COMMENTARY: A few years ago, I sat in on a board presentation from a CISO who took identity seriously. The company had MFA, quarterly recertifications, and could explain exactly what each employee could access and why.
Then an informed board member asked how many
non-human identities were in their environment, and nobody had a precise number. Their identity program had been built around people while
machine identities multiplied quietly in the background.
According to the
Non-Human Identity Management Group, machine identities now outnumber human users by as much as 50 to 1, with some research putting the ratio even higher. Service accounts created for automations that shipped years ago. API keys tied to integrations nobody owns anymore. Credentials generated by someone who has since changed roles or left. Most never go through the lifecycle controls identity programs were designed to enforce because those programs were never designed with machine identities in mind.
[
SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]
What one forgotten token can do
In August 2025,
a threat actor tracked as UNC6395 obtained an OAuth token associated with
Salesloft's Drift chat integration and used it to move through Salesforce environments across hundreds of organizations. The token was trusted, so the activity looked normal throughout. From there, the attacker reached AWS keys, Snowflake tokens, and credentials stored in records because someone had put them there for convenience. Each trusted identity became a doorway to the next.
The token was dangerous not because it was unusual, but because nobody had a reason to look at it again. For a SOC team, that is the signal worth building for: trusted machine identities generating access patterns that would trigger review if a person produced them, but don't because the identity has always been there and always been quiet.
Related reading:
The questions that followed, why it carried that much privilege and why the lateral movement went undetected, weren't only for Salesloft's security team. Our
2026 Data and Identity Security Report found a 43% breach rate among organizations where AI had significantly expanded identity counts, compared with 11% among organizations where it hadn't. Organizations with higher breach rates also reported stronger governance fundamentals than their peers. They were more likely to monitor shadow AI, maintain continuous visibility into sensitive data, and govern non-human identities. Confidence in a security program is exactly what keeps a trusted, forgotten identity off the radar.
Questions every security team should answer
I've spent my career in and around identity, and it was at the center of nearly every incident my teams investigated. Machine identities present the same problem with less visibility and fewer owners, and nothing about them triggers a natural review.
When I assess an environment, the first thing I want to know is whether anyone has a current picture of what's actually there. An inventory generated once a year for an audit doesn't count. Credentials appear constantly, usually without anyone filing paperwork, and a view that's six months old is already wrong.
The second question is ownership. Does each identity have a defined purpose and someone responsible for it? Are credentials being rotated? For most organizations the honest answer is no, or at least not consistently, and an identity without an owner is one nobody will notice when it starts behaving differently.
The third is what happens at the end. When a project closes or someone leaves, does the associated access disappear automatically, or does it depend on somebody remembering? Processes that depend on memory are not controls. NIST CSF 2.0's Identity Management function asks these same questions. Most organizations can answer them for people. Few can answer them for machines.
AI agents accelerate an unsolved problem
An AI agent is just another identity, but one that moves faster than a person, requests and inherits permissions through automated workflows, and can create downstream identities without anyone stopping to review the access being granted. Our
2026 report found that 70% of organizations grant AI systems broader access than they would a person performing the same job, and fewer than half have any policy governing agents.
The Drift token had always been trusted and nobody had a reason to look at it again. Organizations are now deploying agents with that same inherited trust before they have solved the underlying machine identity problem. A governed machine identity program produces a current inventory with defined owners, documented access scope, rotation schedules, and automated deprovisioning when the associated system or project closes. Most programs produce none of that for machines.
Who owns the decision
When an ungoverned identity contributes to a breach, accountability gets difficult to trace. For a service account with a defined owner, there is usually a trail. For an agent operating at machine speed, requesting permissions, creating downstream identities, and interacting across systems, the line back to the person who originally approved the access decision is often gone before anyone thinks to look. Under GDPR's accountability principle and SOX's access control requirements, that gap is an audit finding, not just an operational problem.
Most organizations deprioritized these questions when machine identities seemed like a manageable edge case rather than the fastest-growing population in the environment. Who owns each identity, what it can reach, and when it should stop existing — those questions have always mattered. The Drift token was always there, trusted and unreviewed, until it wasn't.