Invoice Parser Workload
ATC-MID-0005266 · Kubernetes · prod-eu
20
low risk
Ownership
Why it exists, and who answers for it
- Purpose
- Parses supplier invoices inside the finance namespace and writes the result to the ERP.
- Business owner
- Marit Halvorsen · Finance Operations
- Technical owner
- Anders Kohl · Platform Engineering
- Type
- Container identity — A Kubernetes or container workload.
- Environment
- production
- Last authenticated
- 2 minutes ago
The chain
From a person to a resource
Every link is a place a question stops being answerable if nobody recorded it.
- Human ownerAnders Kohl · Platform Engineering
- AI agentAccounts Payable Agent
- Machine identityInvoice Parser Workload
- CredentialSPIFFE SVID
- ResourcesERP · invoices, PostgreSQL · finance
Risk
Why the score is 20
- +10
Data
Handles invoices carrying payment references
- +6
Resource
Two systems, both inside the finance boundary
- +4
Authentication
Attested by namespace and workload image before any credential is issued
- 20Total
Credentials
What it authenticates with
- SPIFFE SVIDshort-livedNothing to steal
spiffe://agenttrustcloud.com/prod/finance/invoice-parser
- Last rotated
- Continuous — rotated hourly
- Last used
- 2 minutes ago
- Expires
- Per SVID, 60 minutes
Effective access
What it can do, against what it has done
Effective permissions, not assigned roles — a role, a group and a resource policy combine into reach that no single screen in the source system shows. 1 of 13 granted actions were not used in the last 90 days.
- ERP · invoicesWrite
held via Direct role
9 actions granted, 8 used. 1 could be removed on the evidence.
- PostgreSQL · financeRead
held via Direct role
4 actions granted, 4 used. 0 could be removed on the evidence.
Blast radius
What a compromise of this credential reaches
1 agent stops working the moment this identity is quarantined — which is exactly what an operator needs to know before doing it.