elyyppa.ai

The NHI Platform Landscape: What To Buy, What To Build, And What's Still Broken

Twenty-four months ago, non-human identity governance was not a software category. Now there's $340M in funding and a dozen platforms. Here's what's actually worth buying, what to build yourself, and what's still unsolved.

The NHI Platform Landscape: What To Buy, What To Build, And What's Still Broken

Published: 2026-06-24 | Category: Cybersecurity & AI | Reading time: ~7 min | Sources cited below


Twenty-four months ago, "non-human identity governance" was not a software category. 🚫

There was no NHI security market to speak of. 💤 Some secrets management tooling 🗄️, some certificate management 📜, some privileged access management bolted onto machines 🛡️ — but no dedicated platforms built around the idea that a service account is an identity and deserves the same lifecycle treatment as a human user. 🧍‍♂️🤖

In 2026, there are over ten. 🚀

GitGuardian's 2026 NHI Security Landscape lists the major players. Cremit's RSAC 2026 field report tracks over $340 million in dedicated NHI funding. 💰 CSO Online named NHI governance one of the top five agenda items at RSAC 2026 — the first time it's had that scale of stage presence. 🎤

The category arrived. 📦 Now the question is what it actually does — and what it doesn't. 🕳️

The four layers of NHI tooling 🏗️

When you map the landscape, four distinct layers emerge. 🗺️ Each solves a different problem. 🔧 And you almost certainly need more than one. 🧩

Layer 1 — Secrets detection and posture 🔍 The starting point. 🚀 Tools like GitGuardian scan your code repositories, CI pipelines, and infrastructure-as-code for hardcoded credentials. 📝 The 2026 State of Secrets Sprawl found 28.65 million secrets added to public GitHub last year 📈 — a 34% year-on-year increase. 📊 This layer tells you what secrets exist and where they leaked. 🫠

Layer 2 — NHI lifecycle and governance platforms 🔄 This is the new layer. 🆕 Platforms like Astrix Security, Oasis Security, Entro, Clutch Security, and GitGuardian's own NHI Governance module treat NHIs as first-class identities. 🪪 They discover them 📡, map their relationships 🕸️, score their risk 🎯, manage their lifecycle 🔁, and — critically — give them owners. 👤

Layer 3 — Machine identity and certificate management 📜 The mature layer. 🏛️ Tools like Venafi, HashiCorp Vault, and the cloud-native workload identity services (AWS IAM Roles Anywhere, Azure Managed Identity, GCP Workload Identity Federation) handle the cryptographic side: certificates 🔐, keys 🗝️, and the rotation machinery that makes short-lived credentials possible. ⏳

Layer 4 — Runtime agent security 🤖 The newest layer. 🆕 And the most contested. ⚔️ Players here include Zenity, which focuses on runtime visibility and inline enforcement for AI agents. 🛡️ This is where you monitor what the agent is actually doing 🧠 — not what its IAM policy says it can do. 📋

What "comprehensive coverage" actually requires 🎯

Zenity published a sharp piece earlier this year warning that most NHI and IAM vendors claiming comprehensive agent security are actually only providing identity governance — and missing runtime visibility across deployment environments, inline enforcement, behavioural analysis, intent monitoring, and the hard boundaries that prevent destructive actions. 🛑

That's not a throwaway line. 💬 It's the central architectural decision in 2026. 🏛️

Identity governance tells you what an agent is allowed to do. ✅ Permission slips. 🎫 Runtime security tells you what an agent is actually doing. 👁️ Surveillance camera. 📹

You need both. 🤝 Because an agent with perfectly scoped permissions can still be hijacked via prompt injection 🎭, can still be told by a user to "act as a finance analyst" 🕵️, and can still change its goal at runtime in ways your provisioning-time policy never approved. 🔄

The runtime gap is the real frontier 🛸

Here's the architectural pattern emerging from the AI Agent Security Summit. 🏔️

Zenity's framing: identity alone is not enough. 🚫 An agent doesn't just carry its own identity — it inherits the permissions of every MCP server, every API integration, every tool it can call. 🧬 This is multiplicative, not additive. ✖️

So even if you perfectly scope the agent's own credential 🎯, the moment it touches an MCP server with broader access 🌐, you've lost containment. 🫥

What comprehensive runtime security actually looks like 🛡️:

  • Inline enforcement ⛔ — the ability to block an agent action before it executes, not just log it after 📝
  • Behavioural analysis 🧠 — detecting when an agent is doing something outside its normal pattern 📊
  • Intent monitoring 🎯 — tracking what the agent is trying to do, not just what credentials it's using 🪪
  • Cross-system visibility 🌐 — seeing the agent's actions across every system it touches, in one place 👁️
  • Hard boundaries 🚧 — kill switches that work regardless of what the identity says is permitted ☠️

