10/06/2026 | Press release | Distributed by Public on 10/06/2026 09:31
In Brief (TL;DR)Organizations spend significant time securing, rotating, and managing non-human identity (NHI) secrets such as API keys, service account credentials, and access tokens. However, the most effective way to reduce risk is to eliminate long-lived secrets wherever possible. Modern approaches such as Workload Identity Federation allow applications and services to prove their identity at runtime and receive short-lived access credentials, reducing the risk of credential theft, misuse, and privilege escalation while improving security and traceability.
For years, organizations have relied on static credentials to authenticate applications, automation tools, and cloud workloads. These secrets often end up scattered across source code, configuration files, CI/CD pipelines, and cloud environments, creating significant security risks.
The problem is simple: anyone who obtains a long-lived credential can often act as the workload it represents.
Modern cloud platforms including AWS, Microsoft Entra, and Google Cloud now support Workload Identity Federation, enabling workloads to authenticate using trusted identity assertions and obtain temporary, least-privilege credentials when needed
The best non-human identity secret is the one you never create.
Long-lived credentials increase an organization's attack surface because they:
Vaulting and rotation remain important controls, but they do not remove the fundamental risk of a reusable credential existing in the first place.
A vaulted secret is protected. A federated identity removes the secret altogether.
Workload Identity Federation replaces static credentials with trusted identity assertions. Instead of storing a permanent key, an application proves its identity to a trusted provider and receives temporary access credentials when needed.
AWS, Microsoft Entra, and Google Cloud all support this model, allowing workloads to authenticate securely without maintaining long-lived secrets. Access is issued only for the required duration and permissions, significantly reducing the risk associated with credential theft.
The workload carries proof of identity rather than a permanent key, making access more dynamic, contextual, and secure.
While federation reduces credential risk, it does not eliminate the need for governance. Organizations must carefully manage trust relationships, ensuring that only approved workloads can assume privileged identities.
Strong governance includes defining trusted identity providers, approved workloads, target permissions, session duration limits, ownership responsibilities, and review processes. Without these controls, organizations risk replacing static credential problems with poorly managed trust policies.
The shift to secretless authentication does not need to happen overnight. Organizations can start by identifying where long-lived credentials exist, prioritizing high-risk workloads, and adopting managed identities or federated authentication for new deployments.
Over time, static credentials can be retired as workloads transition to modern identity-based access models. Success should be measured not simply by the number of secrets stored in a vault, but by the reduction in standing machine authority across the environment.
The future of non-human identity security isn't rotating secrets faster. It's eliminating them wherever possible.
Workload Identity Federation represents a significant step forward for non-human identity security. By replacing static credentials with short-lived, identity-based access, organizations can reduce risk, improve traceability, and support Zero Trust security principles.
The question for security teams is no longer where secrets are stored. It's whether those secrets need to exist at all.
Ready to make AI Accountable?
Talk to an expert Explore our AI Identity Services
About the author
Field CTO at Xalient
David (DJ) Morimanno is the Field CTO at Xalient, where he helps organizations design and deliver identity-centric security strategies for complex, fast-evolving environments.