Every organization now manages more non-human identities than human employees—service accounts, API keys, CI/CD pipelines, containerized workloads, and increasingly, autonomous AI agents. Yet while we've spent decades perfecting human identity governance, non-human identities remain the enterprise's largest blind spot.
This session exposes the cascading risks when non-human identities lack proper lifecycle management. We'll examine how the software supply chain amplifies these risks: compromised build service accounts that inject malicious code, over-privileged GitHub Actions that exfiltrate source code, and AI coding assistants with standing access to production systems. Drawing on recent supply chain breaches (SolarWinds, Codecov, CircleCI), we'll demonstrate how attackers exploit the "identity chaos" in modern development pipelines.
Attendees will learn a practical framework for non-human identity governance covering credential rotation policies, just-in-time access for build systems, workload identity federation, and the emerging challenge of authenticating AI agents that write, review, and deploy code autonomously. We'll introduce the concept of "identity observability" for software pipelines and show how policy-based access control can reduce the attack surface by 70% without slowing development velocity.
Key Takeaways:
- Understand the non-human identity explosion in cloud-native and AI-augmented development
- Learn the 5-step framework for SSCS credential governance
- See real breach patterns where non-human identity failures enabled supply chain attacks
- Discover tools and standards (SPIFFE, Workload Identity, AuthZEN) that scale identity control