Agent identity & access

GitGuardian NHI Governance

GitGuardian's module for non-human identity secrets: the ggscout collector inventories secrets and metadata from secrets managers, CI and infrastructure, tracks consumers, rotation dates and permissions, and flags stale or over-privileged credentials. It governs credentials used by machines and agents rather than issuing agent identities.

commercial · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Agent identity & access · Agent discovery & inventory · Data governance & privacy

Useful conversation with: Security engineer, Platform engineer, IAM manager.

Ask for a demonstration

Show me every secret outside our vaults, who consumes it, when it was last rotated, and the semi-automated rotation workflow for an over-privileged NHI secret.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

NHI Governance uses the ggscout collector to inventory secrets and metadata from secrets managers, CI and infrastructure sources, and analyses the permissions and policies associated with discovered credentials.

Limit: Documentation does not state discovery latency or completeness guarantees; no policy enforcement capability is documented.

Source s2

Vendor claim

The product tracks consumers, rotation dates and permission levels, detects stale, unused and over-privileged secrets, and semi-automates rotation.

Limit: Rotation is described as semi-automated; supported target systems are not enumerated on the page.

Source s1

Limitations to discuss

Sources

  1. NHI Governance - NHI Security Solution for Enterprise · GitGuardian · official product
    Access date reported by researcher: 2026-09-06
  2. Integrate your NHI sources | GitGuardian documentation · GitGuardian · official docs
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction