Skip to content

Invoice Parser Workload

ATC-MID-0005266 · Kubernetes · prod-eu

ProductionContainer identity

20

low risk

Ownership

Why it exists, and who answers for it

Purpose
Parses supplier invoices inside the finance namespace and writes the result to the ERP.
Business owner
Marit Halvorsen · Finance Operations
Technical owner
Anders Kohl · Platform Engineering
Type
Container identity — A Kubernetes or container workload.
Environment
production
Last authenticated
2 minutes ago

The chain

From a person to a resource

Every link is a place a question stops being answerable if nobody recorded it.

  1. Human ownerAnders Kohl · Platform Engineering
  2. AI agentAccounts Payable Agent
  3. Machine identityInvoice Parser Workload
  4. CredentialSPIFFE SVID
  5. ResourcesERP · invoices, PostgreSQL · finance

Risk

Why the score is 20

  • +10

    Data

    Handles invoices carrying payment references

  • +6

    Resource

    Two systems, both inside the finance boundary

  • +4

    Authentication

    Attested by namespace and workload image before any credential is issued

  • 20Total

Credentials

What it authenticates with

  • SPIFFE SVIDshort-livedNothing to steal

    spiffe://agenttrustcloud.com/prod/finance/invoice-parser

    Last rotated
    Continuous — rotated hourly
    Last used
    2 minutes ago
    Expires
    Per SVID, 60 minutes

Effective access

What it can do, against what it has done

Effective permissions, not assigned roles — a role, a group and a resource policy combine into reach that no single screen in the source system shows. 1 of 13 granted actions were not used in the last 90 days.

  • ERP · invoicesWrite

    held via Direct role

    9 actions granted, 8 used. 1 could be removed on the evidence.

  • PostgreSQL · financeRead

    held via Direct role

    4 actions granted, 4 used. 0 could be removed on the evidence.

Blast radius

What a compromise of this credential reaches

ERP · invoicesPostgreSQL · finance

1 agent stops working the moment this identity is quarantined — which is exactly what an operator needs to know before doing it.

Back to the estate · The module behind this view