Governed Estate.
The complete inventory, under cryptographic control.
The inventory of non-human identities under cryptographic control: continuously scored, lifecycle-bound, and attested. The opposite of the shadow estate you already have.
The reason this term exists.
A Governed Estate is what you get when every non-human identity in the enterprise has been discovered, owned, issued a cryptographic identity, and placed under a lifecycle policy that is enforceable in code. It is the opposite of the shadow estate every organization currently has: an unknown number of service accounts, credentials sitting in secret stores nobody remembers configuring, and AI agents that were spun up by pipelines and never accounted for. The distinction matters because compliance, insurance carriers, and boards are increasingly requiring an attestable inventory. A Governed Estate is the artifact that answers those questions in a signed report. A shadow estate is what shows up in the breach post-mortem.
How Arkion applies it.
Arkion's Governed Estate view lists every NHID under management, its owner, its scope, its expiry, its last-seen behavior, and its risk score. New identities enter the estate through the Identity Bootstrap flow at deploy time. Retired identities exit through Lifecycle Authority revocation. The estate is continuously attested; audit is a query against the ledger, not a project.
Terms that live next to this one.
For briefs, RFPs, and analyst reports.
“Governed Estate: The inventory of non-human identities under cryptographic control: continuously scored, lifecycle-bound, and attested. The opposite of the shadow estate you already have.” Arkion Vocabulary, 2026. https://arkion.ai/vocabulary/governed-estate