Skip to main content

When to use one

Decide whether a need should be met by a human user, a group, or a service account.

When to use this​

  • Use it before creating a new service account.
  • Use it when an automated process needs to query data.
  • Use it when a team is improperly sharing credentials.

Before you start​

  • Understand who or what will carry out the action.
  • Confirm whether there is human interaction or an automated routine.
  • Decide who is responsible for the identity's lifecycle.

Step by step​

  1. Use a user for actions taken by people.
  2. Use a group to organize people with the same responsibility.
  3. Use a service account for automations, integrations, and recurring processes.
  4. Avoid sharing personal credentials in automated processes.
  5. Plan review and rotation before putting the account into use.

What happens next​

  • The right identity appears in the audit records.
  • It becomes easier to revoke access without affecting the wrong people.
  • Automated processes depend less on individual users.

Common errors​

  • Creating a service account for daily manual use.
  • Using a single account for several unrelated purposes.
  • Forgetting to review the account when the automation ceases to exist.

Good practice​

  • An important automation should have its own account.
  • Name accounts after the system and the purpose.
  • Keep an inventory of owner, purpose, and data accessed.

Next steps​