What we solve ·How do I fix the way we decide?
Taskforce · Sustain
Who answers for what your service accounts and your agents do?
We have service accounts with privileges and nobody knows who answers for them.
The inventory of everything that is not a person and has access, with a named owner, documented rights and its rotation and revocation rule.
Non-human identity governanceSend this page to whoever decides
Use this today, without hiring anyone
How to start the inventory without help and in what order. Four cuts that run on what you already have and give you the picture you are missing in one afternoon.
- List what is not a person and can get in. Service accounts, integrations, robots, agents, interface keys. Start with the directory and continue with whatever each platform holds on its own, which is where the surprises appear.
- Mark the ones with high privileges. They are the minority and they are the whole risk. Sort by that and forget the rest on the first pass.
- Next to each one, write a person's name. Not an area: a person. The ones left without a name are your finding, and they are usually between thirty and fifty percent.
- Look for the date of the last credential change. If it is more than two years, that credential is known by people who no longer work there.
Ask yourself this before deploying the first agent. Who is going to own its credential and who can revoke it on a Sunday? If there is no answer, the agent should not be in production yet.
This sounds like you if
- You are about to deploy agents and the credential and revocation model is still to be defined.
- Audit asked about service accounts and the list does not exist.
- Someone left who was the informal owner of several integrations.
How we solve it
The method, not the promise.
- Discovery runs from the directories and from each platform, not from interviews. What gets discovered by asking alone comes out incomplete.
- The real rights of each credential get determined, which are not the declared ones.
- A named owner gets assigned, one per credential, and accepted in writing. This is the part that is worth something.
- The full life cycle gets designed: creation, rotation, review and revocation, including what happens when the owner changes role.
- Remediation gets prioritized by privilege and exposure, with a window and a rollback written.
What you receive
- The inventory of non human credentials with their real rights.
- The matrix of owners named and accepted in writing.
- The defined life cycle: creation, rotation, review and revocation.
- The prioritized remediation plan, with a window and a rollback criterion.
The proof that applies here
- Separation of identities and access rights over an operation of more than 200,000 instances, validated in ten rehearsals before the real cutover.
- The systems separation in one of the largest bank divestitures in Latin America: 100% of systems cut over on the legal day, zero failures and zero regulatory findings.
- Eight years under regulatory supervision, where a service account with no owner is a finding.
Before you hire
The inventory and the plan get delivered; the revocation gets executed by your team with a window and a rollback, because taking away an inherited right breaks things nobody knew depended on it.
This is not a new topic in disguise: it is what had to be solved to separate two banks that until yesterday were one, over two hundred thousand instances and against a contractual date. AI agents only made the same problem grow faster.
How many of your high privilege service accounts have a person's name next to them today?
If the problem is a different one
The agent no longer just answers: it executes. Nobody defined how far it can go on its own.
Agentic operation guardrails
The regulator asks why that case was rejected and nobody can reconstruct it.
Automated decision governance
I know there is AI in use and I do not know which tools or with what information.
Shadow AI inventory
