The Authority Population Problem: What Actually Has Power Inside Your Technology Environment?

By Shaurya J. Das — Governance Research Associate, InfraVeritas360 · 11 August 2026

Governance Research Notes · 2026
82 machine identities for every human identity in an organisation.

CyberArk's 2025 research reports this ratio. At first, it looks like an identity security number. But when we look at it from a governance point of view, there is a much bigger question behind it.

For years, identity governance has mainly been built around people. Who has access? Who has privileged access? Who approved it? When was it reviewed? Has the access been removed when somebody changed role or left the organisation? These are established governance questions.

But the technology environment is no longer operated only by people. Service accounts authenticate. APIs exchange information. Certificates establish trust. Applications talk to other applications. Workloads access cloud resources. Automation performs tasks. Third-party integrations connect different environments. And now AI agents are also becoming another part of this population.

This brings up a Foundation Layer question which I believe needs more attention. The question may no longer be only “Who has access?” We may also need to ask “What actually has authority inside the technology environment?”

The Foundation Layer Has Changed

When we talk about infrastructure visibility, we normally think about servers, storage, networks, endpoints, applications, virtual machines and cloud resources. All of this remains important. But knowing what infrastructure exists does not automatically tell us everything which can access, change, control or influence that infrastructure.

Take a production server as a simple example. The organisation may know where it is hosted, what operating system it is running, who owns it, whether it is patched and whether the required security controls are active. But the same server may also be connected with service accounts, certificates, APIs, automation tools, backup identities, monitoring platforms, administrative accounts, cloud services and external systems.

Each of these relationships may carry some level of authority. So the asset itself is only one part of the governance picture. The other part is everything which can act on that asset.

The Expanding Authority Population
From Human Access to Autonomous Digital Authority
Human
Service Account
API / Certificate
Workload
Automation
AI Agent

The governance population is moving beyond people. Authority can now sit across different human and non-human technology entities.

InfraVeritas360 Governance Research Notes · 2026
Infrastructure visibility tells us what exists. Authority visibility tells us what can act on what exists.

Machine Identity Shows the Gap

CyberArk's 2025 Identity Security Landscape research reported approximately 82 machine identities for every human identity. The same research reported that 42% of machine identities had privileged or sensitive access, while 88% of respondents said their organisation's definition of a privileged user applied only to human identities.

A separate CyberArk study on machine identity security reported that 79% of security leaders expected machine identities to increase over the following year, in some cases by as much as 150%.

These numbers are important, but I think the bigger governance issue is not the number itself. The question is whether governance has expanded at the same speed as the population it is expected to govern.

Human identities normally come with context. There is an employee, manager, department, role, joining process and eventually a leaving process. Machine identities can be different. A service account may continue after the project which created it is over. A certificate may continue after ownership has changed. An API credential may provide access without appearing in a normal employee access review.

An automation account may continue with high privilege because nobody wants to disturb a process which is working. The organisation may know that the identity exists, but that does not automatically mean it understands what authority it has, why that authority is still required or who is finally responsible for it.

Inventory and Assurance Are Not the Same

This is where I see an important difference. An identity inventory tells us what identities have been recorded. Authority Population Assurance asks something more difficult: how confident are we that we have identified the complete population which can exercise meaningful authority?

This connects directly with the Governance Denominator Problem. An organisation may have excellent control over everything it knows about. But if something important is missing from the known population, the percentage shown on the dashboard can still give an incomplete picture.

An organisation may report 100% MFA coverage for privileged users, 98% ownership of service accounts and 95% review coverage for workload identities. All three numbers may be correct. But what happens if the population used to calculate those percentages is itself incomplete?

The Denominator Question
How confident are we that everything capable of exercising authority has actually entered the governance population?

From Dependency Intelligence to Authority Intelligence

Knowing that an identity exists is useful. Knowing what depends on that identity is more useful. Knowing what authority that identity carries gives us another level of understanding.

Take a service account supporting an important business application. Governance should ideally understand whether it exists, who owns it, what service depends on it, what it can access or change and what evidence confirms that the authority is still required.

Layer Question We Should Be Able to Answer
Existence Does the identity actually exist?
Ownership Who is responsible for it?
Dependency What business or technology service depends on it?
Authority What can it access, change or execute?
Evidence Can we show that this authority is still required and controlled?

This changes the discussion from saying, “We have 14,000 service accounts” to saying, “We understand which services depend on them, who owns them, what authority they carry and whether that authority is still required.”

For me, the second statement gives much more governance confidence.

The Foundation Layer Governance Chain
From Technology Visibility to Governance Confidence
Visibility
Population
Dependency
Authority
Evidence
Governance Confidence

Governance confidence depends on the quality of the underlying visibility, population, dependency, authority and evidence.

InfraVeritas360 Governance Research Notes · 2026

AI Makes This More Important, But AI Is Not the Problem

AI agents are important in this discussion, but this is not an AI research note. The authority problem existed much before generative AI became popular. Service accounts had authority. Applications had authority. APIs had authority. Automation had authority. Cloud workloads had authority.

AI adds another layer because an AI agent may increasingly take an action rather than only authenticate or follow a fixed process. Microsoft is already introducing specific agent identities together with human sponsors and owners responsible for purpose, access and lifecycle decisions.

This tells us something important. As technology starts acting with more independence, ownership and accountability have to follow it.

