Service accounts, keys, secrets, certificates, privileged accounts, agent identities. They outnumber your employees, most of them answer to nobody, and everyone is afraid to turn one off. Identity Hygiene builds the list, finds each one a named owner, keeps them rotating, and retires what nothing uses — after proving nothing uses it.
Every source you connect is read into one list, and a source that could only be read halfway is reported — never counted as small.
Each identity gets a request in your own service desk, aimed at the team the estate says it belongs to, asking for one named person.
What is past your policy age is batched by system and window, with the consumers listed, the order fixed and a way back written down.
Each owner confirms, on your cycle, that what they own is still needed, still theirs and still at the right level of access.
Only after every system holding it has reported your whole quiet period without seeing it used — and only by disabling it, never deleting.
What breaks is almost never the thing on the label. It is a nightly job, a partner's connection, a monitoring probe — something nobody wrote down. So an identity is never retired because it looks quiet. Four verdicts, and three of them stop the work.
Every system holding it reported your whole quiet period and none of them saw it used. That earns a proposal to a person — not an action.
Something used it inside the window. It stays, and we propose narrowing what it can reach instead.
A gap in the window, a log that only goes back so far, or a system nobody checked. Missing evidence is not evidence of non-use.
Break-glass accounts and anything with a declared dependency are excluded whatever the evidence says.
And when a proposal does turn out to be wrong: the action was a disable with a restore path, so it is undone in a minute — and the reversal is recorded as evidence that the evidence was wrong. Nothing on this team deletes an identity.
A class is one kind of identity, in one system, at one level of privilege. Each climbs on its own record and drops back on its first failure.
Runs on its own from day one. It reads and reconciles; it changes nothing.
Requests and reviews are raised and chased automatically in your service desk — a ticket commits nothing and is reversible.
Planned by the team, executed by your platform or your people. Execution moves to the team one pre-approved class at a time, non-production first.
A person approves each one at entry. A class earns a standing approval only on a verified record: nothing reversed for being wrong, every action backed by evidence covering the full period, and a restore drill passed.
Never. It is irreversible and it destroys the trail that justified it, and a disabled identity is restored in a minute.
One reversal caused by a wrong verdict, or one identity touched outside its change, and the class drops back the same day.
Priced per band of governed identities, plus per identity brought under ownership. Your own identity and operations teams run it. Rotations and revocations can take the same governed path as every other production change through Change Guard, and the agents in your estate are governed by Agent Fleet Guardian. For a one-off proof that each agent's identity, delegation chains and human accountability hold up, see Agent Identity & Delegation Assurance — that is the assessment; this is the running service.