enforce policy per action and assume breach.
7 min read Read guide →

AI Security

6

Non-Human Identity (NHI)

13
Guide Non-Human Identity (NHI)
API Key Management Guide: The Full Lifecycle from Creation to Retirement
How to create, scope, store, rotate and revoke API keys safely, when to use something stronger, and how to respond when a key leaks.
6 min read Read guide →
Guide Non-Human Identity (NHI)
CI/CD Pipeline Identity Security Guide
Secure the identities in CI/CD: keyless OIDC federation, token permissions, untrusted builds, pinned actions, publishing tokens and signing.
5 min read Read guide →
Guide Non-Human Identity (NHI)
Cloud Workload Identity Guide
How cloud workloads get identities without static keys: AWS IAM roles, Azure managed identities, Google service accounts and workload identity federation.
17 min read Read guide →
Guide Non-Human Identity (NHI)
Human vs Non-Human Identity
Human and non-human identities compared: ownership, lifecycle, authentication and governance, plus the risky points where people and machine access meet.
17 min read Read guide →
Guide Non-Human Identity (NHI)
Kubernetes NHI Security Guide
Secure non-human identities in Kubernetes: service accounts, bound tokens, RBAC, secrets and workload identity federation to the cloud, with a checklist.
17 min read Read guide →
Guide Non-Human Identity (NHI)
Machine Identity, PKI and Certificate Lifecycle Guide
Certificates as machine identity: the CA/B Forum move to 47-day TLS certificates, lifecycle automation with ACME, key protection and PQC.
6 min read Read guide →
Guide Non-Human Identity (NHI)
NHI Authentication Guide
How non-human identities authenticate: API keys, OAuth client credentials, mTLS, workload identity federation, SPIFFE and AI agents, with a checklist.
16 min read Read guide →
Guide Non-Human Identity (NHI)
NHI Ownership and Accountability Guide
Why ownership underpins NHI security, how to assign owners at creation, find owners for existing NHIs and handle orphaned identities.
5 min read Read guide →
Buyer's Guide Non-Human Identity (NHI)
NHI Security Platform Buyer’s Guide
A vendor-neutral guide to choosing an NHI security platform: capabilities, evaluation criteria, vendor questions, red flags and PoC plan.
5 min read Read guide →
Guide Non-Human Identity (NHI)
SaaS-to-SaaS and OAuth App Governance Guide
Govern OAuth apps and SaaS-to-SaaS integrations: consent, scopes, token risk, lessons from Salesloft Drift and Klue, and a revocation runbook.
5 min read Read guide →
Buyer's Guide Non-Human Identity (NHI)
Secrets Management Buyer’s Guide
Compare cloud-native, cross-platform and developer-focused secrets managers: core capabilities, vendor questions, red flags and PoC tests.
4 min read Read guide →
Guide Non-Human Identity (NHI)
Secrets Management Guide: Centralise, Restrict, Shorten and Remove
Practical secrets management: centralising secrets, solving secret zero, rotation, dynamic secrets and moving to secretless workload identity.
6 min read Read guide →
Guide Non-Human Identity (NHI)
Service Account Security Guide: Finding, Reducing and Governing Service Accounts
Secure service accounts across AD, Entra ID, cloud, SaaS and databases: discovery, least privilege, managed identities, rotation and governance.
7 min read Read guide →

Identity & Access Management (IAM)

