Failure PatternDecision layer
The Shared Vault Trap: Why IAM & Access Control Stalls When Agencies Pool Client Credentials
Symptom: One vault holds production keys for six or more client tenants, and nobody can name which engineer last rotated the AWS root credential. Root cause: Agencies adopt a password manager for convenience and never graduate to lifecycle governance, so provisioning and deprovisioning stay manual and undocumented.
By InnovaAI ResearchPublished Updated
How do you recognize it?
- •One vault holds production keys for six or more client tenants, and nobody can name which engineer last rotated the AWS root credential.
- •Offboarding takes days because a departing contractor's access lives in a personal password manager that was never federated to the agency directory.
- •Client security questionnaires stall at the question about non-human identity inventory, and the answer is a spreadsheet last edited eight months ago.
- •A single compromised laptop forces a weekend rotation of every shared secret across the book of business, billed as unbillable internal time.
- •Access reviews happen annually before the SOC 2 window rather than continuously, so dormant accounts from churned clients sit active for months.
Why does it happen?
- •Agencies adopt a password manager for convenience and never graduate to lifecycle governance, so provisioning and deprovisioning stay manual and undocumented.
- •Client work is delivered by mixed teams of employees, contractors, and AI agents, but the identity model assumes only full-time staff exist.
- •Secrets for CI pipelines, webhooks, and agent API keys get stored beside human logins, collapsing two different risk tiers into one control plane.
- •Retainer economics reward billable delivery hours, so identity hygiene work has no owner and no line item until an incident creates one.
How do you fix it?
- •Inventory every credential by owner and client tenant this week, then delete anything with no named human accountable for rotation.
- •Separate human logins from machine secrets: move CI tokens and agent keys into a dedicated secrets store rather than the team password vault.
- •Turn on SSO with SCIM provisioning for the agency directory so contractor offboarding revokes access in one action instead of five.
- •Run a 30-day dormant account report and disable anything untouched, then repeat monthly and attach the output to client security reviews.
More for IAM Access Control
- Failure PatternsThe 1Password MSP Console Trap: Why Agencies Fail With Multi-Tenant Billing
- Failure PatternsWhy Agencies Fail With Clerk: The White-Label Resale Trap
- Failure PatternsThe Descope MAU Ceiling Trap: Why Agencies Stall Client Growth on Free and Pro Tiers
- Failure PatternsWhy Agencies Fail With KeyKosh by Treating It as a SaaS