Skip to main content
The NHI review workflow finds non-human identities (NHIs) - service accounts, API tokens, service principals, and applications - and routes each one to its owner for review, so someone decides whether it should stay active at its current privilege level or be disabled. If the owner can’t be found, the review routes to an alternate reviewer instead.
Owners are maintained in Oleria. Configure an NHI ownership assignment workflow first, so ownership - and therefore who gets notified - stays accurate.

How this workflow is built

1

Trigger

Set a schedule for the workflow to run - for example, every day at 9:00 AM UTC.
2

Filter Records

Choose which NHI type to review - API Token, Service Account, Service Principal, or Application - then scope the review across all application instances or select specific ones. Add further filters if needed, such as Credential Type, Dormant Days, or Privilege Level.
3

Assign reviewers

The NHI’s owner is automatically the primary reviewer. Set an alternate reviewer to fall back to if the owner can’t be found, and optionally override the reviewer for specific application instances.
4

Remediation

Choose what happens if a review isn’t completed by its expiration date (7-90 days, 30 by default): Disable NHIs (recommended) disables the NHI’s active access automatically while preserving its record and audit trail, or Do not take any action leaves access as-is and just logs the decision. A reviewer can also choose to disable the NHI directly, or take no action, when they complete the review.
Remediation requires write access to be enabled for the relevant connected integrations, configured under Workspace → Integrations.
5

Send Notifications

Notify the assigned reviewer - for example, by email and Slack.

Build details

Reviewing runs

Select the Runs tab to see the workflow’s execution history - when it ran, which NHIs it found, and each reviewer’s decision.

Contact us

For questions, contact us at support@oleria.com.