Frontiers in Emerging Engineering & Technologies

Open Access Peer Review International
Open Access

Risk-Aware Automated Governance of Service Accounts, Workload Identities, and Machine Credentials in Cloud IAMP

4 Department of Information Science, Japan Institute of Advanced Computing, Japan
4 Department of Information Science, Japan Institute of Advanced Computing, Japan

Abstract

The rapid expansion of cloud-native architectures has increased dependence on service accounts, workload identities, application credentials, API keys, tokens, certificates, and other non-human identities (NHIs). Unlike conventional human identities, NHIs frequently operate continuously, interact programmatically with multiple services, and may possess privileges that are difficult to associate with a clearly accountable individual. Consequently, static access-control models are increasingly inadequate for environments in which identity privileges, workload behavior, and infrastructure dependencies change dynamically. This paper proposes a risk-aware automated governance framework for service accounts, workload identities, and machine credentials within cloud Identity and Access Management (IAM). The framework integrates identity discovery, contextual risk assessment, privilege analysis, lifecycle governance, credential rotation, behavioral monitoring, policy enforcement, and automated remediation. Methodologically, the study develops a conceptual governance model by synthesizing principles of automated protection and governance of non-human identities with algorithmic optimization, classification, feature-selection, and validation perspectives represented in the supplied literature. The resulting framework treats identity governance as a continuous risk-management process rather than a periodic administrative activity. The analysis indicates that risk-aware automation can reduce unmanaged credentials, constrain excessive privilege, improve credential lifecycle visibility, and enable adaptive security decisions. However, automation introduces challenges involving false positives, policy conflicts, operational disruption, explainability, and dependency on accurate identity metadata. The proposed framework therefore combines automated decisions with policy constraints, confidence thresholds, and human oversight for high-impact actions.

How to Cite

Haruto Nakamura, & Aiko Tanaka. (2026). Risk-Aware Automated Governance of Service Accounts, Workload Identities, and Machine Credentials in Cloud IAMP. Frontiers in Emerging Engineering & Technologies, 3(09), 7–13. https://doi.org/10.64917/feet/Volume03Issue09-02

References

I. Ahmad et al., ''Multi-Feature Fusion Based
Convolutional Neural Networks for EEG Epileptic Seizure Prediction in Consumer Internet of
Things'', IEEE Transactions on Consumer Electronics
A. Alqahtani et al., ''Classifying Electroencephalogram Signals Using an Innovative and Effective
Machine Learning Method Based on Chaotic Elephant Herding Optimum'', Expert Systems.
R. R. S. Alnaily
R. R. Borhade and M. S. Nagmode, ''Modified
Atom Search Optimization-based Deep Recurrent Neural Network for Epileptic Seizure Prediction Using Electroencephalogram Signals'',
Biocybernetics and Biomedical Engineering, vol.
, no. 4, pp. 1638-1653, 2020.
C. Brunner et al., ''BCI Competition 2008-Graz
data set A'', Institute for knowledge discovery
(laboratory of brain-computer interfaces), Graz
University of Technology, vol. 16, pp. 1-6, 2008.
R. Chatterjee et al., ''A Novel Machine Learning Based Feature Selection for Motor Imagery
EEG Signal Classification in Internet of Medical
Things Environment'', Future Generation Computer Systems, vol. 98, pp. 419-434.
G. Li et al., ''A Particle Swarm Optimization Improved BP Neural Network Intelligent Model for
Electrocardiogram Classification'', BMC Medical
Informatics and Decision Making, vol. 21, pp.
-15, 2021.
G. A. A. Mary et al., ''Electrocardiogram Signal
Classification in an IoT Environment Using an
Adaptive Deep Neural Networks'', Neural Computing and Applications, vol. 35, no. 21, pp.
-15342.
S. Nandy et al., ''IBoNN: Intelligent Agent-based
Internet of Medical Things Framework for Detecting Brain Response from Electroencephalography Signal Using Bag-of-neural Network'',
Future Generation Computer Systems, vol. 130,
pp. 241-252.
B. Kapoor and B. Nagpal, ''Hybrid Cuckoo Finch
Optimisation Based Machine Learning Classifier
for Seizure Prediction Using EEG Signals in IoT
Network'', Cluster Computing, vol. 27, no. 2, pp.
-2260.
P. Wang et al., ''Multi-parameter Online Optimization Algorithm of BP Neural Network Algorithm in Internet of Things Service'', Neural
Computing and Applications, vol. 33, no. 2, pp.
-515, 2021.
H. Wang et al., ''EEG_GENet: A feature-level
graph embedding method for motor imagery classification based on EEG signals'', Biocybernetics
and Biomedical Engineering, vol. 42, no. 3, pp.
-1040, 2022.
X. Wei et al., ''Inter-subject Deep Transfer Learning for Motor Imagery EEG Decoding'', in Proceedings of the 2021 10th international IEEE/
EMBS conference on neural engineering (NER),
pp. 21-24.
L. A. Yates et al., ''Cross Validation for Model Selection: A Review with Examples from Ecology'',
Ecological Monographs, vol. 93, no. 1.
S. Zhao et al., ''HybMED: A Hybrid Neural Network Training Processor with Multi-Sparsity Exploitation for Internet of Medical Things'', IEEE
Transactions on Biomedical Circuits and Systems.
Ganapathy, S. K. (2025). Automated Governance and Protection of Non-Human Identities in Cloud IAM. Frontiers in Emerging Computer Science and Information Technology, 2(02), 08–20. Retrieved from https://irjernet.com/index.php/fecsit/article/view/cloud-iam-non-human-identities