Blog
Bringing access reviews to your non-human identities
Identity and access management teams spend weeks every year certifying human access. Managers review permissions, approve them, or revoke them. It is a mature, predictable process.
But when it comes to service accounts, machine tokens, and API keys, that rigor vanishes. Most teams only review a non-human identity (NHI) when a breach happens or an auditor asks hard questions. Otherwise, tokens sit active for years without oversight. SailPoint fixes this by bringing formal certification campaigns to your non-human environments.
Applying human governance to machine scale
SailPoint takes the proven framework of Access Certification and adapts it for the complexity of machines.
Governing NHIs is inherently difficult. An API key does not have an HR profile. A service account does not map to a clear org chart. Tracking down the developer who spun up a token usually means digging through Jira or blasting questions in Slack. We replace that manual hunt with a clear, automated workflow.
How SailPoint NHI campaigns work

You do not need to review every token at once. You can define a narrow scope using custom filters, or pick from seven pre-built templates to build a targeted list:
- Orphaned: active credentials with no clear owner.
- Idle: tokens with zero recent activity.
- High-risk: credentials with extreme permissions or abnormal behavior.
- Non-expiring: keys that lack an expiration date.
- Former employee: active machine access tied to departed staff.
- Exposed: live keys that leaked publicly.
- Over-permissioned: service accounts holding privileges they never use.
Admins can clear the noise first
Before developers get involved, the IAM team or campaign admin takes action.

If a token is idle, you can disable it directly from the dashboard. If an owner is obvious, you can reassign it. SailPoint either automates the action or gives you the exact provider console link and steps to do it yourself. You resolve the easy targets before bothering the rest of the company.
Delegate the rest to the owners
The remaining identities go to the people who actually use them. Instead of forcing developers to look at a massive spreadsheet, an owner sees a narrow, targeted list of their specific NHIs, along with the admin's instructions. They know exactly what they need to review.
Log every decision
The campaign dashboard tracks progress in real time. You see what is pending, what is in progress, and what is resolved. When the campaign ends, you export a complete audit log proving exactly who reviewed what, and when.
Closing the governance gap
You already know how to govern human access. SailPoint extends that exact same rigor to the cloud environments, SaaS applications, and CI/CD pipelines where your non-human identities operate.
Explore the feature in depth on our non-human identity access reviews page.