| Directory user or group | A person or managed team | Your connected directory | Console access, attribution, policy scope, ownership, and approvals |
| Provider-native NHI | A machine principal such as a cloud role, service account, managed identity, application, or repository credential | AWS, Azure, Google Cloud, GitHub, or another provider | Discovering machine access, ownership, credentials, activity, and provider posture |
| Agent identity | An autonomous workload owned by your organization | Forge | Runtime enrollment and bounded, keyless provider access |
| LLM Gateway service account | A non-interactive caller of Forge LLM Gateway | Forge | Authenticating an application or service to LLM routes, models, budgets, and policy |
| Forge API or MCP service account | An automation principal for Forge management interfaces | Forge | Calling the Forge API or Forge MCP with explicitly assigned organization permissions |