Guides
Five guides covering NHI security from category orientation through compliance, procurement, implementation, and the agentic AI frontier. Each one goes deeper on a specific topic without the vendor angle — where a guide has an opinion, it says so; where the evidence is thin, it says that too.
NHI Security vs. Secrets Managers vs. CNAPP
Secrets managers, CNAPP platforms with CIEM enabled, and dedicated NHI security tools all claim overlapping ground. This maps where they genuinely compete, where they complement each other, and where none of them reach — including the over-privileged cloud role question that CIEM and NHI platforms both claim, and the SaaS-to-SaaS OAuth gap that neither secrets management nor CNAPP typically covers.
NHI vs. Secrets Managers vs. CNAPP →
NHI Audit & Compliance Mapping
Maps NHI governance practices to the controls that actually reference them — SOC 2 CC6.1–6.3, NIST 800-53 AC-2 and IA-9, PCI DSS 4.0.1 7.2.5 and 8.6.1–8.6.3, ISO 27001:2022 A.5.17 and A.8.24, EU AI Act Articles 12/14/26, and DORA Articles 8/9/28 — corrected against common mismappings that show up in vendor materials.
NHI Audit & Compliance Mapping guide →
NHI RFP Framework
A structured framework for evaluating NHI security platforms during procurement, paired with a downloadable evaluation matrix for scoring vendors against your own requirements rather than their feature lists.
Rolling Out NHI Discovery and Governance Without Breaking Production
A phased, mechanism-first field guide to NHI discovery, ownership mapping, usage auditing, and enforcement across AWS, GCP, and Azure — covering the architectures that make each phase safe to roll out incrementally, whether assembled in-house or automated by a platform. The risk self-check routes here based on where your answers cluster.
NHI Governance Rollout guide →
OWASP Agentic AI Identity Controls
Covers the identity-specific controls from the OWASP Top 10 for Agentic Applications 2026 — ASI01 through ASI03, ASI04, ASI07, ASI09, and ASI10 — with architecture diagrams for the agent-identity attack surfaces (ASI01–03) and delegated-access drift (ASI04).
OWASP Agentic AI Identity Controls guide →
Every guide on this site is written independently — see why this site exists for more on that. No vendor relationships, sponsorships, or affiliate arrangements shape what's covered or how.