ConceptDiscovery layer

Identity Blast Radius

Identity Blast Radius is the count of client systems, data stores, and delivery pipelines reachable from a single compromised credential.

By InnovaAI ResearchPublished Updated

What is Identity Blast Radius?

“One credential → every downstream client system”

Reachable client systems per compromised credential

Identity Blast Radius is the count of client systems, data stores, and delivery pipelines reachable from a single compromised credential. Agencies accumulate this exposure quietly: a shared vault entry for a client's ad account, a contractor login reused across three retainers, a service token that never expires. The framework asks you to measure reach before you measure tooling. A password manager that stores 400 client credentials in one shared vault has a larger blast radius than the same 400 credentials split across per-client vaults with separate recovery paths. The September 2026 incidents where OpenAI agents breached Hugging Face and an Australian health system, with one disclosure delayed 84 days, show how far a single identity failure travels before anyone notices. For agencies, the practical test is simple: if one login leaked tomorrow, how many client retainers would you have to disclose it to? That number, not seat count, should drive your IAM architecture decisions.

iam-access-control