Non-Person Entity
A Non-Person Entity (NPE) is a digital identity that acts in cyberspace but is not a human being. Examples generally include automated accounts, services, or systems that operate on their own rather than being directly used by a person.
A Non-Person Entity (NPE) is an entity related to information technology that has a digital identity and acts in cyberspace, but is not a human actor, per the NIST glossary definition. In practice, NPEs generally encompass digital identities not directly tied to a human user, such as service principals or automated accounts. Note that some sources describe NPE as a governance term used in certain regulatory and enterprise frameworks; specific implementation, credentialing, and identity-management requirements are out of scope here and should be verified against the applicable authoritative guidance.
Why it matters
Non-Person Entities have become a central concern in identity and access management because modern information systems increasingly rely on automated accounts, services, and system-to-system interactions that operate without direct human involvement. As defined by the NIST glossary, an NPE is an entity with a digital identity that acts in cyberspace but is not a human actor. In practice these identities can proliferate quickly, and each one represents a potential access pathway that must be governed, monitored, and secured with the same rigor applied to human users.
The governance challenge is that NPEs are frequently created to support operational needs and may then persist unmanaged, complicating efforts to maintain a complete and accurate inventory of who and what has access to a system. Some sources describe NPE as a governance term used within certain regulatory and enterprise frameworks, which underscores that the concept matters not only technically but also for accountability and oversight. Compliance officers and ISSMs should treat NPE identity management as part of broader access control and identity governance obligations rather than as a purely operational detail.
Because specific credentialing, provisioning, and identity-management requirements for NPEs vary by framework and implementation, organizations should confirm applicable obligations against current authoritative guidance rather than assuming a single uniform standard applies. Note also that no specific incident statistics or figures are asserted here; readers should verify any operational metrics against primary sources.
Who it's relevant to
Inside NPE
Common questions
Answers to the questions practitioners most commonly ask about NPE.