Skip to content
REDMAW

SaaS & Identity

Non-human identity paths across SaaS tenants

Service accounts, tokens and integrations create access paths that cross application boundaries.

RedMaw Research8 min read

Human access is periodically reviewed because it maps to employment. Non-human identity maps to projects, and projects end without their credentials being retired.

How cross-tenant paths form

  • An integration authenticates to two platforms with independent privilege in each
  • A token issued for a narrow task retains a broader scope than the task required
  • Automation runs with an administrative role because narrower roles were never defined
  1. Token
  2. Integration
  3. Second Tenant
  4. Sensitive Records

Each hop validated by successful exploitation

Making paths visible

Access inventories describe grants. Adversarial testing establishes reach: whether a specific credential, used as an adversary would use it, actually retrieves the data at the end of the path.

Tags

  • identity
  • oauth
  • service accounts
  • saas

Keep going

Related

Further reading

Attack LibrarySaaS & Identity

OAuth Token Abuse

Tokens survive password resets. A stale grant is standing access with no owner watching it.

· 7 min read

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.