Orphaned agent permissions

A grant survives after its owner, task or workload no longer has an approved purpose.

01 / Attack path

How the boundary is crossed

A test agent is decommissioned but its cloud role remains active and later gets reused by an unmanaged process.

Attack path and interception point
  1. 01Lower-trust input
  2. 02Attempted instruction
  3. 03Protected action
  4. 04Enforced decision

02 / Containment

Where bounded authority limits the effect

Tie grants to accountable owner and task lifecycle, recertify access and disable unused grants when ownership disappears.

03 / Failure and evidence

The attacker’s opportunity and the defender’s record

Exploit condition

Credential validity outlives the organizational authority that justified it.

Evidence to retain

Record owner change, last use, recertification decision, disabled grant and attempted later use.

04 / Canonical scope

Why this reference stands alone

Long-lived credentials focuses secret lifetime; this threat focuses missing authority ownership.

Protocol or attack trace

Owner-loss lifecycle

Sequence

Test agent is retired, but cloud role remains and is later used by an unmanaged process.

Negative test

On owner removal, suspend grant; later role use must be denied pending recertification.

Primary references

Read the underlying material

Architecture discussion

Choose one consequential action and make its boundary explicit.

Request a Conversation