Security, made operationalPractical guides / September 2026
Inforbasket

Home / Identity & access

Identity briefing

Review admin access before adding another security tool

Map privileged accounts to people, business needs and a clear removal process.

· 2 min read

Security, made operational
The useful takeawayEvery privileged account should have a purpose and an accountable owner.

Inventory the paths to administration

List the places from which someone can control the service: hosting, DNS, source code, deployment, databases and the application itself. Do not stop at the most visible login page. A forgotten infrastructure account may have broader access than an application administrator.

For each account, record its owner, purpose and last review. Separate human access from machine access. Shared accounts make it harder to know who performed a change, so record any unavoidable exception and the plan to remove it.

Check the entire sign-in journey

OWASP’s authentication guidance covers controls such as multifactor authentication, recovery and reauthentication for sensitive operations. A strong normal login can be undermined by a weaker recovery path. Examine both.

Walk through a lost-device scenario with a test account. Who approves recovery? What evidence is checked? Where are recovery materials held? The goal is a process that remains usable without quietly granting anyone who can send an email administrative access.

Make removal a normal operation

Choose a review cadence and repeat the review after role changes or departures. Confirm that disabling an account removes the intended access across connected services. Existing sessions and long-lived tokens may need separate treatment depending on the platform.

Close each review with a short list of changes and unresolved exceptions. A screenshot of a user list is not a complete review: the useful result is a reason for each retained privilege. Start with the accounts that can change identity, billing, DNS or production deployments.

Before you finish

  • Infrastructure accounts included
  • Account owners recorded
  • Recovery path reviewed
  • Removal process tested