IAM

NHI Registry

The Non-Human Identity registry catalogs every service account, API key, machine credential, and CI/CD token across your organization. Each NHI entry tracks the owning team, creation date, last-used timestamp, expiration policy, and an automatically calculated risk score based on privilege level, age, and usage patterns.

Orphaned NHIs -- credentials with no active owner or no recent usage -- are flagged for review. The registry integrates with access review campaigns so NHIs are recertified alongside human identities.

NHI Registry screenshot

Key Configuration

  • NHI discovery sources (AD service accounts, API keys, CI tokens)
  • Ownership assignment rules
  • Orphan detection threshold (days since last use)
  • Risk score weights
All documentation Question about this? Talk to us