Unowned machine user discovered in a production account
- Why
- A machine user with an access key appeared in a production AWS account with no owner tag
- What
- aws-user/etl-runner-3 (service account) with one access key
- Who
- Owner unknown — no Owner, Team or ManagedBy tag, and nobody has assigned one
- Where
- AWS account data-prod · environment prod (from the connector)
- How
- Discovered by a sync; AWS reports its access key last used 2 hours ago, while the user itself reports no last use
- Blast radius
- Reach to 3 resources classified high impact · effective access, an upper bound
- Recommendation
- Assign an owner, confirm its purpose or retire it, move the workload to a role instead of a static key
- Action
- Assign owner · propose remediation for second-person approval
- Evidence
- IAM snapshot 2026-08-20 · access key metadata · sync diff #48213