IT & Cyber Audit
Service Account Inventory
Governance of non-human service and application accounts holding system-level privileges.
Non-human accounts are the most over-privileged and least governed identities
Service and application accounts often hold standing system-level privileges, never expire and are excluded from the joiner-mover-leaver controls that govern human users, making them a prime target in the AGSA's IT control reviews and a recognised vector for fraud and cyber compromise. King IV places accountability for technology governance with the governing body. AuditPro Core maintains an inventory of these non-human accounts with their privileges and ownership so that orphaned, over-privileged and undocumented service accounts are identified and brought under control.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Service accounts
1 284
No assigned owner
207
16% of total
Passwords > 1 yr old
418
Domain-admin rights
34
Service accounts by privilege tier
High-risk service accounts
| Account | System | Owner | Pwd age (days) |
|---|---|---|---|
| svc-payroll-batch | PERSAL | Unassigned | 612 |
| svc-billing-etl | Revenue system | IT Ops | 488 |
| svc-backup-agent | Backup | Unassigned | 731 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Why service accounts evade normal controls
Because no person owns them directly, service accounts are routinely missed by access reviews and termination processes. They accumulate privilege over time and persist long after the system they served is gone.
Ownership and accountability
Every service account needs a named human owner who is accountable for its existence, privilege level and continued need. An account with no owner cannot be governed or safely retired.
Least privilege and credential hygiene
Service accounts frequently run with far more privilege than the integration requires and with passwords that never change. Both expand the blast radius if the credential is compromised.
Interactive logon risk
A service account that can be used for interactive logon, or whose credentials are shared with administrators, blurs accountability and should be specifically flagged.
How AuditPro Core Bridges the Gap
- Inventory: all non-human accounts are catalogued with their privilege level, host system and integration purpose.
- Ownership mapping: each account is linked to a named accountable owner, with orphaned accounts flagged.
- Exception workflow: over-privileged, stale-credential or interactive-capable accounts are routed for remediation.
- Continuous monitoring: the inventory is refreshed so newly created or newly orphaned accounts are detected promptly.
Key Takeaways
- Service accounts escape joiner-mover-leaver controls and accumulate standing privilege.
- Assign a named, accountable owner to every non-human account.
- Enforce least privilege and credential rotation to limit compromise impact.
- Flag service accounts capable of interactive logon as elevated risk.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
