Security, made operationalPractical guides / September 2026
Inforbasket

Home / Identity & access

Access design

Give each service account a smaller job

Design machine access around one workload, a limited permission set and a documented owner.

· 2 min read

Security, made operational
The useful takeawaySeparate credentials make permission changes and incident response easier to reason about.

Name the job before creating the account

A service account should represent a workload, not a person’s convenience. Describe the exact operation it needs: read one storage location, deploy one application or write one class of records. Avoid starting from a broad administrator role and hoping to reduce it later.

Create a permissions worksheet with the resource, allowed action, environment and owner. A development job and a production job often deserve distinct credentials even when the code is similar. This gives you a clearer boundary when one environment needs to be disabled.

Treat the credential as a managed secret

OWASP’s secrets guidance recommends managing secrets throughout their lifecycle, including access, rotation and revocation. Store credentials in the appropriate secret facility for the runtime, restrict who can retrieve them and avoid putting them in source code or diagnostic output.

Record where the account is used before changing it. An apparently idle credential may belong to a monthly job. Review the scheduler, deployment configuration and application settings so the inventory reflects actual dependencies rather than memory.

Test what the account cannot do

In an authorised test environment, verify the required operation succeeds and an out-of-scope operation is denied. Use harmless test resources. Record the outcome and the policy version so a later change can be compared against the same expectation.

Plan replacement and revocation separately. A replacement credential should be installed and verified before the old one is removed when the platform permits overlap. If the credential may be compromised, use the incident procedure to decide the urgency and acceptable service disruption.

Before you finish

  • One workload identified
  • Production access separated
  • Denied operations checked
  • Revocation owner assigned

Technical reference
OWASP: secrets management