The rise of Non-Human Identities (NHIs)
Blog post from Doppler
Non-human identities, including service accounts, application credentials, workloads, automation, and AI agents, now outnumber human identities by roughly 144 to 1, creating governance challenges that conventional employee-focused identity systems cannot address. Unlike human accounts, these identities are created dynamically, often lack clear owners or business context, and can persist after their associated workloads have changed or ended, making manual reviews and static inventories insufficient. The discussion argues that effective governance requires lifecycle controls that establish an identity’s purpose, accountable owner, least-privilege access, expiration, monitoring, credential rotation, and rapid revocation capability. It recommends prioritizing high-risk identities with production or sensitive-system access, treating credential creation as a security event, migrating long-lived static secrets into managed systems, and using short-lived or dynamic credentials where possible. Secrets-management platforms can support these practices by centralizing credential distribution, enforcing workload-specific access, automating rotation, recording activity, and enabling swift revocation during incidents.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 8 | 1,985 | 445 | 125 | -23% |
| AI Agents | 3 | 5,422 | 1,164 | 237 | -21% |
| MCP | 2 | 8,107 | 809 | 199 | -26% |
| Platform Engineering | 1 | 1,090 | 244 | 75 | -24% |
| Zero Trust | 1 | 194 | 58 | 26 | -23% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.