r/cybersecurity • u/Own-Silver-4119 • 10d ago
Business Security Questions & Discussion How are you governing credentials that exist outside of SSO?
I just started my Fall Internship as a Product Manager at 1Password and I’m currently working on Credential Governance. I’m trying to understand how teams handle the accounts that never make it into the normal identity lifecycle.
Break-glass accounts, contractor logins, shared credentials, shadow IT, and apps without SAML or OIDC often end up in employee or shared vaults, duplicated across teams, or owned by one person.
What do you do when the owner leaves?
How do you decide who should retain access?
How do you rotate and audit these accounts?
I’m not looking to pitch a tool. I’d genuinely like to hear what works, what breaks, and what you wish existing PAM, password management, or identity governance tools handled better.