Non-Human Identity Security

Find the machine identities you don't know you have.

Service accounts, API keys, OAuth grants, and AI agent credentials now outnumber your employees many times over — and most have no owner, no expiration, and too much access. I find them, rank the risk, and help you fix the worst ones in weeks, not quarters.

OktaMicrosoft Entra IDActive DirectoryGoogle WorkspaceCompTIA Security+
10:1

Non-human identities to humans in a typical cloud-native organization.

12%

of organizations feel highly confident they can prevent an attack through an NHI.

1 key

That's all it takes. A leaked token walks right past every MFA prompt you've deployed.

The problem

Your identity program was built for people.
Your attack surface isn't.

You've invested in SSO, MFA, and access reviews for employees. Meanwhile, the identities doing most of the work in your environment never log in, never get reviewed, and never leave.

01 / sprawl

No inventory

Can your team list every service account, API key, and integration in your tenant — and who owns each one? Most can't.

02 / privilege

Standing, over-scoped access

Long-lived tokens with admin-level scopes are the fastest path for lateral movement after a single leak.

03 / orphans

Owners leave. Credentials don't.

Offboarding removes the person. Their OAuth grants, scripts, and automation accounts quietly keep running.

04 / audit

Audit and insurance questions

SOC 2, ISO 27001, and cyber-insurance questionnaires increasingly ask how machine access is governed. "We're not sure" isn't an answer.

05 / AI agents

The AI agent explosion

Every copilot, agent, and automation your teams adopt mints new credentials. Few organizations track them at all.

06 / third parties

Risky OAuth grants

Users click "Allow" on third-party apps every day, granting mail, file, and directory access to vendors nobody vetted.

Services

Fixed scope. Fixed price. Clear outcomes.

Start with an assessment. Every engagement ends with something you can act on — not a slide deck of generic best practices.

STEP 01 — START HERE

NHI Discovery & Risk Assessment

From $4,000
1–2 weeks · read-only access

A complete inventory of your non-human identities, ranked by real risk.

  • Service accounts, API tokens, and app integrations across your identity provider
  • Third-party OAuth grants in Microsoft 365 / Google Workspace
  • Orphaned, stale, and over-privileged identities flagged
  • Executive summary + prioritized remediation roadmap
Request an assessment
STEP 02

Remediation Sprint

From $8,000
4–8 weeks

Work through the roadmap and close the highest-risk gaps.

  • Decommission orphaned accounts and stale credentials
  • Rotate and vault secrets; scope down to least privilege
  • Assign owners and expiration policies
  • A repeatable process for creating new NHIs safely
Talk about remediation
STEP 03

Governance Retainer

From $2,000 / month
Ongoing

Keep the gains from eroding as new integrations and AI agents appear.

  • Quarterly re-assessment and drift report
  • Review of new integrations before they go live
  • SOC 2 / ISO 27001 evidence support
  • Direct line to an identity specialist
Discuss a retainer

Founding client pricing: I'm taking on a small number of first assessments at a reduced rate in exchange for a testimonial and an anonymized case study. Ask about it on our call.

01

Discovery call

20 minutes. We talk through your stack, your audit timeline, and what's worrying you.

02

Scoped access

Read-only API access to agreed systems, under NDA. Nothing changes in your environment.

03

Scan & analysis

Automated discovery plus manual review. Every finding is verified by a person, not just a script.

04

Readout

A walkthrough with your team: what we found, what it means, and what to fix first.

OktaMicrosoft Entra IDActive DirectoryMicrosoft 365Google WorkspaceOAuth / third-party appsService accountsAPI tokensAI agent credentials
About

I build the foundations everything else depends on.

I'm Michael Yee. For the last four years I've worked hands-on in enterprise identity and IT at a cybersecurity company — administering Okta, Microsoft Entra ID, Active Directory, and Google Workspace, alongside device management and network infrastructure. Identity is the layer every other system trusts, so that's where I've chosen to specialize.

Working inside identity platforms every day, I kept seeing the same blind spot: organizations govern their people carefully, while the service accounts, tokens, and integrations behind the scenes pile up quietly — unowned and over-privileged. So I built nhi-scanner, a Python tool for discovering and risk-ranking non-human identities, and started BuildWithYee to help companies close that gap.

You'll work with me directly — no hand-off to a junior team. My approach is practical: verify every finding, explain it in plain language, and leave you with a process your team can run without me.

Hands-on, not theoreticalReal admin experience in the platforms I assess.
Read-only by defaultAssessments never change your environment.
Plain-language findingsWritten for both engineers and leadership.
Built to hand offProcesses your team can own long-term.
FAQ

Common questions

What exactly is a "non-human identity"?

Any identity that isn't a person: service accounts, API keys and tokens, OAuth app grants, workload identities, certificates, bots, and AI agents. They authenticate and hold permissions just like employees do — but usually without MFA, reviews, or an offboarding process.

Who is this for?

Companies of roughly 100–1,000 employees running Okta or Microsoft Entra ID — especially those preparing for SOC 2 or ISO 27001, renewing cyber insurance, adopting AI tools quickly, or operating without a dedicated identity team.

Do you need admin access to our systems?

No. Assessments use read-only API access, scoped to the systems we agree on, under a mutual NDA. Nothing in your environment is modified during an assessment.

We already bought an NHI security tool. Do we still need this?

Tools are great at surfacing findings; the hard part is deciding what matters, assigning ownership, and actually remediating. I can work alongside the platform you already have and help you operationalize it.

How quickly can we start?

Usually within one to two weeks of a discovery call. Assessments take one to two weeks from the time access is granted.

Get started

Do you know who owns every service account in your tenant?

If that question makes anyone on your team wince, let's talk. A 20-minute call, no pitch deck — just an honest look at where your machine identity risk probably sits.