Good practice
Keep service accounts secure, traceable, and aligned with least privilege.
When to use this
- Use it when creating, reviewing, or investigating service accounts.
- Use it in audits of automations.
- Use it when defining governance standards for integrations.
Before you start
- Have an inventory of existing accounts.
- Identify the owner, the purpose, and the data accessed.
- Set a review and rotation schedule.
Step by step
- Make sure every account has a responsible owner.
- Use clear names and a single purpose.
- Grant only the data needed.
- Rotate secrets periodically.
- Revoke unused accounts.
- Review the attached data rules.
- Monitor the audit trail for sensitive accounts.
What happens next
- The organization reduces the risk of forgotten credentials.
- Auditors can understand who or what used data.
- Automation stays separate from human identities.
Common errors
- A generic account for several systems.
- A secret shared through unapproved channels.
- Broad access with no review.
Good practice
- One account, one purpose.
- A clear owner and periodic review.
- Least privilege always, especially for automations.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.