Non-Human Identity Software
an independent guide to NHI security software
Subscribe
Tool

Where Is Your Machine Identity Risk Concentrated?

A nine-question self-check

Machine identity risk is rarely spread evenly across an organization — it tends to concentrate in one or two areas, depending on how credentials are created, tracked, and managed today. These nine questions surface where that concentration is likely to be, and point to specific checks worth running and guide sections worth reading based on the answers. This is a starting point for figuring out where to look first, not a verdict on what to buy.

0 of 9 answered
Question 1 — Third-Party Credential Provisioning

When someone needs to connect an internal application to a third-party service — Stripe, SendGrid, OpenAI, and similar — what's the actual workflow for creating that credential?

Question 2 — Departing-Employee Credential Mapping

If someone who'd created several service accounts, API keys, or webhook integrations left tomorrow, how would you identify everything they created?

Question 3 — Orphaned and Idle Service Accounts

How does your organization handle service accounts or API keys that are no longer actively used but still have access?

Question 4 — Vault Coverage

Roughly what share of active credentials live in a centralized vault (HashiCorp Vault, AWS Secrets Manager, or similar) versus config files, environment variables, or code?

Question 5 — Leak Detection Timing

When a credential does end up committed to a repository in plaintext, how is that usually caught?

Question 6 — Rotation Posture

What's the current state of credential rotation for production systems?

Question 7 — Trust in Automated Enforcement

If a tool started automatically restricting access for identities it flagged as over-privileged or unused, what would need to be true before your team trusted it in production?

Question 8 — Agentic AI Visibility

How would you describe visibility into AI agents, MCP implementations, or LLM-based tools (Copilot Studio, LangChain, agent frameworks) accessing systems or data?

Question 9 — SaaS-to-SaaS OAuth Oversight

When one SaaS platform requests OAuth access to another — a marketing tool requesting access to Microsoft 365 or Salesforce, for example — what oversight exists?