IAM
NHI Registry
The Non-Human Identity registry catalogs every service account, API key, machine credential, and CI/CD token across your organization. Each NHI entry tracks the owning team, creation date, last-used timestamp, expiration policy, and an automatically calculated risk score based on privilege level, age, and usage patterns.
Orphaned NHIs -- credentials with no active owner or no recent usage -- are flagged for review. The registry integrates with access review campaigns so NHIs are recertified alongside human identities.
Key Configuration
- NHI discovery sources (AD service accounts, API keys, CI tokens)
- Ownership assignment rules
- Orphan detection threshold (days since last use)
- Risk score weights