Back to Insights
Industry Trends·SG/NL/AE

The Ghost in the Machine Has Admin Rights

Nobody knows who gave them. Machine identities now outnumber human ones in most enterprise environments — and nobody owns them. The governance frameworks we built were designed for humans. The actors multiplying fastest are not.

Harald H.R. AgterhuisHarald H.R. Agterhuis·February 22, 2026
Contents · 4 sections+

There is a quiet crisis unfolding inside enterprise IT environments that nobody is particularly keen to discuss at the board level. Not because it's complicated — it isn't. But because it exposes something deeply uncomfortable: that the governance frameworks organisations spent the last decade building were designed for humans. And humans, it turns out, are now a minority in their own digital estates.⁠‌‌​​​​‌​‍‌​‌​‌​​‌‍​‌​‌​​‌‌‍​‌​​​‌​‌‍​‌​‌​​‌​‍​‌​​​​‌‌‍​‌​‌‌​​​‍​‌​​‌​​‌‍​​‌​‌‌‌‌‍​‌‌​​‌‌‌‍​‌‌​‌​​​‍​‌‌​‌‌‌‌‍​‌‌‌​​‌‌‍​‌‌‌​‌​​‍​​‌​‌‌​‌‍​‌‌​‌​​‌‍​‌‌​‌‌‌​‍​​‌​‌‌​‌‍​‌‌‌​‌​​‍​‌‌​‌​​​‍​‌‌​​‌​‌‍​​‌​‌‌​‌‍​‌‌​‌‌​‌‍​‌‌​​​​‌‍​‌‌​​​‌‌‍​‌‌​‌​​​‍​‌‌​‌​​‌‍​‌‌​‌‌‌​‍​‌‌​​‌​‌‍​​‌​‌‌​‌‍​‌‌​‌​​​‍​‌‌​​​​‌‍​‌‌‌​​‌‌‍​​‌​‌‌​‌‍​‌‌​​​​‌‍​‌‌​​‌​​‍​‌‌​‌‌​‌‍​‌‌​‌​​‌‍​‌‌​‌‌‌​‍​​‌​‌‌​‌‍​‌‌‌​​‌​‍​‌‌​‌​​‌‍​‌‌​​‌‌‌‍​‌‌​‌​​​‍​‌‌‌​‌​​‍​‌‌‌​​‌‌⁠

Let me paint you a picture.

Your organisation has deployed AI agents to handle customer triage. Automation bots to reconcile invoices. RPA platforms to process compliance checks. API integrations threading your cloud infrastructure together like invisible sinew. Service accounts quietly humming away, running workloads that nobody quite remembers authorising. Cloud-native applications spawning identities like rabbits in spring.

All of them have access. All of them have privileges. All of them are, in the language of identity and access management, actors.

And yet, when you ask who is responsible for the service account running your financial data pipeline at 2am on a Tuesday — you are often met with the corporate equivalent of a shrug. "It's just a system account."

No. It isn't.

I.The accountability gap nobody budgeted for

We have spent considerable energy in recent years talking about Zero Trust architecture. Least privilege. Identity-first security. Worthy ambitions, all of them. But they were conceived in a world where the identity problem was fundamentally a human problem. Rogue employees. Credential theft. Insider threats.

The new problem is structural, not behavioural. It is not that a malicious actor compromised a machine identity. It is that nobody owns it in the first place.

Machine identities — service accounts, API keys, bot credentials, agent tokens — are now proliferating faster than governance teams can track them. In many environments, non-human identities already outnumber human ones by a ratio that would alarm any risk committee unfortunate enough to be told the truth. These identities hold elevated privileges. They operate continuously. And they answer to no one.

When a human misuses access, you investigate. You have an audit trail. You have a name. You have a performance review on file and a legal team on speed dial.

When a machine identity misbehaves — or is quietly compromised, or drifts outside its intended scope, or is simply abandoned when the vendor relationship ends — you often don't know it happened. And when you do find out, the first question — who was responsible for this identity? — is frequently unanswerable.

That is not a technology failure. That is a governance failure dressed up as an IT problem.

II.Autonomous privilege is not a feature

Here is the uncomfortable framing that the industry has been slow to confront: if no human is accountable for a non-human identity, you have not automated a process. You have created autonomous privilege.

Autonomous privilege sounds rather thrilling in a sci-fi context. In an enterprise risk context, it is a liability with a very expensive tail.

The solution is not to slow down AI adoption or treat automation as inherently suspect. That ship has sailed, and frankly, it was never a realistic option for organisations competing at pace. The solution is to extend accountability frameworks to every identity in the estate — regardless of whether that identity belongs to a human or a system.

Every machine identity should have a named human custodian. Not a team. Not a department. A person. One person who can be held responsible for what that identity does, what it can access, and what happens when it is no longer needed.

Every machine identity should be registered against a configuration item. Lifecycle-managed. Policy-bound. Monitored against an accountable authority. Decommissioned when its purpose expires — not left to drift through the environment like a ghost with a valid access token.

This is not exotic. It is the same principle we apply to human identities, extended to cover the actors we have been quietly ignoring.

III.The sovereign dimension

There is a larger argument lurking beneath the operational one, and it is worth naming plainly.

At enterprise scale, unmanaged machine identity is operational risk. At national scale, it is something closer to digital sovereignty risk. As governments and regulators increasingly scrutinise AI deployment, the question of who is accountable for automated decision-making — not just who built it — is moving from philosophy seminar to regulatory requirement.

The organisations that get ahead of this will not be those with the most sophisticated AI deployments. They will be those who built accountability structures capable of governing them.

The rest will be explaining to their boards — and eventually to regulators — how a service account nobody owned managed to become a significant compliance event.

IV.What this means if you are hiring for it

From where I sit — placing technology and infrastructure leaders across Singapore, Amsterdam, and Dubai — the organisations asking the right questions are now hiring for this intersection specifically. Not pure security. Not pure IAM. But leaders who understand that identity governance in a machine-dense environment requires a fundamentally different operating model.

The CISO who can only think in human identity terms is already behind. The IAM leader who has not yet built a non-human identity programme is operating on borrowed time. And the CTO who thinks AI deployment and governance are sequential activities — first deploy, then govern — is setting up an expensive lesson.

The future is not just Zero Trust. It is accountable trust.

And accountable trust requires someone, somewhere, with their name attached to every actor in your environment. Human or otherwise.

Three Ways to Begin a Mandate.

Every engagement starts with alignment. Choose the path that matches where you are.

Confidential · 30 minutes · Partner-led · No obligation

Three candidates, every one we would hire ourselves.

Commission a Search

You know the role. You need the operator. Define what this hire needs to unlock.

Begin AI Assessment

Two weeks of precision diagnostics before committing to a search. Know what you need before you hire for it.

See the Assessment

Submit a brief without your company name. We confirm fit before any details are exchanged.

Request Partner Allocation

A confidential briefing with a resident corridor partner. No gatekeepers, no intermediaries.

Request Partner Allocation

Secure calendar allocation — cross-border mandates only.