What are non-human identities?
A non-human identity is a digital identity used by something other than a person to authenticate to systems, applications, data, or infrastructure.
Examples include:
- Service accounts used by applications, backups, or scheduled jobs
- Application identities, service principals, and managed identities
- Workload identities used by containers, pipelines, and automation
- API keys, tokens, certificates, and OAuth applications
- Bots and AI agents that access systems or act on a user’s behalf
Human identities usually have an employee or administrator attached to them. Non-human identities are tied to a process, application, or integration. That difference makes them easy to miss during access reviews and difficult to investigate when something goes wrong.
If an identity can authenticate, access data, call an API, or trigger an action, it belongs in your security review, even if no one calls it a “user.”