Join our Newsletter — 33% off our NHI Course
Maturity Model · NHI & AI governance

NHI & AI Governance Maturity Model

Five levels, from Ad hoc to Optimised, for governing non-human identities and the AI agents that now use them. Find where you are, see what good looks like, and know what to fix first.

By Lalit Choda (Mr. NHI), NHI Mgmt Group · Updated 4 October 2026

Find Your Level: Free Assessment
The five levels

The Model at a Glance

Each level covers traditional non-human identities and, below the line, what changes with agentic AI.

  1. Level 1Ad hoc
    • Weak controls
    • No visibility
    • Stale accounts
    • Secrets hardcoded

    With agentic AI
    • Agents deployed unregistered
    • Running on developer credentials
    • Agent population unknown
    See Level 1
  2. Level 2Developing
    • Policies and standards
    • Partial inventory
    • Manual controls and hygiene
    • Ad-hoc audits

    With agentic AI
    • Sanctioned agents known
    • Shadow agents invisible
    • Agents not separated from other NHIs
    See Level 2
  3. Level 3Defined
    • Governance in place
    • Inventory and ownership
    • Secrets vaulting and scanning
    • CI/CD integration

    With agentic AI
    • Agent catalogue established
    • Ownership tied to application
    • Scope documented against purpose
    • Joiner, mover, leaver covers agents
    See Level 3
  4. Level 4Managed
    • Automated provisioning
    • Workload identity
    • Secrets cycled automatically
    • Detection & response

    With agentic AI
    • Behavioural baselining
    • Orphan agent detection
    • Recertification on model update
    See Level 4
  5. Level 5Optimised
    • Preventive controls
    • Secretless JIT credentials
    • Zero standing privilege
    • Policy at point of access

    With agentic AI
    • Authorisation at point of action
    • Credentials scoped to task
    • Multi-agent trust chain policy
    • Intelligent detection, remediation & automation
    See Level 5
Click or tap any level to see what it looks like
Why it matters

Why a Maturity Model

Non-human identities (service accounts, API keys, tokens, certificates and secrets) outnumber people in most organisations, often by 50–100x. AI agents now use those same credentials to act on their own, at machine speed. Governing them is not a single project but a journey.

The NHI & AI Governance Maturity Model gives that journey a shape: five levels, each describing what good looks like for traditional non-human identities and for AI agents. Use it to benchmark where you are, agree where you need to be, and prioritise the steps in between.

  • 21%of organisations keep a real-time registry of their AI agents
  • 28%can reliably trace an AI agent’s actions
  • 84%doubt they could pass an audit of agent behaviour or access controls

Source: Cloud Security Alliance, Securing Autonomous AI Agents: survey of 285 IT and security professionals, September–October 2025 (published February 2026).

Level 1

Ad hoc

Weak controls, no visibility, unmanaged and stale accounts, secrets hardcoded into source.

Non-Human Identities

  • No inventory of non-human identities
  • Credentials embedded in source code
  • Stale, unmanaged accounts persist
  • Third-party OAuth grants and integrations unknown

AI Agents

  • Agents deployed without registration
  • Running on credentials inherited from proof-of-concept developers
  • Agent population unknown and ungoverned

To Reach Level 2

  • Build a first inventory of NHIs, OAuth grants and AI agents
  • Find and remove secrets hardcoded in source code
  • Give every critical account and agent an owner

Lifecycle stages to focus on: Continuous Discovery & Inventory · Classification & Ownership

↑ Back to the model
Level 2

Developing

Policies and standards exist on paper, a partial inventory has been built, and controls and hygiene are manual. Audits are ad hoc rather than continuous.

Non-Human Identities

  • Written policies and standards in place
  • Partial inventory
  • Manual controls and hygiene
  • Ad hoc audits
  • Static secrets, rotated by hand if at all

AI Agents

  • Sanctioned agents roughly known; shadow agents invisible
  • Agents not separated from other NHIs in the inventory
  • Autonomous agents treated like batch-job service accounts

To Reach Level 3

  • Complete the inventory across every platform, including OAuth grants and third-party integrations
  • Tie ownership to applications, not people
  • Deploy a secrets vault and scan code, CI/CD and chat for secrets
  • Create a mandatory agent catalogue

Lifecycle stages to focus on: Continuous Discovery & Inventory · Posture Management · Secretless Credentials

↑ Back to the model
Level 3

Defined

Governance is formally in place, inventory and ownership are established, secrets vaulting is deployed and scanning is integrated into CI/CD pipelines. Third-party OAuth grants are inventoried, with owners and reviewed scopes.

