Question for folks managing identity/access at a growing company: how are you tracking access that isn’t tied to a person?
Service accounts, bots, and now AI agents pile up fast -each has credentials, most have no clear owner, and nothing triggers their removal. When a person leaves, you (usually) have an offboarding process. When a service account gets spun up at 2am to unblock a deploy, it just seems to live forever.
Curious what’s actually working for people - tooling, process, or “yeah, we’re struggling with this too.” Trying to learn how different teams handle it.