BeyondTrust extends privileged access control to AI agents and service accounts
BeyondTrust has released NHI Governance, a solution on its Pathfinder platform that brings privileged access control to the service accounts, API keys, OAuth clients, workload identities, and AI agents running across enterprise environments. The company has applied that discipline to human access for over two decades, and it is now extending the same controls to a population of non-human identities that already outnumbers people in nearly every organisation while remaining largely ungoverned.
Enterprises have spent recent years building inventories of their non-human identities without gaining any hold over the standing privilege those identities carry. NHI Governance sets out to close that gap by assigning ownership, enforcing least privilege, retiring stale identities, and pulling AI agents under the same controls, with US general availability planned for Fall 2026 and other global regions to follow thereafter.
Why the privileged surface outgrew the controls guarding it
Service accounts, API keys, OAuth clients, workload identities, and AI agents now hold most of the standing privilege inside the enterprise, and they outnumber the workforce that once held it. Research from BeyondTrust Phantom Labs found that non-human identities already vastly outnumber human ones, with enterprise AI agents growing more than 460% year over year, and yet almost none are ever assigned an owner, their privileges are rarely reviewed or rightsized, and their credentials are seldom rotated or retired. Most are granted access on the day they are created and keep hold of it indefinitely.
The industry's answer has been to inventory these identities. A longer list is not a control. The danger was never that an identity exists, but the privilege it carries and everything that privilege can reach. Recent SaaS-to-SaaS software supply chain attacks have shown as much, with attackers compromising the OAuth tokens trusted between applications to gain legitimate access to data at scale, using no malware, no escalation, and no human in the loop, so that every action reads as authorised for the simple reason that it is. Discovery and visibility do nothing to halt an attack of that kind, since stopping the exfiltration depends on controls executed ahead of the incident, whether that means access already scoped down, the token already rotated, or the unused identity already retired before the attacker arrives.
The gap between seeing an identity and governing what it can reach
Marc Maiffret, Chief Technology Officer at BeyondTrust, said seeing non-human identities was only half the equation. “The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren't using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have,” he said. He added that this was not paperwork bolted onto a tool built for employee onboarding, but the work of managing non-human identities at machine scale.
NHI Governance is built to execute the non-human equivalent of joiner, mover, leaver actions in the order that reduces risk, beginning with ownership so that every identity is assigned to a person or team accountable for it and nothing runs unowned. From there it enforces least privilege by locking down the identities that hold real privilege and constraining what each one can reach, closing paths to privilege the identity was never meant to have. The stale, orphaned, and abandoned identities that make up most of the ungoverned population are then decommissioned, so the attack surface shrinks rather than expanding unchecked. AI agents, for their part, are brought under the same controls with their own credentials and their own access.
Across the identity security sector, discovery, governance, and enforcement are converging onto single platforms rather than sitting in separate tools. For more than two decades, BeyondTrust has helped organisations reduce identity-based risk by governing privileged access across their most critical systems, and it now extends that record to non-human identities. Identity Security Insights already provides visibility and intelligence across non-human identities and the privileges they hold, while Password Safe secures, manages, and rotates the credentials behind them.
NHI Governance turns that visibility and credential management into lifecycle governance that establishes ownership, enforces least privilege, and reduces identity-based risk across the enterprise. As part of the Pathfinder platform, it follows the recent introduction of AI Agent Security and unifies discovery, governance, and enforcement so that privilege is secured consistently across every identity capable of privileged action.