Non-Human Identity Software
an independent guide to NHI security software
Subscribe
Tool

What Happens When You Cut Off an Orphaned Identity?

Shadow logging vs. hard block, side by side

Phase 4 of the NHI rollout guide argues for shadow logging over an outright revocation when an orphaned identity is still making active calls — the audit trail from a scoped deny is the signal, not the block itself. This simulates both routing modes for the same traffic, so the difference shows up in the metrics instead of staying an abstract argument.

Simulation inputs

Neither input changes anything in your environment — this is a model of the tradeoff, not a live connection.

140 req/sec
Security insight coverage
100%
Induced pipeline outages
0%
Telemetry collection state
Active Auditing
Incoming Orphan Requests 140 token calls/sec
Inline Proxy Router Mode: Passive Telemetry Copy
Remediation Ledger Logging Context IP & Payload
Production Database Status: 200 OK (Passing)

The 0%/100% split on induced outages isn't a forecast for any specific environment — it's the structural point: a scoped deny that only blocks actions inconsistent with the identity's role doesn't touch the request path shown here at all, while a hard block severs it entirely regardless of whether anything downstream still depends on it.

Export this scenario. Download the selected mode, traffic volume, and resulting metrics as a PDF. Requires a free subscription.

See what's in the paid edition →