Skip to content

Legacy Warehouse ETL

ATC-MID-0004010 · Snowflake

DormantService account

80

high risk

Ownership

Why it exists, and who answers for it

Purpose
None on record. Nobody has stated why this identity exists.
Business owner
Unassigned
Technical owner
Unassigned
Type
Service account — A non-human operating account.
Environment
production
Last authenticated
311 days ago

The chain

From a person to a resource

Every link is a place a question stops being answerable if nobody recorded it.

  1. Human ownerNobody — this identity has no owner of record
  2. AI agentNone. This identity runs without an agent above it
  3. Machine identityLegacy Warehouse ETL
  4. CredentialDatabase password
  5. ResourcesSnowflake · warehouse, Snowflake · customer schema

Risk

Why the score is 80

  • +24

    Ownership

    No owner of any kind. The team that created it no longer exists

  • +20

    Dormancy

    Has not authenticated in 311 days and is still enabled

  • +16

    Privilege

    Warehouse administrator, with none of it used

  • +12

    Credential

    Password never rotated since it was issued

  • +8

    Data

    Can read the customer schema

  • 80Total

Credentials

What it authenticates with

  • Database passwordlong-livedBearer secret

    Snowflake · warehouse admin

    Last rotated
    Never since issue
    Last used
    311 days ago
    Expires
    Never

Effective access

What it can do, against what it has done

Effective permissions, not assigned roles — a role, a group and a resource policy combine into reach that no single screen in the source system shows. 89 of 89 granted actions were not used in the last 90 days.

  • Snowflake · warehouseAdministrative

    held via Direct role

    71 actions granted, 0 used. None of this has ever been exercised.

  • Snowflake · customer schemaRead

    held via Direct role

    18 actions granted, 0 used. None of this has ever been exercised.

Blast radius

What a compromise of this credential reaches

Snowflake · warehouseSnowflake · customer schema

No agent depends on this identity, so containing it stops nothing else.

Back to the estate · The module behind this view