Vendor platform security is covered by contracts, attestations and the vendor's own program. The customer side, covering identities, roles, service accounts, grants, integrations, sharing and configuration, is rarely tested adversarially by anyone.
The customer side of the line
- Standing privileged roles that no longer match any job function
- Service accounts with credentials that outlive the projects that created them
- OAuth grants consented once and never reviewed
- Integrations that bridge two tenants and quietly widen access
- Sharing settings that make sensitive records reachable without authentication
- Compromised Identity
- SaaS Platform
- Sensitive Customer Records
Each hop validated by successful exploitation
Tags
- saas
- identity
- oauth
- shared responsibility