Orphaned Identity.
Active privilege with nobody responsible.
A non-human identity holding active privilege with no named owner. A rotation policy cannot rotate what it cannot address.
The reason this term exists.
An Orphaned Identity is a non-human with production access and no named human accountable for it. It is what happens when the engineer who created a service account leaves the company, when a contractor's project ends, or when a system was migrated but its authorization was not. Orphaned identities are the primary target of every 2026 named breach involving non-human credentials: they carry standing privileges, they are not being rotated, and no one is watching them. They are also the most measurable failure of governance: a policy that cannot enumerate its orphans is a policy on paper. Every mature NHIG program starts by resolving orphaned identities to owners.
How Arkion applies it.
The Arkion Discovery Scan surfaces every orphaned non-human identity in an environment. Each is flagged for one of three actions: reassign to a new named owner, retire and revoke, or wind down under a temporary custodian while a permanent owner ramps up. The signed audit ledger records which action was taken and by whom.
Terms that live next to this one.
For briefs, RFPs, and analyst reports.
“Orphaned Identity: A non-human identity holding active privilege with no named owner. A rotation policy cannot rotate what it cannot address.” Arkion Vocabulary, 2026. https://arkion.ai/vocabulary/orphaned-identity