An identity hygiene checklist for people, machines and agents
NextGen Identity Security desk · 2026-07-21
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
3 min read
1. Build one inventory
List every identity: employees and contractors, service accounts, API keys and tokens, OAuth apps, and AI agents. The tools on the identity visibility page differ mainly in how many sources they read. Veza lists 325+ integrations; NewCore's Identity Discovery names Okta, AWS, Microsoft, BambooHR, Salesforce and Google; Semperis's free Purple Knight covers Active Directory, Entra ID and Okta.
2. Give every identity an owner
An identity without an owner cannot be reviewed and is rarely removed. OWASP's first non-human identity risk, improper offboarding, is what happens when service accounts and keys outlive the project or person that created them. Entro maps every non-human identity and secret to a human owner; Silverfort maps human owners for service accounts; NewCore ties each agent action to an accountable person or team.
3. Remove stale and excessive access
Start with accounts that have not been used and grants that have not been exercised. Veza detects dormant accounts and excessive privileges. NewCore's discovery flags stale grants and offers to revoke them. For Active Directory, Purple Knight grades 218+ indicators of exposure and compromise.
4. Close MFA and SSO gaps
Find people who can sign in without MFA and applications they reach without going through single sign-on. Push Security, which runs as a browser extension, surfaces login paths that bypass SSO and missing MFA. Where you can, move administrators first to phishing-resistant methods such as passkeys or FIDO2 keys.
5. Replace long-lived secrets
OWASP lists secret leakage and long-lived secrets among its top non-human identity risks. Rotate what must stay, and replace what can be replaced with credentials issued per request. CyberArk rotates and manages application secrets centrally; Aembit and NewCore issue short-lived credentials so fewer long-lived ones exist.
6. Bring AI agents in from the start
Register each new agent with an owner, a purpose and scoped access before it runs, rather than discovering it later. Okta and Silverfort both describe discovering unregistered agents, which is useful precisely because many are not registered.
7. Repeat
Hygiene decays. Run the inventory and the stale-access review on a fixed schedule, and treat every new source of identities, a new SaaS app or a new agent platform, as a trigger to run it again.
Related pages
Sources
- Veza: https://veza.com/
- NewCore: Identity Discovery: https://newcore.com/platform/identity-discovery
- Semperis Purple Knight: https://www.semperis.com/purple-knight/
- OWASP Non-Human Identities Top 10 (2025): https://owasp.org/www-project-non-human-identities-top-10/
- Entro Security: https://entro.security/
- Silverfort: non-human identity security: https://www.silverfort.com/platform/non-human-identity-security/
- NewCore: Agent Guardian: https://newcore.com/platform/agent-guardian
- Push Security: https://pushsecurity.com/
- CyberArk secrets management: https://www.cyberark.com/products/secrets-management/
- Aembit: https://aembit.io/
- Okta: Secure AI: https://www.okta.com/solutions/secure-ai/
- Silverfort: AI agent security: https://www.silverfort.com/platform/ai-agent-security