Identity & Access Management · Lesson 8 of 8
Privileged and service access
Privileged accounts can make powerful changes. Workload accounts run services and need identifiable ownership, even though no person signs in as the workload.
Different identities. Clear accountability.
Illustrative administrative and automated work.
- Human administrator
Named administrative identity, controlled elevation where supported, and separation from ordinary work.
- Reporting workload
Dedicated identity, documented owner and purpose, narrow dataset access, and managed or short-lived credentials where practical.
Read the visualWhat prevents a staff departure from orphaning the reporting job?
Documented workload ownership, a maintained dedicated identity, and an approved ownership-transfer process.
Limit privileged use
Use named administrative identities and controlled elevation where supported. Keep ordinary work separate from administrative tasks.
Assign workload owners
Document what the service does, what access it needs, and who maintains it. Avoid dependence on a departing employee’s personal account.
Review credentials and access
Prefer managed or short-lived credentials where practical. Review privileges and rotate or revoke credentials using an approved process.
Put it in context
A scheduled reporting job runs under a dedicated identity with access to its dataset. Its owner and permissions are documented, so a staff departure does not orphan it.
Powerful and non-human accounts need narrow access and clear ownership.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.