Rogue Identity.
Operating outside governance. Deniable. Damaging.
A non-human operating outside governance: no certificate binding, no rotation schedule, no revocation path. Present in every enterprise. Visible in none of them until the inventory is honest.
The reason this term exists.
A Rogue Identity is one step past orphaned: no certificate binding, no rotation schedule, no revocation path, and often no visibility. Rogue identities are what show up in supply-chain compromises, insider-abuse investigations, and the aftermath of a poorly-managed migration. They may have been deliberately created to bypass IAM. They may be leftovers from an old vendor integration. They may be an attacker's foothold. The point is: an enterprise that cannot enumerate its non-human identities cannot distinguish between a legitimate service account and a rogue one. Every 2026 breach analyzed in the Arkion Field Notes eventually hinges on a rogue identity that had no owner and no oversight.
How Arkion applies it.
Rogue Identities are refused at runtime by an Arkion-governed estate: their certificate is not signed by the estate's authority, their identity does not resolve to a named human, and the audit ledger has no attestation event. When Arkion detects an identity acting inside the estate without governance, it is quarantined and the security team is alerted.
Terms that live next to this one.
For briefs, RFPs, and analyst reports.
“Rogue Identity: A non-human operating outside governance: no certificate binding, no rotation schedule, no revocation path. Present in every enterprise. Visible in none of them until the inventory is honest.” Arkion Vocabulary, 2026. https://arkion.ai/vocabulary/rogue-identity