When agencies create or manage profiles with their own credentials, the organisation can lose ownership, oversight, and the ability to reliably revoke access. If those accounts are not transferred or shut down, ghost accounts can remain active under the brand name. That weakens accountability, complicates offboarding, and increases the chance of misrepresentation or unauthorized activity.
Why This Matters for Security Teams
Letting agencies use their own credentials to manage brand accounts creates an identity and ownership gap, not just an operational shortcut. The brand may lose the ability to prove who created an account, who can revoke it, and whether access was ever transferred back. That turns routine marketing work into a governance problem that can surface as impersonation, content drift, or an unmanaged account that still speaks for the organisation.
This is a familiar failure mode in non-human identity management, where credentials outlive the business relationship that justified them. NHIMG’s Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs treats lifecycle control as essential because access without clear ownership quickly becomes ungovernable. The same pattern appears in the Guide to the Secret Sprawl Challenge, where stale credentials and unclear custody widen the attack surface.
The risk is not theoretical. According to The 2024 Non-Human Identity Security Report from Aembit, only 19.6% of security professionals express strong confidence in their organisation’s ability to securely manage non-human workload identities. In practice, many security teams encounter account ownership failures only after an agency relationship ends and the brand discovers it no longer controls the profile.
How It Works in Practice
The core problem is that agency-managed brand accounts are often created under personal or vendor-owned identities, then treated as if they were organisational assets. That breaks normal identity governance because the account may exist outside the brand’s directory, policy, and offboarding process. Best practice is to make the brand the account owner, then grant agency users access through delegated roles, just-in-time privileges, or controlled shared workflows rather than handing over permanent credentials.
For security teams, the practical model is to separate account ownership from day-to-day execution. The brand should control the primary credentials, recovery methods, billing, and recovery email or phone. Agencies should receive scoped access through role-based delegation where supported, or through monitored workflow approvals and short-lived access where platform features are limited. That aligns with the least-privilege principles reflected in the NIST Cybersecurity Framework 2.0 and with identity hygiene guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls.
Operationally, the account lifecycle should include onboarding, delegation, review, transfer, and revocation. If the agency created the account, the brand should still require a documented transfer of ownership before production use. Where the platform does not support transfer, the organisation should treat the profile as a controlled exception and maintain evidence of access review, credential custody, and exit procedures. This is also consistent with the risk patterns described in NHIMG’s Top 10 NHI Issues, which highlights lifecycle gaps as a recurring control failure. These controls tend to break down when agencies use personal logins across multiple client accounts because revocation becomes manual, inconsistent, and easy to miss.
Common Variations and Edge Cases
Tighter account control often increases operational friction, requiring organisations to balance speed for campaign teams against ownership, auditability, and recovery. Not every platform supports clean delegation, so some environments force a tradeoff between ideal governance and practical use of the channel.
Current guidance suggests three common exceptions need special handling. First, legacy platforms may only support shared passwords, which is a poor practice but sometimes unavoidable until the account can be migrated. Second, agencies may need temporary elevated access for crisis communications or paid media escalation, which should be time-boxed and approved. Third, some brands deliberately let agencies create disposable test accounts, but those should never be conflated with official brand presence.
There is no universal standard for this yet, but the direction is clear: organisations should use the OWASP Non-Human Identity Top 10 as a control lens for ownership, secret handling, and lifecycle risk, while applying NIST SP 800-63 Digital Identity Guidelines principles where identity proofing and recovery matter. The safest pattern is to assume that any account not fully owned by the brand can become a ghost account unless transfer, monitoring, and revocation are built into the contract and the offboarding checklist.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Brand accounts owned by agencies create unmanaged non-human identity sprawl. |
| OWASP Agentic AI Top 10 | LLM-03 | Delegated account use needs scoped runtime access instead of shared standing credentials. |
| CSA MAESTRO | MAESTRO-4 | Operational control of autonomous or delegated access depends on clear lifecycle governance. |
| NIST CSF 2.0 | PR.AC-4 | Least privilege and access governance apply directly to agency-managed brand accounts. |
| NIST AI RMF | Account ownership and revocation are governance issues under AI risk management too. |
Set accountable owners and lifecycle controls for any delegated identity or access path.
Related resources from NHI Mgmt Group
- How should organisations manage shared access to social media accounts without losing control when employees or agencies leave?
- What breaks when organisations try to manage unmanageable applications with only password managers or network controls?
- What breaks when organisations leave default credentials in AI hiring and applicant systems?
- What breaks when organisations do not have strong visibility into privileged and over-entitled accounts?