# Non-human identity governance: Where SCIM fits (and where it doesn't)

DevFeed: [Non-human identity governance: Where SCIM fits (and where it doesn't)](<https://devfeed.tech/articles/non-human-identity-governance-where-scim-fits-and-where-it-doesn-t-58132.md>)

Original publisher: [Read original article](<https://workos.com/blog/non-human-identity-governance-and-scim>)

Author: WorkOS

Published: 2026-09-22T00:00:00Z

Content type: article

Language: en

Sources: [WorkOS](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [non-human-identity](<https://devfeed.tech/tags/non-human-identity.md>), [owasp-top-10](<https://devfeed.tech/tags/owasp-top-10.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This article examines governance challenges for non-human identities such as AI agents, service accounts, and API keys. It explains how SCIM can help manage their lifecycle while noting that machine identities do not follow the same onboarding and offboarding patterns as employees.

## Source excerpt

Most organizations already have more AI agents and service accounts than employees, and almost none of them are governed. Here's what SCIM can do about that, and where it stops.