Weak controls, no visibility, unmanaged and stale accounts, secrets hardcoded into source.
Non-Human Identities
- No inventory of non-human identities
- Credentials embedded in source code
- Stale, unmanaged accounts persist
- Third-party OAuth grants and integrations unknown
AI Agents
- Agents deployed without registration
- Running on credentials inherited from proof-of-concept developers
- Agent population unknown and ungoverned
To Reach Level 2
- Build a first inventory of NHIs, OAuth grants and AI agents
- Find and remove secrets hardcoded in source code
- Give every critical account and agent an owner
Lifecycle stages to focus on: Continuous Discovery & Inventory · Classification & Ownership
↑ Back to the model
Policies and standards exist on paper, a partial inventory has been built, and controls and hygiene are manual. Audits are ad hoc rather than continuous.
Non-Human Identities
- Written policies and standards in place
- Partial inventory
- Manual controls and hygiene
- Ad hoc audits
- Static secrets, rotated by hand if at all
AI Agents
- Sanctioned agents roughly known; shadow agents invisible
- Agents not separated from other NHIs in the inventory
- Autonomous agents treated like batch-job service accounts
To Reach Level 3
- Complete the inventory across every platform, including OAuth grants and third-party integrations
- Tie ownership to applications, not people
- Deploy a secrets vault and scan code, CI/CD and chat for secrets
- Create a mandatory agent catalogue
Lifecycle stages to focus on: Continuous Discovery & Inventory · Posture Management · Secretless Credentials
↑ Back to the model
Governance is formally in place, inventory and ownership are established, secrets vaulting is deployed and scanning is integrated into CI/CD pipelines. Third-party OAuth grants are inventoried, with owners and reviewed scopes.
Non-Human Identities
- Formal governance framework operating
- Inventory with ownership tied to applications and services
- Secrets vaulting deployed
- Secrets scanning in CI/CD pipelines
- OAuth grants and integrations inventoried with owners
AI Agents
- Mandatory agent catalogue
- Every agent registered with its scope and purpose
- Joiner, mover, leaver processes extended to agents
- Agents without an owner do not run
To Reach Level 4
- Automate provisioning and decommissioning, with owner and expiry set at creation
- Move pipelines and cloud workloads to workload identity (no stored keys)
- Rotate any remaining secrets automatically
- Switch on monitoring and orphan-agent detection
Lifecycle stages to focus on: Provisioning & Decommissioning · Secretless Credentials · Detection & Response
↑ Back to the model
Provisioning and decommissioning are automated, workload identity replaces stored keys for cloud and CI/CD, remaining secrets are cycled without manual intervention, permissions are right-sized from actual usage, and detection with automated response is operational.
Non-Human Identities
- Automated provisioning and decommissioning
- Workload identity for cloud and CI/CD (no stored keys)
- Remaining secrets rotated without manual intervention
- Permissions right-sized from actual usage
- Detection with automated response
AI Agents
- Behaviour baselines replace static rules
- Continuous detection of orphaned agents
- Recertification triggered by model updates
- New capabilities approved before reaching production
To Reach Level 5
- Move to just-in-time, short-lived credentials everywhere (zero standing privilege)
- Make access policy-based and context-aware
- Automate response: revoke or rotate credentials the moment a leak or anomaly is confirmed
Lifecycle stages to focus on: Posture Management · Detection & Response · Preventive Controls
↑ Back to the model
Preventive controls operate by default, secretless just-in-time credentials replace static ones, no identity holds standing privilege, access is policy-based and checked at the moment of action, and security is integrated rather than bolted on.
Non-Human Identities
- Preventive controls on by default
- Secretless: just-in-time credentials replace static secrets
- Zero standing privilege
- Policy-based, context-aware access at each request
- Anomalies detected and remediated automatically
AI Agents
- Authorisation checked at the moment of action
- Credentials scoped to a single task
- Trust-chain policy enforced at every agent handoff
- Drift detected and credentials revoked automatically
To Stay at Level 5
- Keep policies and baselines tuned as agents change
- Test revocation and kill switches regularly
- Reassess as new identity types and platforms appear
Lifecycle stages to focus on: Preventive Controls · Secretless Credentials
↑ Back to the model