diff --git a/baton/active-directory.mdx b/baton/active-directory.mdx
index 00d94d5d..509a8e4b 100644
--- a/baton/active-directory.mdx
+++ b/baton/active-directory.mdx
@@ -31,6 +31,8 @@ The Active Directory connector supports [automatic account provisioning and depr
User profiles include UAC-derived state booleans, FILETIME timestamps, and configurable extension attributes — see [User profile attributes](#user-profile-attributes) under Reference.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
### Connector actions
Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the [Perform connector action](/product/admin/automations-steps-reference#perform-connector-action) automation step.
diff --git a/baton/aws.mdx b/baton/aws.mdx
index 2e6fcf87..31709dd6 100644
--- a/baton/aws.mdx
+++ b/baton/aws.mdx
@@ -36,6 +36,8 @@ The AWS connector supports [automatic account provisioning and deprovisioning](/
[This connector can sync secrets](/product/admin/inventory) and display them on the **Inventory** page.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## AWS STS web identity action
The connector exposes the global `assume_role_with_web_identity` action for
diff --git a/baton/azure-infrastructure.mdx b/baton/azure-infrastructure.mdx
index 1daeb5fd..1bd8e533 100644
--- a/baton/azure-infrastructure.mdx
+++ b/baton/azure-infrastructure.mdx
@@ -28,6 +28,8 @@ sidebarTitle: "Microsoft Azure Infrastructure"
The Microsoft Azure Infrastructure connector works optimally when connected to a tenant licensed with either Microsoft Entra ID P2 or Microsoft Entra ID Governance. Other license types are supported, but the connector is not able to provide the same level of detail in all synced information. See the instructions below about using the **Skip Entra ID P2 License Features** configuration option if you do not have one of these license types.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## Gather Azure Infrastructure credentials
Configuring the connector requires you to pass in credentials generated in Azure Infrastructure. Gather these credentials before you move on.
diff --git a/baton/capabilities.mdx b/baton/capabilities.mdx
index 1af7861b..1c6dfe92 100644
--- a/baton/capabilities.mdx
+++ b/baton/capabilities.mdx
@@ -18,7 +18,8 @@ og:description: "A quick reference for how each connector can be set up and what
= Connector supports [external ticketing](/product/admin/external-ticketing)
= Connector reports last login information
= Connector creates starter account passwords and [saves them to a vault](/product/admin/vaults/)
- = Connector detects [shadow apps](/product/admin/shadow-apps)
+ = Connector detects [shadow apps](/product/admin/shadow-apps)
+ = Connector syncs [non-human identities](/product/admin/nhi)
| Connector | Hosting | Provisioning | Other |
@@ -26,7 +27,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [15Five](/baton/fifteenfive) | | | |
| [1Password](/baton/1password) | | | |
| [7shifts](/baton/sevenshifts) | | | |
-| [Active Directory](/baton/active-directory) | | | |
+| [Active Directory](/baton/active-directory) | | | |
| [ActiveCampaign](/baton/activecampaign) | | | |
| [Adobe](/baton/adobe) | | | |
| [ADP Workforce Now](/baton/adp-workforce-now) | | | |
@@ -57,7 +58,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [AWS Bedrock AgentCore](/baton/aws-bedrock-agentcore) | | | |
| [AWS Cognito](/baton/aws-cognito) | | | |
| [AWS v1](/baton/v1/aws) | | | |
-| [AWS v2](/baton/aws) | | | |
+| [AWS v2](/baton/aws) | | | |
| [BambooHR v1](/baton/v1/bamboohr) | | | |
| [BambooHR v2](/baton/bamboohr) | | | |
| [Basecamp](/baton/basecamp) | | | |
