Service Accounts Don’t Change Jobs. Their Owners Do.
- A service account never changes departments. An API key never receives a termination notice from HR. The people who own them do both, and the non-human identities (NHIs) they leave behind often keep running exactly as before.
Service accounts, API keys, OAuth clients, workload identities, and pipeline credentials run applications, cloud infrastructure, and CI/CD with no person at the keyboard. They also outnumber people. In a survey of 577 identity and security leaders at U.S. enterprises, commissioned by the identity governance vendor Omada, respondents reported that NHIs now outnumber human identities in most organizations, and executives were far more likely than practitioners to put the ratio at 50:1 or higher (Omada, State of Identity Governance 2026).
That scale raises a governance question: how should an NHI be governed when the people, teams, or business responsibilities behind it change?
Enterprises built Joiner-Mover-Leaver (JML) processes for people. NHIs have no equivalent lifecycle. What they do have, or should have, is an owner. By connecting each NHI to an accountable human owner and integrating that relationship with identity governance and administration (IGA), organizations can use human lifecycle events, particularly Mover events, to initiate governance actions for both human and non-human access.
Tying NHI governance to accountable owners builds on a framework Sunnykumar Kamani presented at the IEEE International Conference on AI in Cybersecurity in February 2026 for automatically identifying NHIs, mapping them to accountable owners, and certifying their access (Identity Governance in DevSecOps: Automated Access Reviews for CI/CD Pipelines). Triggering those certifications from lifecycle events, and not only from the calendar, is the next step.
The ownership gap
An NHI rarely exists without a business purpose. A service account supports an application, an API key connects two services, and a pipeline identity deploys software to production. Each should come with answers to basic governance questions. Who owns this identity? Why does it exist? What can it reach? Does it still need that access? Who reviews it?
Many organizations struggle with the first question. In CyberArk's 2025 machine identity security survey, 38% of security leaders cited identifying who controls access through a machine identity as a challenge. Omada's respondents described responsibility for NHIs as spread across security, IAM, DevOps, cloud, application, and infrastructure teams, and a small share reported no clearly defined owner at all.
Consider a DevOps engineer responsible for several service accounts and pipeline identities. When the engineer transfers to another department, the Mover process updates the engineer's manager, department, role, and personal access. It does nothing about the identities the engineer owns. They keep running, still assigned to someone whose new job has nothing to do with them, and the organization may not notice until the next scheduled certification, or later.
Ownership is the link between the human identity lifecycle and the NHI lifecycle.
Establishing ownership comes first
A lifecycle trigger can act only on relationships that already exist. Before a Mover event can route an NHI for review, the organization needs an inventory of its NHIs and an accountable owner for each one. That starts with discovery across cloud accounts, CI/CD platforms, vaults, and directories, followed by assigning owners from the evidence available: who created the identity, which application it serves, who has changed it, and who relies on what it does. Where the evidence runs out, the application owner can serve as the default owner until someone better placed accepts the role. Discovery and ownership mapping are the work Kamani's framework sets out to automate.
Ownership should also land on a named person, not only on a team. Team ownership is convenient, but a team never transfers departments, so its members' Mover events never touch the identities it owns. The pattern is already common with AI agents. In a survey of 100 security and identity leaders at Fortune 500 and Global 2000 companies conducted by SailPoint, another identity security vendor, 65% of organizations assigned AI agent ownership to entire teams rather than a specific individual, and another 17% had no clear ownership structure at all. A named owner, backed by a team for continuity, keeps the lifecycle signal intact.
The Mover event as a governance trigger
In my experience, access certification still runs on the calendar. Organizations run quarterly, semiannual, or annual campaigns in which managers and application owners decide whether existing access should remain.
Periodic certification still matters, but its timing creates a gap. Suppose an employee's access is certified at the end of a quarter, and two weeks later the employee transfers to another business unit. The business context has changed materially, and the next scheduled review may be months away.
Lifecycle-driven governance closes that gap by changing what starts the process. Rather than relying only on the calendar, organizations can let identity changes start it: a change produces a Mover event, which prompts a governance evaluation, which produces a targeted certification and an access decision.
The IGA platform detects a change in department, manager, role, or responsibility as a Mover event, then evaluates whether the change affects existing access or ownership relationships. If it does, the platform generates a targeted certification without waiting for the next enterprise-wide campaign. The Mover event stops being an administrative update and becomes a governance trigger.
Extending Mover-based reviews to non-human identities
The approach becomes particularly valuable for NHIs once they are mapped to accountable owners. Consider an application engineer responsible for several service accounts, API credentials, and CI/CD identities who transfers from the application team to another business function. An event-driven process would run in seven steps:
- The engineer's role or department changes.
- The IGA platform detects the Mover event.
- The platform identifies the engineer's affected access and the NHIs connected to the engineer through ownership or responsibility.
- It evaluates whether the ownership relationship, and the access associated with those identities, still fit the new business context.
