Authors: Rohit Agnihotri.
Abstract: The proliferation of agentic automation, microservice workloads, and API-first architectures has produced an identity ecosystem where non-human identities (NHIs), such as service accounts, API tokens, machine certificates, CI/CD pipeline credentials, and autonomous AI agents, now outnumber human identities by an average ratio of 45:1 in enterprise environments. Conventional perimeter-centric and even role-based access control frameworks were designed for human users operating within bounded organizational boundaries, and they are structurally ill-equipped to govern the dynamic, ephemeral, and machine-speed behavior of NHIs operating across distributed cloud and hybrid infrastructures. This article presents a comprehensive analysis of Zero Trust (ZT) principles as applied to NHI governance and agentic automation security. We synthesize the technical architecture of NHI-aware Zero Trust frameworks, evaluate empirical performance and breach cost data, systematize the principal attack vectors targeting NHIs, and propose an original Eight-Pillar ZT-NHI Governance Model. Our analysis demonstrates that fully deployed ZT frameworks with AI-driven automation reduce average breach costs from USD 5.28 million to USD 1.76 million (a 67% reduction), while identity-centric micro-segmentation reduces lateral movement success rates by 84%. We further identify critical capability gaps in current ZT deployments, particularly in the automation and orchestration pillar, and articulate a forward-looking research agenda addressing the unique governance challenges of autonomous AI agent identities.
International Journal of Science, Engineering and Technology