Skip to content

[REVIEW] privileged-access: add shared admin attribution controls gates #2742

@stmr

Description

@stmr

[REVIEW] privileged-access: add shared admin attribution controls gates

Skill Being Reviewed

Skill name: privileged-access
Skill path: skills/identity/privileged-access/

False Positive Analysis

A shared emergency admin credential can be acceptable only if vaulted, checked out per named user, MFA-protected, recorded, alerted, and rotated after use.

Coverage Gaps

Privileged access review should require attribution controls for shared/root accounts. Without checkout correlation, audit logs show admin but not the human actor.

Edge Cases

  • Vendor support uses shared account during outage.
  • Root account login is blocked except vault workflow.
  • Session recording exists but is not linked to checkout ID.

Remediation Quality

  • Require checkout ID, human user, approval, MFA, session log, and post-use rotation.
  • Flag direct shared-account use outside vault.
  • Require root/shared account use review after every activation.

Comparison to Other Tools

PAM can provide checkout logs; SIEM gives platform logs. Review should correlate both.

Overall Assessment

Add shared admin attribution gates so privileged actions remain accountable.

Bounty Info

  • I have read and agree to the CONTRIBUTING.md bounty terms.
  • Preferred payment method: PayPal samik4184@gmail.com

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions