Machine callers are identities too.
API Access Management issues and governs tokens for programmatic callers, so a service or integration authenticates with a scoped credential rather than a broad one. Our work is inventorying machine callers and scoping the tokens they hold.
API Access Management governs what a service, script, or integration may call. It is where non-human access is either scoped deliberately or granted broadly and forgotten.
What it is
API Access Management issues and governs tokens for programmatic callers, so a service or integration authenticates with a scoped credential rather than a broad one.
It is for organizations whose integrations currently authenticate with credentials created by whoever built them.
What it does
Scoped tokens
A caller gets what it needs rather than what was convenient at the time.
Tokens with a lifecycle
Issued, rotated, and revoked, which is what makes an inventory meaningful.
Where it fits
L1, identity and access, controlling behavior that appears at L2 and L4. Every integration and every agent is a machine caller. Scoping those callers is the same work as scoping people, and it is done far less often.
What we do with it
Inventorying machine callers
The integrations and scripts already authenticating, which is the finding that usually surprises.
Scoping and rotation
Narrowing what each may call, and making rotation something that happens.
Ongoing review
Machine credentials outlive their purpose unless somebody reviews them.
Where it earns its place
An estate with scripted integrations
Credentials in scripts on somebody's machine are the most common unowned access in any estate.
An organization connecting assistants
An assistant is a machine caller. The same scoping applies.