Skip to main content

NHI Inventory

The NHI Inventory (Admin → Agent Registry → Non-Human Identities) is the inventory of the machine credentials behind your AI — the API keys, service accounts, and BYOK keys that agents, MCP servers, and workloads use. It rolls up identities discovered by every Cloud AI Provider connector, scores their risk, and gives you controls to block or revoke them.

What each identity shows

  • Provider (SecureAI / OpenAI / Anthropic / Azure / GCP / AWS) and type (agent / mcp / workload).
  • Risk score (0–100) with contributing factors (see below).
  • SMLTP verdict chip (blocked / enforced / monitor) and receipt count.
  • Used-by, last-used (idle days), rotation, and an expiry countdown.
  • Status: healthy / remediation / critical.

Control levels

How much you can do to an identity depends on how it was discovered:

Which clouds are revocable

Actions

Risk scoring

The governance sweeper computes a composite 0–100 score from factors including: dormant / dormant-critical, rotation-overdue / rotation-critical, expired / expiring-soon, broad scopes, no owner, reactivated, and monitor-only. Reactivation of a previously-dormant identity raises an alert.