8
Guide Identity & Access Management (IAM)
Active Directory and Entra ID Hardening Guide
Prioritised AD and Entra ID hardening: tier zero, privileged groups, service accounts, delegation, certificate services and hybrid identity.
5 min read Read guide →
Guide Identity & Access Management (IAM)
Authorisation Models Guide: RBAC, ABAC, ReBAC and Policy Engines
Compare RBAC, ABAC, ReBAC and policy-based access control, externalised authorisation and AuthZEN, for people, workloads and AI agents.
5 min read Read guide →
Guide Identity & Access Management (IAM)
Customer IAM (CIAM) Guide: Securing Customer Identity
CIAM essentials: stopping credential stuffing and account takeover, passkeys, secure recovery, delegated and agent access, and consent.
4 min read Read guide →
Buyer's Guide Identity & Access Management (IAM)
IAM and Identity Provider Buyer’s Guide
Choose a workforce identity provider: SSO, phishing-resistant MFA, lifecycle, admin security, NHI and agent support, vendor security, PoC.
4 min read Read guide →
Guide Identity & Access Management (IAM)
IAM and IGA Basics
A plain-English guide to IAM and IGA: identities, authentication, authorization, provisioning, access reviews and governance for people and machines.
18 min read Read guide →
Guide Identity & Access Management (IAM)
Identity Provider and SSO Security Guide
Harden your IdP and SSO: admin protection, phishing-resistant MFA, session and token security, help-desk recovery and federation monitoring.
5 min read Read guide →
Guide Identity & Access Management (IAM)
Passwordless and Passkeys Guide for Workforce and Customers
How passkeys and FIDO2 give phishing-resistant sign-in, what NIST SP 800-63B-4 requires, and how to roll out and secure recovery.
5 min read Read guide →
Guide Identity & Access Management (IAM)
Workforce Identity Security Guide
Protect employee identities with phishing-resistant MFA, SSO, joiner-mover-leaver provisioning and safe help desk resets, and see the attacks they stop.
17 min read Read guide →

Identity Governance (IGA)

5

Privileged Access (PAM)

6

Identity Visibility, Posture & Threat Detection

5

Governance, Risk & Compliance

9
Guide Governance, Risk & Compliance
Agentic AI Compliance Guide: EU AI Act, NIST AI RMF and ISO/IEC 42001
Map AI agent identity controls to the EU AI Act (post-Omnibus dates), NIST AI RMF, ISO/IEC 42001, GDPR, DORA and NIS2, with audit evidence.
8 min read Read guide →
Template Governance, Risk & Compliance
Agentic AI Security Policy Template
A ready-to-adapt policy template for AI agents covering registration, identity, access, human oversight, tools, monitoring and retirement.
9 min read Read guide →
Executive Briefing Governance, Risk & Compliance
Board and CISO Briefing: Agentic AI Identity Risk
AI agent identity risk in business terms: five questions for the board, what good looks like, where to invest, metrics and a 90-day plan.
6 min read Read guide →
Guide Governance, Risk & Compliance
Building the Business Case for Identity and NHI Security
Build a credible business case for NHI, IAM, PAM or agent identity investment: evidence, value framing, risk quantification and costs.
4 min read Read guide →
Guide Governance, Risk & Compliance
Identity Convergence Guide
What identity convergence means across workforce, privileged, customer, NHI and AI agent identity, its benefits and limits, and how to start.
4 min read Read guide →
Maturity Model Governance, Risk & Compliance
Identity Security Maturity Model
A five-level maturity model across eight capabilities for workforce, privileged, customer, non-human and AI agent identities.
4 min read Read guide →
Guide Governance, Risk & Compliance
Identity Security Metrics and KPIs Guide
Outcome-based identity security metrics for authentication, privilege, lifecycle, NHIs and AI agents, with a board-level dashboard.
4 min read Read guide →
Guide Governance, Risk & Compliance
Identity Security Programme Guide
Structure an identity security programme across human, non-human and AI agent identities: scope, RACI, roadmap, funding and governance.
4 min read Read guide →
Regulatory Map Governance, Risk & Compliance
Identity Security Regulatory Map
Map identity controls to DORA, NIS2, the EU AI Act, GDPR, SOX, PCI DSS, HIPAA, NIST, ISO 27001 and the Essential Eight.
5 min read Read guide →
No guides match these filters.

Go deeper with NHI Mgmt Group.

NHI Ultimate Guide → NHI Foundation Level Course → NHI Breaches → Glossary → FAQ → Products → NHI & AI Podcast → Forum → Our Services →

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course