← Back to Knowledge CentreInsight

What your non-human identity programme doesn't cover

NHI programmes now govern service accounts, workload identities and credentials — how machines authenticate inward. Almost none govern how those same machines present outward: the phone numbers, SIP identities and sender IDs your services answer on.

The non-human identity insight was correct, and security teams were right to act on it: machine identities outnumber human ones by orders of magnitude, and for years they were the ungoverned majority of the identity estate. Mature NHI programmes now inventory service accounts, rotate credentials, govern workload identities and track certificates — how every machine authenticates to your systems.

Here is the question those programmes don't answer: your NHI programme knows every service account. Does it know every phone number your services answer on?

The same systems, facing the other way

Every service that authenticates inward through governed credentials may also present outward through communication identifiers — the telephone numbers your IVR and contact centre answer on, the SIP identities your voice platforms trunk through, the sender IDs your notifications and verification codes go out under. These are identities in every meaningful security sense: they represent your organisation to the outside world, they can be hijacked or spoofed, they accumulate silently, and someone is accountable for them whether or not anyone knows who.

Yet they sit outside the NHI perimeter — not because anyone decided that, but because of substrate. Credentials live in your infrastructure, where vaults and IAM tooling can reach them. Communication identifiers live in carrier accounts, registries and attestation systems outside your infrastructure, with lifecycles of their own — allocation, porting, attestation, sender registration — that no secrets manager has ever heard of. NHI tooling doesn't cover this surface for a defensible reason: it was never in scope. That doesn't make the surface governed. It makes it nobody's.

Why security should care about someone else's inventory

It's a fraud surface. Caller-ID spoofing, vishing and sender-ID abuse trade directly on communication identifiers whose ownership and attestation posture nobody is watching. You cannot defend the trust of numbers you cannot count.

Orphans stay live. A decommissioned service's credentials get revoked by the NHI process. Its phone numbers frequently don't — they keep answering, keep forwarding, keep costing, unmonitored. An orphaned identifier is an unwatched asset with a live connection to the public network.

Incident response hits a wall. "Who controlled this identifier on this date, and who authorised its last change?" is the same evidence question NHI programmes learned to answer for service accounts. Asked about a phone number or a sender ID, most organisations answer from spreadsheets and carrier-portal archaeology — fragments of fragments.

Machine communication is accelerating the gap. AI agents are now being issued their own numbers and SIP endpoints to place calls and send messages autonomously. The credential half of an agent's identity lands neatly in your NHI programme. The communication half — the identity it presents to the telephone network — currently lands nowhere. The blind spot is growing on exactly the frontier security is being asked about.

Adjacent disciplines, not one discipline

To be precise about the relationship: Communication Identifier Governance is not a sub-domain of NHI, and it is not a competitor to your NHI tooling — it is the adjacent discipline covering the identity surface NHI legitimately doesn't: ownership, policy, lifecycle and evidence for the identifiers your organisation presents to the communication ecosystem. The two answer the same governance questions about different halves of the machine-identity estate — one inward-facing, one outward-facing. The platform architecture shows how the outward half gets governed without replacing the carrier and platform relationships it lives in.

Three questions to ask this week

The same test that works for the rest of the estate works here, asked of whoever owns telecom: Can we count the communication identifiers our services present on — one number, from one record? Can we prove control — owner, policy, and who authorised the last change — for any of them, on demand? Who owns their governance — by name? If the answers arrive slowly, the Governance Maturity Model will tell you what stage you're looking at; in our experience, organisations mature on NHI are often at stage 1 or 2 on the communication side — the estates were built by different teams, on different timelines, and it shows.

Wondering where your own estate stands? Arrange an assessment