ARKION
§ Vocabulary/ vi. Governed Estate

Governed Estate.

The complete inventory, under cryptographic control.

Definition

The inventory of non-human identities under cryptographic control: continuously scored, lifecycle-bound, and attested. The opposite of the shadow estate you already have.

§ 01 · Why it matters

The reason this term exists.

A Governed Estate is what you get when every non-human identity in the enterprise has been discovered, owned, issued a cryptographic identity, and placed under a lifecycle policy that is enforceable in code. It is the opposite of the shadow estate every organization currently has: an unknown number of service accounts, credentials sitting in secret stores nobody remembers configuring, and AI agents that were spun up by pipelines and never accounted for. The distinction matters because compliance, insurance carriers, and boards are increasingly requiring an attestable inventory. A Governed Estate is the artifact that answers those questions in a signed report. A shadow estate is what shows up in the breach post-mortem.

§ 02 · In practice

How Arkion applies it.

Arkion's Governed Estate view lists every NHID under management, its owner, its scope, its expiry, its last-seen behavior, and its risk score. New identities enter the estate through the Identity Bootstrap flow at deploy time. Retired identities exit through Lifecycle Authority revocation. The estate is continuously attested; audit is a query against the ledger, not a project.

§ 04 · Cite this term

For briefs, RFPs, and analyst reports.

Governed Estate: The inventory of non-human identities under cryptographic control: continuously scored, lifecycle-bound, and attested. The opposite of the shadow estate you already have.” Arkion Vocabulary, 2026. https://arkion.ai/vocabulary/governed-estate