SERVICE ACCOUNT GOVERNANCE

Service accounts and secrets proliferate with old credentials and no rotation, so the blast radius of a single leaked secret is huge and unknown. Machine identity is the ungoverned majority.

Actors

  • Identity & Access (IAM) Lead
  • IT & Infra Leads
  • Cloud Security Lead

Systems / Vendors

  • PAM / secrets management
  • IAM / IGA
  • Cloud (AWS / Azure / GCP)

Business Question

"How old are our service-account secrets, are they rotating, and what's the blast radius if one leaks?"

What SPoG Does

  • Tracks secrets age, rotation compliance and blast-radius analysis.
  • Governs service and machine identities.
  • Reduces the impact of a leaked credential.

Outcome Metrics

−40%

Stale secrets

1

Service-account governance view

6–10 wks

To first outcomes