The explosion of service accounts, API keys, and workload identities has created a governance gap that most security teams have yet to close.