Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Back to Findings
Read-only local preview. Status changes are kept in memory for this session only — no cloud write occurs.

Risky service account with long-lived key

Source: cloud api guard

high
In remediation
Actions
Preview-only lifecycle transitions. Each action appends to the audit trail below.
Details

A service account holds an editor role and a user-managed key unused for 90+ days.

Affected frameworks / controls

zagos-cloud-api-guard
iso-27001
CAG-3
A.5.15

Evidence summary

Sample IAM export (ev-005) flagged 1 over-privileged service account.

Recommendation

Reduce the role to least privilege and disable the unused key.

Recommended remediation workflow

Review AI system classification

Re-assess the risk classification and registration of an AI system. · SLA 72h

View workflow
Metadata
OwnerSam Okafor
Due dateJun 3, 2026
DetectedMay 26, 2026
Resolved-
Linked evidence
Evidence sharing a control with this finding.
EvidenceStatusOwnerAction
IAM policy export
Pending review
Sam OkaforOpen
Audit trail
  • May 26, 2026 · system detected
  • May 26, 2026 · Sam Okafor status_changed (open → in-remediation)