Identity Bootstrap.
Provisioning identity before the first request.
Provisioning a governed identity at deploy time: before the first API call, before the first secret, before the first audit gap. The opposite of retroactive discovery.
The reason this term exists.
Identity Bootstrap is the corrective action at the front of the lifecycle. Instead of discovering a non-human that has been running for six months and retrofitting an owner onto it, Bootstrap issues the NHID at deploy time, binds it to an owner drawn from the identity provider, sets scope and expiry from policy, and signs an attestation event before the identity ever makes its first request. Bootstrap is what turns discovery from a recurring cleanup exercise into a maintenance function. It is also what makes governance credible: the enterprise can honestly say that every non-human currently in production entered under Bootstrap and is therefore known, owned, and revocable.
How Arkion applies it.
Arkion integrates with the CI/CD pipelines and provisioning frameworks that deploy non-humans (Kubernetes, Terraform, Helm, GitHub Actions, cloud IAM SDKs) so that Bootstrap runs invisibly at deploy time. Developers do not carry the governance burden; the platform does. The named human owner is drawn from the pipeline's authenticated user in Okta or Microsoft Entra ID.
Terms that live next to this one.
For briefs, RFPs, and analyst reports.
“Identity Bootstrap: Provisioning a governed identity at deploy time: before the first API call, before the first secret, before the first audit gap. The opposite of retroactive discovery.” Arkion Vocabulary, 2026. https://arkion.ai/vocabulary/identity-bootstrap