A workload identity is a non-human identity assigned to software running in an environment, such as a virtual machine, container, function, application or automation job. It enables the workload to authenticate and access resources without impersonating a human user.
Governance should bind the identity to a workload owner and deployment lifecycle, minimize permissions, prefer short-lived credentials and remove the identity when the workload is retired.