@@ -116,7 +117,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [Crisp](/baton/crisp) | | | |
| [CrowdStrike](/baton/crowdstrike) | | | |
| [Cursor](/baton/cursor) | | | |
-| [Databricks](/baton/databricks) | | | |
+| [Databricks](/baton/databricks) | | | |
| [Datadog v1](/baton/v1/datadog) | | | |
| [Datadog v2](/baton/datadog) | | | |
| [Dayforce](/baton/dayforce) | | | |
@@ -167,7 +168,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [GitHub Enterprise](/baton/github-enterprise) | | | |
| [GitHub Enterprise Cloud](/baton/github-enterprise-cloud) | | | |
| [GitHub v1](/baton/v1/github) | | | |
-| [GitHub v2](/baton/github) | | | |
+| [GitHub v2](/baton/github) | | | |
| [GitLab v1](/baton/v1/gitlab) | | | |
| [GitLab v2](/baton/gitlab) | | | |
| [Gladly](/baton/gladly) | | | |
@@ -176,14 +177,14 @@ og:description: "A quick reference for how each connector can be set up and what
| [Google AlloyDB](/baton/alloydb) | | | |
| [Google BigQuery](/baton/google-bigquery) | | | |
| [Google Cloud Platform](/baton/v1/google-cloud-platform) | | | |
-| [Google Cloud Platform with Google Workspace](/baton/google-cloud-platform) | | | |
+| [Google Cloud Platform with Google Workspace](/baton/google-cloud-platform) | | | |
| [Google Identity Platform](/baton/google-identity-platform) | | | |
| [Google Kubernetes Engine](/baton/gke) | | | |
| [Google Looker](/baton/looker) | | | |
| [Google Workspace v1](/baton/v1/google-workspace) | | | |
-| [Google Workspace v2](/baton/google-workspace) | | | |
+| [Google Workspace v2](/baton/google-workspace) | | | |
| [Gorgias](/baton/gorgias) | | | |
-| [Grafana](/baton/grafana) | | | |
+| [Grafana](/baton/grafana) | | | |
| [Grammarly](/baton/grammarly) | | | |
| [Greenhouse](/baton/greenhouse) | | | |
| [GrowthBook](/baton/growthbook) | | | |
@@ -217,7 +218,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [JetBrains TeamCity](/baton/teamcity) | | | |
| [JetBrains YouTrack](/baton/youtrack) | | | |
| [JFrog Artifactory](/baton/artifactory) | | | |
-| [JumpCloud](/baton/jumpcloud) | | | |
+| [JumpCloud](/baton/jumpcloud) | | | |
| [Kayako](/baton/kayako) | | | |
| [Keeper](/baton/keeper) | | | |
| [Keycloak](/baton/keycloak) | | | |
@@ -246,12 +247,12 @@ og:description: "A quick reference for how each connector can be set up and what
| [Microsoft Azure](/baton/azure) | | | |
| [Microsoft Azure AD](/baton/v1/azure) | | | |
| [Microsoft Azure DevOps](/baton/azure-devops) | | | |
-| [Microsoft Azure Infrastructure](/baton/azure-infrastructure) | | | |
+| [Microsoft Azure Infrastructure](/baton/azure-infrastructure) | | | |
| [Microsoft Azure Kubernetes Service](/baton/aks) | | | |
| [Microsoft Dynamics 365 Business Central](/baton/microsoft-dynamic-365-business-central) | | | |
| [Microsoft Dynamics 365](/baton/microsoft-dynamics) | | | |
| [Microsoft Dynamics 365 - Finance & Operations](/baton/microsoft-dynamics-fo) | | | |
-| [Microsoft Entra ID](/baton/microsoft-entra) | | | |
+| [Microsoft Entra ID](/baton/microsoft-entra) | | | |
| [Microsoft Fabric](/baton/fabric) | | | |
| [Microsoft SharePoint](/baton/sharepoint) | | | |
| [Microsoft SQL Server](https://github.com/conductorone/baton-sql-server) | | | |
@@ -277,10 +278,10 @@ og:description: "A quick reference for how each connector can be set up and what
| [Okta AWS Federation](/baton/okta-aws-federation) | | | |
| [Okta CIAM Workforce](/baton/okta-ciam-workforce) | | | |
| [Okta v1](/baton/v1/okta) | | | |
-| [Okta v2](/baton/okta) | | | |
+| [Okta v2](/baton/okta) | | | |
| [OneLogin v1](/baton/v1/onelogin) | | | |
-| [OneLogin v2](/baton/onelogin) | | | |
-| [OpenAI](/baton/openai) | | | |
+| [OneLogin v2](/baton/onelogin) | | | |
