NEWFreshservice is now a Ploy integrationSee what shipped

Non-human identity

A non-human identity (NHI) is any account or credential that acts without a person behind it (service accounts, API keys, OAuth apps, bots, and AI agents), and that holds access the same way a human does.

A non-human identity is anything that authenticates and holds entitlements without being a person: the service account a deployment pipeline runs as, the API key a script uses, the OAuth app an employee authorised three years ago, the bot in your messaging tool and, fastest-growing of all, AI agents acting on someone's behalf.

Why they are the harder half of the estate

Most organisations now have more non-human identities than employees, and the non-human ones miss every control built around people. They do not join or leave through HR, so lifecycle automation never fires. They do not sit in a team, so nobody is obviously accountable when a review asks "does this still need access?". And their credentials do not expire on an offboarding date: a key created for a project routinely outlives the project, the owner, and sometimes the company's memory that it exists.

What governing them looks like

The workable pattern is to treat NHIs as first-class identities rather than exceptions: inventory them alongside people, give every one a named human owner, scope them to least privilege, and put them through the same reviews. That is how Ploy's non-human identities page approaches it, and for the AI-agent subset, agent governance adds controls of its own.