← Identity Fabric
Grayskull Technology · Lab Identity Governance Fabric · 2 / 5

Ownership & category model

what you'll learn: the classes of identity, who owns each, and why manager ≠ owner ≠ delivers
The core mental model

HRIS governs humans. Every non-human identity is owned by a human and tied to the service it delivers. Three relationships the org chart wrongly collapses into one pointer: manager (super_ref, people only), owner (accountable human, for every NHI), and delivers (the service). Agents add a fourth — on-behalf-of a human sponsor.

The classes

ClassExampleSystem of recordOwnerOrg-chart nodeTies toLifecycle trigger
Human workergary.townsendHRIS-Liteselfyes (super_ref)employment
Elevatedt0/t1/t2-gtown.admlinked to human (IGA/PAM)the humanno — linkedparent human + tiercascades from human
Break-glassbreak-glass-lab.admIGA/PAMrole + sponsornoprotected roledormant · audited
Service accountsvc-duoauthproxyNHI registry (taxonomy.psd1)human owner + backupnoService (CMDB) + CIsthe service, not the owner
Service principalMSOL_…NHI registryintegration ownernointegration / app CIthe integration
Agent / agenticautomation · claude-codeNHI registry (Duo agent)on-behalf-of humannohuman sponsor + service + scopethe human (re-own/retire)

Topology

Identity ownership and category topology
Where each class lives, who owns it, and the downstream governance pipeline (IGA governs it; a leaver cascades to elevated + orphan-detects owned NHIs).

Where it doesn't live

Non-human identities are not Workers. HRIS's population is people; the NHI registry (taxonomy.psd1) holds service accounts, principals, and agents, each carrying a pointer to its accountable human owner. This is the same split Cisco Identity Intelligence is becoming — Oort for humans, Astrix for non-human — with BloodHound Enterprise adding the attack-path view (which owned identities are a path to your T0 tier / Tier Zero). More on the agentic AI page.

And where does the secret live? Not with the identity. The NHI registry governs the service account; its credential is vaulted in 1Password — humans check out break-glass the CyberArk PVWA way, machines fetch their own secret via 1Password Connect the CCP way. Identity and secret are governed together, stored apart — see the architecture page.

← Prev: The identity fabric Hub Next: Lifecycle & JML →