+| [OpenAI](/baton/openai) | | | |
| [OpenSearch](/baton/opensearch) | | | |
| [Oracle Cloud Infrastructure](/baton/oracle-cloud-infrastructure) | | | |
| [Oracle Field Service](/baton/oracle-field-service) | | | |
@@ -342,7 +343,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [Salesforce Mulesoft](/baton/mulesoft) | | | |
| [Salesforce Tableau](/baton/tableau) | | | |
| [Salesforce v1](/baton/v1/salesforce) | | | |
-| [Salesforce v2](/baton/salesforce) | | | |
+| [Salesforce v2](/baton/salesforce) | | | |
| [Salesloft](/baton/salesloft) | | | |
| [SAP Ariba](/baton/ariba) | | | |
| [SAP Cloud Identity](/baton/sap-cloud-identity) | | | |
@@ -369,7 +370,7 @@ og:description: "A quick reference for how each connector can be set up and what
| [Smartsheet](/baton/smartsheet) | | | |
| [Snipe-IT](/baton/snipe-it) | | | |
| [Snowflake v1](/baton/v1/snowflake) | | | |
-| [Snowflake v2](/baton/snowflake) | | | |
+| [Snowflake v2](/baton/snowflake) | | | |
| [Snyk](/baton/snyk) | | | |
| [SonarQube](/baton/sonarqube) | | | |
| [Sonatype Nexus](/baton/sonatype-nexus) | | | |
diff --git a/baton/databricks.mdx b/baton/databricks.mdx
index 96e98f3e..8b9f1b70 100644
--- a/baton/databricks.mdx
+++ b/baton/databricks.mdx
@@ -18,6 +18,8 @@ sidebarTitle: "Databricks"
The Databricks connector supports [automatic account provisioning and deprovisioning](/product/admin/account-provisioning).
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## Gather Databricks credentials
Configuring the connector requires you to pass in credentials generated in Databricks. Gather these credentials before you move on.
diff --git a/baton/github.mdx b/baton/github.mdx
index aeb22b23..20180f63 100644
--- a/baton/github.mdx
+++ b/baton/github.mdx
@@ -29,6 +29,8 @@ Repository permissions that are inherited through team membership are labeled as
[This connector can sync secrets](/product/admin/inventory) and display them on the **Inventory** page.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## Gather GitHub credentials
Configuring the connector requires you to pass in credentials generated in GitHub. Gather these credentials before you move on. To set up the GitHub connector, you can choose to create a personal access token (classic), a fine-grained access token, or a GitHub app.
diff --git a/baton/google-cloud-platform.mdx b/baton/google-cloud-platform.mdx
index bbb327f8..c7ff23ec 100644
--- a/baton/google-cloud-platform.mdx
+++ b/baton/google-cloud-platform.mdx
@@ -42,6 +42,8 @@ This follows from C1 having no way to represent an IAM condition, so both provis
[This connector can sync secrets](/product/admin/inventory) and display them on the **Inventory** page.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## Gather Google Cloud Platform with Google Workspace credentials
Configuring the connector requires credentials from both Google Cloud Platform and the Google Workspace Admin console. You'll complete the following steps:
diff --git a/baton/google-workspace.mdx b/baton/google-workspace.mdx
index 2eda7dcb..f6854fc2 100644
--- a/baton/google-workspace.mdx
+++ b/baton/google-workspace.mdx
@@ -27,6 +27,8 @@ The Google Workspace connector supports [automatic account provisioning and depr
The connector also supports group creation (via the `create_group` connector action) and deletion, [continuous sync](/baton/faq#syncing), and targeted sync for accounts, groups, and roles.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
### Connector actions
Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the [Perform connector action](/product/admin/automations-steps-reference#perform-connector-action) automation step.
