Qeluntra Supplier Workload
ATC-MID-0000412 · Microsoft Entra ID
18
low risk
Ownership
Why it exists, and who answers for it
- Purpose
- Lets the Supplier Risk Agent read supplier financial-risk records from the Qeluntra API.
- Business owner
- Dominique Bexley · Procurement
- Technical owner
- Anders Kohl · Platform Engineering
- Type
- Managed identity — A cloud-managed workload identity with no secret to hold.
- Environment
- production
- Last authenticated
- 4 minutes ago
The chain
From a person to a resource
Every link is a place a question stops being answerable if nobody recorded it.
- Human ownerAnders Kohl · Platform Engineering
- AI agentSupplier Risk Agent
- Machine identityQeluntra Supplier Workload
- CredentialManaged identity
- ResourcesQeluntra Supplier API, PostgreSQL · procurement
Risk
Why the score is 18
- +8
Data
Reads confidential supplier financials
- +6
Resource
Reaches two production systems
- +4
Privilege
Read-only, and nearly every granted action is used
- 18Total
Credentials
What it authenticates with
- Managed identityshort-livedNothing to steal
Qeluntra Supplier API · read
- Last rotated
- Continuous — platform-managed
- Last used
- 4 minutes ago
- Expires
- Per token, 60 minutes
Effective access
What it can do, against what it has done
Effective permissions, not assigned roles — a role, a group and a resource policy combine into reach that no single screen in the source system shows. 1 of 9 granted actions were not used in the last 90 days.
- Qeluntra Supplier APIRead
held via Direct role
6 actions granted, 5 used. 1 could be removed on the evidence.
- PostgreSQL · procurementRead
held via Direct role
3 actions granted, 3 used. 0 could be removed on the evidence.
Blast radius
What a compromise of this credential reaches
1 agent stops working the moment this identity is quarantined — which is exactly what an operator needs to know before doing it.