Skip to main content

Revoking a service account

Revoke a service account when the automation ends, changes owner, or presents a risk.

When to use this​

  • Use it when the integration has been discontinued.
  • Use it when the account has lost its responsible owner.
  • Use it in response to suspected misuse.

Before you start​

  • Confirm the impact with the process owner.
  • Check whether a replacement is planned.
  • Review which data and routines depend on the account.

Step by step​

  1. Open Service Accounts.
  2. Find the account.
  3. Review its description, owner, and attached access.
  4. Choose revoke or disable, as appropriate.
  5. Read the impact shown.
  6. Confirm the action.
  7. Notify those responsible for the automation.

What happens next​

  • The account stops being used for new access.
  • The revocation is recorded in the audit trail.
  • The attached data rules should be reviewed and removed if no longer needed.

Common errors​

  • Revoking an account in use with no replacement plan.
  • Disabling temporarily when the right action was permanent revocation.
  • Leaving orphaned data rules behind after removing the account.

Good practice​

  • Revoke ownerless accounts immediately after confirmation.
  • Keep a record of the decision behind the revocation.
  • Review the related access afterwards.

Next steps​