> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Non-human identities

> Inventory, investigate, and contain provider-native machine identities.

Forge brings cloud and repository machine identities into one inventory while
preserving their provider-native identity. Open **Identities → NHIs** to review
service accounts, IAM roles and users, applications, managed identities,
repository credentials, and other supported non-human principals.

## What Forge shows

Each record can include its provider and account scope, native type, status,
credential posture, activity, AI relationships, ownership evidence, access,
and the source connection that produced the record. Missing evidence is shown
as unavailable rather than inferred.

Provider actors and contacts are attribution leads. Forge reports an
accountable human owner only when the provider record joins to accepted
directory, SCIM, email, or person evidence. Bots, applications, deleted users,
and login-only records remain machine or unresolved identities.

## Inventory and evidence coverage

Inventory is collected from each connected AWS account, Azure tenant and
subscription, Google Cloud project, and GitHub organization. A sync can be
complete, partial, stale, permission-blocked, or failed for an individual
evidence family. Other successfully collected identities remain available when
one provider surface is incomplete.

Use the evidence section in an identity drawer to distinguish current provider
state from historical activity, accountable ownership from a provider contact,
direct grants from inherited access, and an empty result from a permission or
retention gap.

## Native actions

Supported identities can expose provider-native actions such as revoke or
disable. An inventory connection never authorizes those actions by itself.
Forge enables an action only when a separate operator connection is healthy and
the server has an exact target, current before-state, expected provider effect,
and independent readback plan.

Previewing an action does not change provider state. Execution creates a
durable operation and preserves provider acceptance, execution, readback,
residual access, and completion as separate facts. If readback cannot prove the
expected state, Forge reports the operation as pending or unproven rather than
successful.

<Warning>
  Disabling a principal or credential may prevent new authentication without
  ending previously issued sessions or tokens. Review the residual-access result
  before treating containment as complete.
</Warning>

## Troubleshooting incomplete inventory

Open the source integration and inspect its latest Test and Sync results. Add
only the permission named by the failed evidence family, then run Sync again.
A healthy read from one cloud service does not prove that every NHI, activity,
credential, or ownership source is readable.
