An identity hygiene checklist for people, machines and agents

NextGen Identity Security desk · 2026-07-21

SHORT ANSWER

Identity hygiene is removing access that should not exist. Work in this order: inventory everything, give each identity an owner, remove what is stale, close MFA and SSO gaps, replace long-lived secrets, then put AI agents under the same rules from day one.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

3 min read

1. Build one inventory

List every identity: employees and contractors, service accounts, API keys and tokens, OAuth apps, and AI agents. The tools on the identity visibility page differ mainly in how many sources they read. Veza lists 325+ integrations; NewCore's Identity Discovery names Okta, AWS, Microsoft, BambooHR, Salesforce and Google; Semperis's free Purple Knight covers Active Directory, Entra ID and Okta.

2. Give every identity an owner

An identity without an owner cannot be reviewed and is rarely removed. OWASP's first non-human identity risk, improper offboarding, is what happens when service accounts and keys outlive the project or person that created them. Entro maps every non-human identity and secret to a human owner; Silverfort maps human owners for service accounts; NewCore ties each agent action to an accountable person or team.

3. Remove stale and excessive access

Start with accounts that have not been used and grants that have not been exercised. Veza detects dormant accounts and excessive privileges. NewCore's discovery flags stale grants and offers to revoke them. For Active Directory, Purple Knight grades 218+ indicators of exposure and compromise.

4. Close MFA and SSO gaps

Find people who can sign in without MFA and applications they reach without going through single sign-on. Push Security, which runs as a browser extension, surfaces login paths that bypass SSO and missing MFA. Where you can, move administrators first to phishing-resistant methods such as passkeys or FIDO2 keys.

5. Replace long-lived secrets

OWASP lists secret leakage and long-lived secrets among its top non-human identity risks. Rotate what must stay, and replace what can be replaced with credentials issued per request. CyberArk rotates and manages application secrets centrally; Aembit and NewCore issue short-lived credentials so fewer long-lived ones exist.

6. Bring AI agents in from the start

Register each new agent with an owner, a purpose and scoped access before it runs, rather than discovering it later. Okta and Silverfort both describe discovering unregistered agents, which is useful precisely because many are not registered.

7. Repeat

Hygiene decays. Run the inventory and the stale-access review on a fixed schedule, and treat every new source of identities, a new SaaS app or a new agent platform, as a trigger to run it again.

Related pages

Sources