Identity governance was designed around a person. Someone joins and gets access, moves teams and it changes, leaves and it's revoked, and every quarter a manager certifies the access still makes sense. The model rests on a human in the loop who can vouch for what an identity should be able to do.
Non-human identities have no such person. Service accounts, API tokens, and OAuth integrations far outnumber humans, and the workforce playbook breaks on them.
Why Attestation Becomes Theater
Machine identities are created and retired at the speed of a CI/CD pipeline, so a quarterly review never catches up. Most organizations can't say who owns half their service accounts, so recertification lands on someone with no basis to judge it, who approves it to clear the queue. And IGA governs entitlements — the access that exists on paper — while saying almost nothing about the access actually used. A token can hold a scope for years that no one has exercised or revisited.
Govern by Behavior
A behavioral model watches what each non-human identity actually does: what it touches, when, how often, which systems it talks to. A service account that has never read from finance, suddenly pulling records, stands out against that baseline, while an entitlement review would show nothing wrong. This is the same foundation that already works on people. Abnormal baselines what normal looks like for a user and flags the deviation. The principle doesn't care whether the identity has a pulse.
Machine identities never had a manager and never clock out. Governing them starts with watching how they behave.
See the latest from Abnormal's product and engineering teams.

