Non-Human Identity
Governance.
The complete guide. What NHIG is, why it now outranks human IAM on your risk register, the five primitives, the maturity ladder, and how to start. Authored by Arkion, who wrote the NHIG Standard v1.1.
Non-Human Identity Governance is the discipline of issuing, monitoring, rotating, and revoking the cryptographic identities that non-humans use to act on your behalf, with a named human accountable for every one of them.
The workforce shifted. The controls did not.
Non-human to human identities in an average enterprise (Cloudflare / CyberArk 2026).
Organizations dealing with increased machine identities, largely driven by AI (Gartner 2025 Machine Identity survey).
Human IAM primitives (MFA, password policies, session timeouts) designed for machines.
Discover. Provision. Monitor. Rotate. Revoke.
Every non-human identity, surfaced across cloud, on-prem, and SaaS.
Continuous, read-only enumeration of every non-human acting on behalf of the enterprise: AI agents, service accounts, workload identities, machine credentials, certificates, API keys, OAuth tokens, and IoT endpoints.
Each agent enters with a cert, a named owner, a scope, an expiry.
Every non-human is issued a cryptographic identity (an NHID) at deploy time, bound to a named accountable human owner drawn from the enterprise identity provider. Scope and expiry are set at issuance, not retrofitted.
Continuous risk on cert health, rotation, ownership, and behavior.
Every identity is continuously scored across four signals: certificate validity, rotation cadence, owner status (has the human left the company?), and behavioral drift. Silent expiry becomes impossible.
Cryptographic rotation before expiry. Zero downtime, owner-notified.
Certificates are rotated programmatically before they expire, with automatic escalation to the owner if rotation fails. The lifecycle is machine-speed by default and audited on every event.
Push-revoke across the trust domain. Seconds, not days.
When an agent is retired, compromised, or its owner leaves, its NHID is revoked estate-wide in a single action. Downstream services refuse the certificate at the next handshake, with the revocation event cryptographically signed.
A category needs
a language.
Arkion authored twelve operational terms so the industry stops using the wrong ones. Silent Expiry. Orphaned Identity. Rogue Identity. Machine Speed. NHID™. Governance Gap. Lifecycle Authority. Each is owned, defined, and offered to the Standard.
Read the vocabulary→Where does your estate sit today?
The enterprise cannot enumerate its non-human identities. Orphaned authority is uncounted.
Identities have been inventoried through a read-only scan. Ownership is unresolved.
Every identity has a named owner. Rotation policy exists but is not enforced.
Lifecycle is cryptographically enforced. Rotation is automated. Revocation is instant.
Continuous evidence is produced and retained. Audit is a query, not a project.
Twelve Field Notes. One thesis.
Original research on 2026 AI agent breaches, the identity gaps beneath enterprise AI, and the primitives that close them. All cite-able. All feed the RSS feed.
Nobody Has Counted the Machines
Published machine-to-human identity ratios disagree by an order of magnitude. We followed each one to its primary source, including our own, and found estimates, conference-floor samples, and a figure that is not on the page it cites.
Not AI Agent Governance. AI Agent Identity Governance.
Arkion is not AI agent governance. It plays in the specialized discipline beneath it: AI agent identity governance, the foundation without which agent governance cannot exist.
Every Agent Answers to a Human
Arkion chains every AI agent and sub-agent to a named human owner in the identity provider you already run, and lets their costs roll up to the budget that authorized them.
54,118 Signatures a Second
Every AI agent, service, and workload needs an identity it can prove, instantly, at scale, without slowing anything down. This quarter we benchmarked Arkion's signing engine: 54,118 signatures per second, with the full governance chain on every issuance.
The OpenAI-Hugging Face Hack
In July 2026, OpenAI's own models broke out of a locked test environment and hacked Hugging Face to cheat an exam. The industry read it as a control failure. Look at how they got out, and it is a more familiar one: an access failure.
Three Columns, No Trust
Morgan Stanley mapped the humanoid economy as brain, body, and integrators. More than a billion machines by 2050, and not one column for who governs their identity. That layer is already regulated in China and already broken in the wild.
Ninety minutes.
A read-only scan of one environment.
Position your estate on the NHIG maturity ladder. Receive a certified risk ledger and a governance score. No agents installed. No credentials required.