Machine identities need owners too
Every automated account needs a named person responsible for it, or it becomes permanent.
Nobody rotates its credentials because nobody knows what will break. Nobody removes it because nobody is sure what depends on it. It outlives the project, the team and the employee who created it, quietly holding permissions nobody has reviewed. The ownership field is the boring administrative detail that decides whether these get cleaned up or accumulate for a decade.
More on Identity and authentication
- Session lifetime is a security decisionSomebody chose how long it burns
- Step-up authentication protects sensitive momentsThe arm only comes down once
- MFATwo things to hand over, one that will not go
- PAMSign it out, do not keep it
- Account recoveryThe other lane
- AuthenticationIt only answers the first question