- It triggers a targeted certification, routed to the appropriate manager, application owner, or designated reviewer.
- The reviewer retains, revokes, or reassigns the access and the ownership.
- The platform carries out the remediation and records the decision for audit.
This addresses a core NHI lifecycle challenge: the machine identity itself may never generate a lifecycle event, but a change involving its human owner can.
When the owner leaves
Movers are the subtle case. Leavers are the urgent one. When an owner leaves the organization, the Leaver process removes that person's access. The NHIs the person owned lose their only accountable human, while their own credentials remain valid.
Credentials do not retire themselves. GitGuardian, a secrets security vendor, retested credentials it had confirmed as valid after they leaked publicly in 2022, and found in January 2026 that more than 64% still worked. Those were leaked secrets, not orphaned ones, but the lesson carries over: without someone accountable for rotation and revocation, a credential can outlive everyone who remembers creating it.
The Leaver workflow should therefore handle the NHIs first. Before it removes the departing owner's access, it should require each owned NHI to be reassigned to a new accountable owner or deactivated. Reversing that order is one of the ways orphaned identities are created.
Targeted reviews instead of more reviews
Event-driven governance should not mean launching a full certification campaign after every identity change. That would create unnecessary review volume and feed certification fatigue.
The objective is to recognize material lifecycle events and scope the response to them. A minor attribute correction may require no action. A department transfer, a significant role change, a manager change, or a change in application ownership is more likely to affect whether existing access remains justified. For each event, the workflow should determine the impact, define the scope, and review and remediate only what the change touches.
Scope matters. When an employee moves between departments, the organization does not need to recertify every entitlement the person holds; the workflow can identify the access and NHI relationships most likely to be affected. Nor does the response always have to be a certification. Depending on the circumstances, it can be transferring NHI ownership, revoking access, assigning a new accountable owner, rotating a credential, requesting additional approval, or taking no action when the change does not materially affect access.
AI agents raise the stakes
AI agents are NHIs that act. A service account does what its code tells it to do; an agent decides what to do within the access it holds. That makes its owner more than an administrative contact. The owner is the person positioned to approve what the agent does and to stop it when something goes wrong.
When that owner moves to another role or leaves, the agent does not notice. It keeps working with the same access, now without anyone accountable for its behavior. The same Mover and Leaver triggers apply, and for an agent the review should cover not only what it can reach but who is now responsible for approving and stopping its actions.
Periodic and event-driven governance working together
Lifecycle-triggered certification does not eliminate the need for periodic access reviews. The two approaches complement each other. Periodic certification provides broad, recurring assurance across identities, applications, and entitlements. Event-driven certification provides responsiveness when meaningful changes occur between those scheduled reviews.
Periodic governance asks whether access remains appropriate at a scheduled point in time. Event-driven governance asks whether something that just changed affects whether access remains appropriate. Combining the two gives organizations scheduled assurance and lets identity governance respond more quickly to changing business context. For NHIs, whose lifecycle depends on relationships with people, applications, and teams, a change to any of those relationships can provide the signal needed to reassess ownership and access.
Toward continuous identity governance
The broader opportunity is to move identity governance closer to the point at which access risk changes. Traditional certification is time-aware: a review occurs because a set period has elapsed. Lifecycle-triggered certification is context-aware: a review occurs because something relevant has changed. The progression runs from periodic access reviews, to lifecycle-aware reviews, to event-driven identity governance.
Managing NHIs requires more than discovering service accounts and securing credentials. It requires knowing who is accountable for each identity and letting changes in that accountability drive access decisions. The goal is not simply to automate more access reviews. It is to use identity context to start the right governance action at the right point in the lifecycle, so that meaningful changes, not only calendar dates, determine when access is reassessed.
Sources
- CyberArk. (2025, March 13). 2025 State of Machine Identity Security Report [Infographic]. Business Wire. https://mms.businesswire.com/media/20250313883089/en/2408458/1/CyberArk_2025_State_of_Machine_Identity_Security_Report_Infographic_FINAL.pdf?download=1
- GitGuardian. (2026, March 17). The State of Secrets Sprawl 2026. GitGuardian. https://www.gitguardian.com/state-of-secrets-sprawl-report-2026
- Kamani, S. (2026, February). Identity Governance in DevSecOps: Automated Access Reviews for CI/CD Pipelines. In Proceedings of the 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC), Houston, TX, February 18–20, 2026. IEEE. https://doi.org/10.1109/ICAIC67076.2026.11395732
- Omada. (2026, February 10). The State of Identity Governance 2026. Omada. https://omadaidentity.com/resources/analyst-reports/state-of-iga/
- SailPoint. (2026). The Year of the AI Agent: How AI Agents Are Reshaping Governance, Risk, and Digital Trust. SailPoint. https://www.sailpoint.com/identity-library/year-of-ai-agent

