Non-Human Identity Pavilion (Not streamed or recorded)
Combined Session
Wednesday, May 07, 2025 14:30—15:30
Location: A01
Wednesday, May 07, 2025 14:30—15:30
Location: A01
This panel session will provide practitioner insights and best practices on implementing a Non-Human Identity (NHI) program — from adopting a risk-based approach, to addressing key lifecycle processes for managing NHIs, and outlining logical steps to mature your organization's capabilities and processes.
This talk explores two primary use cases for Non-Human Identity (NHI): securing CI/CD pipelines and enabling federated workload identity. As machine identities become central to modern infrastructure, it's critical to secure automated systems like CI/CD, where bots and service accounts often hold overprivileged permissions. By applying strong identity management, just-in-time access, and auditability to these systems, organizations can eliminate risk associated with static credentials and standing privileges. The second use case focuses on federated workload identity—enabling services across cloud, on-prem, or hybrid environments to securely authenticate using short-lived, verifiable credentials instead of static secrets. Together, these approaches help establish a scalable and secure foundation for managing NHIs in complex, distributed environments.