Ownership & lifecycle

Every identity gets an owner.And an end of life.

Machines do not resign, transfer or retire on their own. Trustivan attaches an accountable owner and a lifecycle to every discovered non-human identity — preferring teams to people, so accountability does not leave with an engineer.

AvailableIdentity Governance · M2

Ownership, lifecycle and rotation findings available · provider-side rotation not executed

Top owners

By governed identities

  • PLPlatform teamInfrastructure1,943
  • DSData servicesAnalytics1,120
  • MLML platformAI engineering688
  • ?Unknown ownerNeeds attribution402

Illustrative

Dormant identities

No provider-reported use in 90 days

23%2,857 identities

Illustrative

The problem

Nobody remembers creating it. Everybody depends on it.

Human governance is built on joiners, movers and leavers. Machines have no HR record, no manager and no last day — unless the platform gives them one.

Orphaned identities

Creators leave, projects end, and the service accounts they made keep authenticating

Ownership mismatch

The tag says one team, the pipeline belongs to another, and the person who knows has moved on

Purpose drift

An identity created for one export now holds every permission its team ever needed

Lifecycle

Discover. Own. Certify. Track rotation. Retire.

A lifecycle for machines, with evidence produced at every stage and a finding raised when an identity is unowned, stale or overdue for rotation.

  1. 01

    Discover

    An identity is observed from its provider, with the creation time the provider reports and an owner hint from its tags.

    Evidence
    source snapshot · sync run
    If skipped
    Not in inventory
    Available
  2. 02

    Own

    An accountable team or person is assigned, or taken from a provider tag with its confidence shown. The change is written to the audit trail.

    Evidence
    owner record · audit event
    If skipped
    Unowned identity
    Available
  3. 03

    Certify

    A campaign asks a named reviewer to certify or revoke the identity’s access — API only today. A revocation records an instruction; it does not remove access.

    Evidence
    certification decision · timestamp
    If skipped
    Unreviewed access
    Available
  4. 04

    Rotate

    Age, expiry and rotation-overdue are tracked per credential, not per identity. Rotation at the provider is proposed and approved; it is not executed.

    Evidence
    credential age · rotation finding
    If skipped
    Long-lived credential
    Available
  5. 05

    Retire

    When the purpose ends, decommissioning is proposed and approved by a second person and recorded; the change at the provider is made by a person.

    Evidence
    proposal · approval record
    If skipped
    Stale identity
    Future capability

What you get

Accountability that survives reorganizations.

Owners are teams wherever possible, confidence is written down, and every change leaves a record — so ownership does not evaporate when one engineer leaves.

Owner attribution

Take owners from provider tags or assignment by a person, with the confidence and the source shown

Certification campaigns

Ask a named reviewer to certify or revoke an identity’s access and record each decision — API only, no console screen yet

Team ownership

Assign identities to teams rather than people, so accountability survives a transfer or a departure

Orphan detection

Flag identities whose owner is unknown or only a tag hint — as findings, not blanks

Dormancy

Surface identities that still hold an active credential but, where the provider reports last use, no longer authenticate

Ownership evidence

Keep owner changes, lifecycle changes and certification decisions in the hash-chained audit trail

Offboarding

Ownership that survives offboarding.

When a person leaves, their account is disabled within the hour. The service accounts, keys and integrations they created are not — because no system knew they were theirs. Trustivan points ownership at teams wherever it can, so a departure leaves an accountable owner behind, and an identity with no resolvable owner becomes a finding.

  • Team ownership first, so a departure does not orphan a production identity.
  • Unowned is a finding, raised whenever no owner resolves to a person or a team.
  • Nothing disappears silently: owner and lifecycle changes are recorded with actor, time and evidence.

Availableownership and lifecycle · M2

See the orphaned-identity use case
HighOrphaned identityLong-lived credential

Orphaned service identity with reachable production data

Why
Orphaned service account still holds active production credentials
What
svc-billing-export (service identity)
Who
Owner unknown — no owner tag and no assigned owner
Where
cloud account prod-core · region eu-west-1
How
Long-lived access key (age 611 days), still active, on a machine IAM user
Blast radius
2 production databases, 1 backup bucket, 4 downstream services
Recommendation
Assign owner, rotate to short-lived credential, scope role to export-only
Action
Propose remediation · assign owner · quarantine in platform
Evidence
AWS IAM sync 2026-08-19 · access-key metadata · owner tag absent
Evidence before claims — when evidence is missing, Trustivan shows unknown, never a fabricated score.Illustrative finding · sample environment

Give every machine identity an owner.

See owner attribution, lifecycle states and an unowned-identity finding on the demonstration estate.