diff --git a/baton/grafana.mdx b/baton/grafana.mdx
index 0e1d5f54..035aa6de 100644
--- a/baton/grafana.mdx
+++ b/baton/grafana.mdx
@@ -18,6 +18,8 @@ sidebarTitle: "Grafana"
Team membership can be granted and revoked. Grafana RBAC roles that a team holds (IRM and OnCall plugin roles such as **Schedules Editor**) are synced as read-only assignments and require Grafana Cloud or Enterprise. Service accounts are synced with their organization role; they are read-only.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
**Roles are optional**
diff --git a/baton/jumpcloud.mdx b/baton/jumpcloud.mdx
index 7cf5487a..59f71cd6 100644
--- a/baton/jumpcloud.mdx
+++ b/baton/jumpcloud.mdx
@@ -19,6 +19,8 @@ This page covers the JumpCloud **connector**, which syncs and provisions access
| Applications | | |
| Roles | | |
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## Gather JumpCloud credentials
Configuring the connector requires you to pass in credentials generated in JumpCloud. Gather these credentials before you move on.
diff --git a/baton/microsoft-entra.mdx b/baton/microsoft-entra.mdx
index de8e3bbd..c8103b1b 100644
--- a/baton/microsoft-entra.mdx
+++ b/baton/microsoft-entra.mdx
@@ -55,6 +55,8 @@ The `additionalAttributes` field accepts a JSON string containing any writable [
*Due to limitations of the Microsoft Graph API and Office 365 Exchange Online API, the connector cannot provision Mail Enabled Security groups or Distribution groups using OAuth.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
### Connector actions
Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the [Perform connector action](/product/admin/automations-steps-reference#perform-connector-action) automation step.
diff --git a/baton/okta.mdx b/baton/okta.mdx
index c39f25ee..dd0a09dd 100644
--- a/baton/okta.mdx
+++ b/baton/okta.mdx
@@ -109,6 +109,8 @@ Syncing standard and custom admin roles requires a super admin token.
[This connector can sync secrets](/product/admin/inventory) and display them on the **Inventory** page.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
### Connector actions
Connector actions are custom capabilities that extend C1 automations with app-specific operations. The Okta connector's actions are reached from **two different automation steps**, and which step offers an action is determined by the action itself — you cannot choose:
diff --git a/baton/onelogin.mdx b/baton/onelogin.mdx
index cc093375..57dffa0a 100644
--- a/baton/onelogin.mdx
+++ b/baton/onelogin.mdx
@@ -27,6 +27,8 @@ This page covers the OneLogin **connector**, which syncs and provisions access d
*You can opt into syncing privilege data; this is not synced by default.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
## Gather OneLogin credentials
Configuring the connector requires you to pass in credentials generated in OneLogin. Gather these credentials before you move on.
diff --git a/baton/openai.mdx b/baton/openai.mdx
index f0c95c5e..6e91f1a4 100644
--- a/baton/openai.mdx
+++ b/baton/openai.mdx
@@ -31,6 +31,8 @@ sidebarTitle: "OpenAI"
* Organization custom roles (dynamic, fetched per organization)
* Project custom roles (dynamic, fetched per project)
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
**Group member listing requires a paid plan.** Listing group members and syncing group-inherited role grants requires a Business, Enterprise, or higher OpenAI plan. Free plan accounts will not have group membership grants synced.
diff --git a/baton/salesforce.mdx b/baton/salesforce.mdx
index 4336ebbf..1ae5aced 100644
--- a/baton/salesforce.mdx
+++ b/baton/salesforce.mdx
@@ -48,6 +48,8 @@ To add an optional field mapping in C1, use the exact Salesforce field API name
*You have the option to sync user accounts that use non-standard licenses.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
### Connector actions
Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the [Perform connector action](/product/admin/automations-steps-reference#perform-connector-action) automation step.
diff --git a/baton/snowflake.mdx b/baton/snowflake.mdx
index f4eb8d21..3fd5577a 100644
--- a/baton/snowflake.mdx
+++ b/baton/snowflake.mdx
@@ -31,6 +31,8 @@ The Snowflake connector supports [account provisioning](/product/admin/account-p
[This connector can sync secrets](/product/admin/inventory) and display them on the **Inventory** page.
