Many agents do not get an identity of their own. They run on an existing service account, cloud role or API key, and inherit everything that identity could already do. The agent is new. The access is years old.
In the PaperCut campaign, hundreds of AI agents exploited print servers at 395 organisations. Where the software ran as a domain-admin service account, the attacker needed no further exploit to take the domain. In the retail campaign Gambit reconstructed, one database identity could read card data, create tables and drop backups. The exploit opened the door. The service account decided how far the attacker got.
Five questions Elmoz answers for every service account, role and key an agent runs on.
Including identities shared by several agents or services.
Roles, group memberships and data stores, traced as paths.
Service accounts whose owners have left are flagged.
Keys that have not rotated in months and where they are stored.
Scope a role, split a shared identity or rotate a key, with the impact shown first.
Scope a role, split a shared identity or rotate a key, with the impact shown first.
The agent is new. The access is years old. Three agents share one service account whose role can delete the production backups. Elmoz shows the shared identity and the reach in one view.
Short answers on agents that run on existing service accounts and roles.
They should have one. When an agent reuses an existing service account or key, it inherits all of that identity's access and its actions cannot be told apart from the original service.
Trace what each service account can reach, not only which roles it has. Look first at identities that reach production data, domain admin groups or backups, and at identities without a current owner.
When several agents or services use one identity, compromising any of them gives the attacker the combined access. Splitting the identity limits the blast radius.
Every use case ends in the same place: a path from an identity to sensitive data.
Book a demo and we walk through the access paths in an environment like yours.