The common governance question is therefore not whether an entity is human or machine. The question is whether its authority is known, owned, connected, required, controlled and evidenced.

AI is an extension of the Authority Population Problem. It is not the complete problem.

Authority Population Assurance

This leads to a research proposition which I am calling Authority Population Assurance. It is not being presented here as an established industry framework. It is a governance hypothesis which needs to be challenged and tested.

In simple terms, Authority Population Assurance is the level of confidence an organisation has that the important human and non-human entities capable of exercising authority have been identified, connected to ownership, linked with their dependencies, checked for continued requirement and supported by evidence.

The Authority Population Assurance Model
Moving from Identity Discovery to Evidence-backed Authority Assurance
KNOWN
OWNED
CONNECTED
REQUIRED
CONTROLLED
EVIDENCED

A proposed assurance model for testing whether digital authority is understood beyond a simple identity inventory.

InfraVeritas360 Governance Research Notes · 2026

What Would Validate or Disprove This Hypothesis?

This is important because a research hypothesis should not become a conclusion only because it sounds logical. It needs to be tested.

One way to test Authority Population Assurance would be to compare the identity population already known to an organisation with evidence discovered independently across infrastructure, applications, cloud environments, certificates, workloads, automation and operational dependencies.

We would then need to understand whether the additional discovery materially changes the governance denominator. Did previously unknown identities appear? Did ownership gaps appear? Were privileged relationships found outside the expected population? Did important business dependencies rely on identities whose purpose or ownership could not be clearly established?

If evidence-based discovery regularly changes the denominator in a material way, then the issue is bigger than identity administration. It becomes a governance assurance problem.

On the other hand, if existing IAM and governance processes repeatedly identify the same complete population, with ownership, dependency and authority already properly evidenced, then this hypothesis may add limited additional value. That possibility should also remain open.

Research Validation Test
The objective should not be to prove the hypothesis right. The objective should be to find out whether the evidence supports it.

Six Questions Leadership May Need to Ask

01. Do we know everything capable of authenticating, accessing or acting within our critical technology environment?

02. Can every important non-human identity be connected to an accountable owner?

03. Do we understand which business and technology services depend on these identities?

04. Can we explain why the authority given to each critical identity is still required?

05. Can we demonstrate that the authority is appropriately controlled?

06. What evidence gives us confidence that the population itself is reasonably complete?

How This Connects Back to the Foundation Layer

This is where the subject becomes much bigger than IAM or cybersecurity. Machine identity is one part of the problem. AI agents are another. The larger question is how much confidence leadership has in the actual technology environment underneath its governance reporting.

Visibility asks what actually exists. Population Assurance asks whether the known population is reasonably complete. Dependency Intelligence asks what the organisation depends on. Authority Population Assurance asks what can act on those systems and dependencies. Evidence Confidence asks whether management has enough evidence to rely on the reported position.

Dashboards can report controls. Policies can define what should happen. IAM platforms can manage identities. Security platforms can protect credentials. But governance still needs confidence that the underlying technology reality is being represented correctly.

Foundation Layer Research Proposition

InfraVeritas360 Research Hypothesis
An organisation cannot demonstrate control over digital authority until it can reasonably demonstrate what entities — human, machine or AI — are capable of exercising that authority.

This does not replace identity governance. It extends the governance question. For many years, we have been asking who has access. Perhaps we now also need to ask what has authority.

And underneath both questions sits another important question: How do we know we have found all of it?

This is where identity moves beyond only an IAM discussion and becomes part of the Foundation Layer of Technology Governance.

Perhaps the next governance denominator is not only identity. It is authority.

Evidence Base

Primary Research Sources

CyberArk — 2025 Identity Security Landscape Research
Machine identity population, privileged access and human-only privileged-user definition.
View original CyberArk research →

CyberArk — 2025 State of Machine Identity Security Report
Research on machine identity growth, discovery and security exposure.
View original CyberArk report →

Microsoft Entra — Agent Identity Governance
Microsoft guidance on AI agent identities, accountability, sponsorship, access and lifecycle governance.
View Microsoft documentation →

Research Note

External statistics and observations in this article are acknowledged to their original sources. “Authority Population Problem”, “Authority Population Assurance”, “The Authority Population Assurance Model” and their connection with the Foundation Layer are InfraVeritas360 research interpretations and hypotheses. They should not be read as terminology created, validated or endorsed by CyberArk or Microsoft.

A Note of Thanks

Research grows through questions, discussions and different perspectives.

This research is continuing to evolve through conversations, questions and different perspectives. Team InfraVeritas360 would like to thank everyone who has interacted with this work so far — through online discussions, direct conversations, personal meetings, comments, questions and independent feedback.

Every interaction is helping us look at the Foundation Layer from a different angle. Some discussions support the thinking, some question it, and some take us towards an area which we had not considered earlier. All of them have value for the research.

We will continue reaching out, sharing observations and coming back to many of you as the research develops. Thank you to everyone who has been part of this journey so far.

Suggested Citation

InfraVeritas360. “The Authority Population Problem: What Actually Has Power Inside Your Technology Environment?” Governance Research Notes, 2026.

Related Practical Assessment

This research also contributes to the thinking behind the InfraVeritas360 Foundation Layer assessment methodology. Foundation Layer Check →

Governance Research Notes (GRN)
Independent research observations on infrastructure governance, operational assurance and enterprise risk. Published by InfraVeritas 360 for practitioner and institutional reference.