Machine identities need owners too

Every automated account needs a named person responsible for it, or it becomes permanent.

Nobody rotates its credentials because nobody knows what will break. Nobody removes it because nobody is sure what depends on it. It outlives the project, the team and the employee who created it, quietly holding permissions nobody has reviewed. The ownership field is the boring administrative detail that decides whether these get cleaned up or accumulate for a decade.

More on Identity and authentication