Non-Human Identities

  • Formal governance framework operating
  • Inventory with ownership tied to applications and services
  • Secrets vaulting deployed
  • Secrets scanning in CI/CD pipelines
  • OAuth grants and integrations inventoried with owners

AI Agents

  • Mandatory agent catalogue
  • Every agent registered with its scope and purpose
  • Joiner, mover, leaver processes extended to agents
  • Agents without an owner do not run

To Reach Level 4

  • Automate provisioning and decommissioning, with owner and expiry set at creation
  • Move pipelines and cloud workloads to workload identity (no stored keys)
  • Rotate any remaining secrets automatically
  • Switch on monitoring and orphan-agent detection

Lifecycle stages to focus on: Provisioning & Decommissioning · Secretless Credentials · Detection & Response

↑ Back to the model
Level 4

Managed

Provisioning and decommissioning are automated, workload identity replaces stored keys for cloud and CI/CD, remaining secrets are cycled without manual intervention, permissions are right-sized from actual usage, and detection with automated response is operational.

Non-Human Identities

  • Automated provisioning and decommissioning
  • Workload identity for cloud and CI/CD (no stored keys)
  • Remaining secrets rotated without manual intervention
  • Permissions right-sized from actual usage
  • Detection with automated response

AI Agents

  • Behaviour baselines replace static rules
  • Continuous detection of orphaned agents
  • Recertification triggered by model updates
  • New capabilities approved before reaching production

To Reach Level 5

  • Move to just-in-time, short-lived credentials everywhere (zero standing privilege)
  • Make access policy-based and context-aware
  • Automate response: revoke or rotate credentials the moment a leak or anomaly is confirmed

Lifecycle stages to focus on: Posture Management · Detection & Response · Preventive Controls

↑ Back to the model
Level 5

Optimised

Preventive controls operate by default, secretless just-in-time credentials replace static ones, no identity holds standing privilege, access is policy-based and checked at the moment of action, and security is integrated rather than bolted on.

Non-Human Identities

  • Preventive controls on by default
  • Secretless: just-in-time credentials replace static secrets
  • Zero standing privilege
  • Policy-based, context-aware access at each request
  • Anomalies detected and remediated automatically

AI Agents

  • Authorisation checked at the moment of action
  • Credentials scoped to a single task
  • Trust-chain policy enforced at every agent handoff
  • Drift detected and credentials revoked automatically

To Stay at Level 5

  • Keep policies and baselines tuned as agents change
  • Test revocation and kill switches regularly
  • Reassess as new identity types and platforms appear

Lifecycle stages to focus on: Preventive Controls · Secretless Credentials

↑ Back to the model
Two dimensions

Maturity Is Rarely the Same Everywhere

Assess your level across both dimensions. You may be Managed for certificates in the cloud and Ad hoc for API keys on-premises.

Type of Identity

CertificatesAPI keysTokens & OAuth grantsSecretsDirectory service accountsWorkload identitiesAI agents

Platform

Public cloudOn-premisesDatabasesMainframeSaaSThird-party applications
Putting it to work

How to Use the Model

  1. Map Your MaturityScore each identity type on each platform. Maturity is rarely the same everywhere.
  2. Weight by ExposureConsider level of privilege, access to sensitive data and closeness to production.
  3. Fix the Worst FirstStart where privilege is highest and maturity lowest.
  4. Reassess RegularlyAI agents change faster than traditional NHIs, so revisit your levels often.
FAQ

Common Questions

What is the NHI & AI Governance Maturity Model?

A five-level framework by Lalit Choda (Mr. NHI) of NHI Mgmt Group for governing non-human identities and AI agents. The levels run from Ad hoc to Developing, Defined, Managed and Optimised, and each describes the controls in place for traditional NHIs and for AI agents.

Can we be at different levels in different areas?

Yes, and most organisations are. Assess maturity across two dimensions, type of identity and platform, then focus first where privilege is highest and maturity lowest.

Why does the model cover AI agents?

AI agents are non-human identities that make their own decisions. They inherit every NHI weakness and add new ones, so each level describes what governing agents looks like alongside traditional NHIs.

Where should we start?

With an inventory. A population of identities you cannot list stays at Level 1, whatever other controls you have.

How do we find our level?

Take the free NHI & AI Governance Maturity Assessment. It takes about five minutes and emails you a report with your level, your top risks and next steps.

Find Your Level in Five Minutes

Take the free NHI & AI Governance Maturity Assessment for your level, your top risks and a tailored report by email.

Take the model with you. All five levels, for NHIs and AI agents, in a two-page PDF.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

Free PDF by email

Get the guide

Enter your details and we’ll email you a download link.

Fill in all fields marked * and tick the PDF box to continue.