+[This connector syncs non-human identities](/product/admin/nhi) and displays them on the **Identities & NHI** dashboard.
+
### Connector actions
Connector actions are custom capabilities that extend C1 automations with app-specific operations.
diff --git a/docs.json b/docs.json
index b2222664..5d9659c3 100644
--- a/docs.json
+++ b/docs.json
@@ -313,6 +313,7 @@
"pages": [
"product/admin/query",
"product/admin/inventory",
+ "product/admin/nhi",
"product/admin/external-insights",
"product/admin/findings"
]
diff --git a/images/product/assets/nhi-finding-detail.png b/images/product/assets/nhi-finding-detail.png
new file mode 100644
index 00000000..93d1c6c2
Binary files /dev/null and b/images/product/assets/nhi-finding-detail.png differ
diff --git a/images/product/assets/nhi-identities-table.png b/images/product/assets/nhi-identities-table.png
new file mode 100644
index 00000000..f4eac12b
Binary files /dev/null and b/images/product/assets/nhi-identities-table.png differ
diff --git a/product/admin/nhi.mdx b/product/admin/nhi.mdx
new file mode 100644
index 00000000..b598f025
--- /dev/null
+++ b/product/admin/nhi.mdx
@@ -0,0 +1,48 @@
+---
+title: "Non-human identities (NHI)"
+og:title: "Non-human identities (NHI)"
+og:description: "See how C1 classifies and surfaces non-human identities across your connected sources."
+description: "See how C1 classifies and surfaces non-human identities across your connected sources."
+sidebarTitle: "Non-human identities"
+---
+
+{/* Editor Refresh: 2026-09-02 */}
+
+The **Identities & NHI** dashboard gives you one place to see every identity C1 discovers across your connected sources — human and non-human alike — including a dedicated view for non-human identities (NHIs).
+
+
+**NHI capabilities are under active development.** Classification, ownership, and policy support for non-human identities will keep expanding: follow the [release notes](/product/release-notes) for updates.
+
+
+## What counts as an NHI
+
+In C1, a non-human identity (NHI) is a resource classified as one of the following:
+
+- **App registration** — for example, an Entra enterprise app, OAuth app, GitHub App, or Databricks service principal.
+- **Assumable role** — for example, an AWS IAM role or GCP workload identity.
+- **Managed identity**
+
+Service accounts, secrets, and agents are related but separate categories that C1 tracks on the same dashboard — see [Find identities across your environment](#find-identities-across-your-environment) below. They aren't classified as NHIs.
+
+## Find identities across your environment
+
+Navigate to **Identity security** > **Identities & NHI** to view the dashboard. It has a tab for each identity category C1 tracks — **Human users**, **Service**, **Secrets**, **Agents** — plus a dedicated **NHI** tab scoped to the app registrations, assumable roles, and managed identities described above.
+
+
+
+
+
+Each tab lists its identities grouped by the connected app they came from, with:
+
+- **Type and subtype** — the resource's classification (app registration, assumable role, or managed identity) alongside a more specific detail string, such as `entra.enterprise_application` or `aws.role.lambda`.
+- **Owner** — who owns the identity, if anyone. Unowned NHIs are one of the most common gaps this dashboard surfaces.
+- **Findings** — any open [findings](/product/admin/findings) tied to the identity, such as an unowned non-human identity.
+
+Search by name, or filter by app, owner, type, or **Has findings** to narrow the list down.
+
+Click an identity's finding to open its detail view, with the same evidence, remediation guidance, and activity trail described in [Findings](/product/admin/findings#work-with-a-finding).
+
+
+
+
+