Human, non-human and agent identities: who owns each account
ILM Reference editors · Published 2026-06-09 · 2 minute read
TRACK: BASICS · LESSON 1 OF 11
Every account needs someone who answers for it. For employees and contractors that is the person and their manager, driven by HR records. For service accounts, break-glass accounts and AI agents there is no HR record, so ownership has to be assigned by name. Accounts without an owner become orphan accounts.
Which account types does a lifecycle program cover?
| Account type | Lifecycle trigger | Owner who answers for it |
|---|---|---|
| Employee | HR system record | The person and their manager |
| Contractor or external user | Contract start and end, or a sponsor's request | The sponsor |
| Local account | Created inside the application | The application owner |
| Service account | Created by an engineer or platform | A named technical owner |
| Privileged account | Role or request for admin rights | The account holder and the system owner |
| Break-glass account | Created for emergencies | A named administrator, reviewed after each use |
| AI agent | Registered by a team or platform, or created by another agent | A named sponsor |
Why does ownership matter more than the account type?
NIST SP 800-53 control enhancement AC-2(3) asks organizations to disable accounts that are no longer associated with a user or individual. An account with a named owner can be reviewed, changed and removed. An account without one is an orphan account, whatever its type.
Non-human accounts are the growing share. Microsoft's Entra what's new page lists sponsorship lifecycle tasks for agent identities as generally available in May 2026, and Orchid Security's Identity Gap: 2026 Snapshot states that 67% of non-human accounts are created directly within applications. The AI agent identity lifecycle note covers what vendors shipped for this in 2026.
What is the one habit to build?
Add owner departure to the leaver checklist. When a person leaves, list every service account, agent and external user they own or sponsor, and assign a new owner or remove the account.
Sources
- AC-2 control text, catalog mirror
- Microsoft Learn, What's new in Microsoft Entra
- Orchid Security, Identity Gap: 2026 Snapshot
- NIST glossary, privileged account
Reviewed Sep 2026
Next lesson: SCIM provisioning basics
The standard behind most automated provisioning, and the accounts it never sees.