Source: cloud api guard
A service account holds an editor role and a user-managed key unused for 90+ days.
Affected frameworks / controls
Evidence summary
Sample IAM export (ev-005) flagged 1 over-privileged service account.
Recommendation
Reduce the role to least privilege and disable the unused key.
Recommended remediation workflow
Review AI system classification
Re-assess the risk classification and registration of an AI system. · SLA 72h
View workflow| Evidence | Status | Owner | Action |
|---|---|---|---|
| IAM policy export | Pending review | Sam Okafor | Open |