If your NHI platform can't do all five of those, you don't have agent security. 🤖❌ You have a really fancy inventory tool. 📋

The revocation problem nobody has solved 🛑

Let me name the hardest problem in NHI governance. 🏔️

Revocation. 💀

Specifically: when an AI agent is decommissioned — when its task is done ✅, when the model is replaced 🔄, when the business process changes 📦, when the underlying API is retired ⚰️ — how do you guarantee that every credential, every token, every MCP connection, every integration permission dies with it? ☠️

The honest answer in 2026 is: most organisations can't. ❌

Agents sprawl. 🌿 They accumulate credentials over time. 📚 They get re-purposed for adjacent tasks without going through a clean decommissioning. 🔄 They get embedded in workflows that other workflows depend on. 🕸️ Pulling the credential means pulling something downstream with it. 💥

The platforms that solve this well do three things: 🛠️

1. Map dependencies before revoking 🗺️ — know what depends on this NHI before you kill it 💀 2. Issue short-lived credentials by default ⏳ — so revocation happens automatically via expiry, not via a manual ticket 🎫 3. Treat identity, intent, and lifecycle as one system 🔗 — not three separate governance workstreams 🧩

If your current stack treats them as separate workstreams, you have a 2024 architecture for a 2026 problem. 📅

How to think about buying decisions 💰

If you're a CISO 🛡️, an MSP 🖥️, or a security architect 📐 evaluating this space, here's the framework I'd use. 🧠

Step 1 — Inventory first 📋 Before you buy anything, know what you have. 👀 Most NHI platforms will do discovery for you. 🔍 Don't skip this step. 🚫

Step 2 — Match the tool to the layer 🧅 Don't expect one platform to do everything. 🎯 You'll likely need a secrets detection tool 🔍 plus a lifecycle governance platform 🔄 plus runtime agent security 🤖. Trying to consolidate prematurely means gaps. 🕳️

Step 3 — Insist on runtime, not just posture 👁️ Any vendor that only talks about discovery, inventory, and scoring is selling you 2024 architecture in a 2026 wrapper. 🎁 Demand to see runtime enforcement demos. 🎥

Step 4 — Test revocation ☠️ Ask the vendor: "Show me what happens when I revoke an active credential mid-workflow." 🎬 If their answer is "we send a webhook" 📩 or "the next rotation will pick it up" 🔄, you don't have real revocation. 🚫

Step 5 — Plan for the agent layer separately 🤖 The vendors that started in service account governance are still catching up on agent-specific runtime controls. 🏃 The vendors that started in agent runtime are still building lifecycle governance. 🏗️ Most enterprises will run two platforms in parallel for at least 18 months. 📅

What's still broken 🛠️

Even with $340 million in funding 💰 and a dozen platforms 🚀, three problems remain unsolved at the industry level. 🌍

Standards. 📏 There is no equivalent of OAuth or SAML for agent-to-agent trust. 🤝 Every vendor is inventing its own. 🛠️ MCP is a protocol for tool use 🧰, not for identity governance. 🪪 Until a standard emerges, interoperability will be painful. 😣

Ownership at scale. 📈 As agents proliferate across an enterprise 🏢, the named-owner model starts to break. 🧍‍♂️ Who's the owner of an agent that three teams use? 🤷 The lifecycle gap from the intermediate piece gets worse 📉, not better, with scale. 📊

Cross-system visibility. 🌐 An agent that touches Salesforce, Slack, GitHub, and your internal data warehouse simultaneously has no single audit trail. 🫥 Each system logs the action independently. 📋 Stitching them together is a 2026 problem nobody has elegantly solved. 🧩

The bottom line 🎯

Non-human identity governance went from zero to board-level priority in 24 months. 📈 That's not hype. 📣 That's the market responding to a real attack surface that AI agents just made 10x larger. 📐

The platforms exist. 🏗️ The patterns are known. 📚 The question for every security leader 🛡️ is no longer whether to govern NHIs as identities 🪪 — it's how fast you can get the four layers in place ⏱️ before an agent your organisation deployed last quarter becomes the entry point for a breach next quarter. 💥

The clock is running. ⏰


Sources: GitGuardian 2026 NHI Security Landscape; GitGuardian State of Secrets Sprawl 2026; Cremit RSAC 2026 NHI Field Report; CSO Online RSAC 2026 coverage; Zenity — Comprehensive Agentic AI Security; Zenity — Identity Isn't Enough: Runtime Context for AI Agents; Microsoft Secure Access Report 2026; NHIMG community analysis

Which layer of your NHI stack is currently the weakest — discovery, lifecycle, secrets, or runtime? 🤔 That answer tells you exactly where to spend the next dollar. 💷