Join our Newsletter — 33% off our NHI Course

Secret-Bearing Workflow

A business workflow system that can store, move or expose credentials as part of normal operations. In this context, ServiceNow tickets, KBs, attachments and CMDB records become part of the secret surface because users paste tokens or keys into them during support activity.

What a secret-bearing workflow actually is

A secret-bearing workflow is not just a process that happens to handle sensitive data. It is a business or support workflow whose ordinary steps can ingest, transport, display, or retain credentials, so the workflow itself becomes part of the secret surface.

This matters because the workflow may be operated by people who are not thinking like secret custodians. A ticket, knowledge article, attachment, comment, export, or CMDB field can silently become a storage location for tokens, keys, passwords, or certificates if users paste them there to get work done.

Where the secret surface expands

The core idea is that the risk is created by workflow behaviour, not only by a dedicated secrets vault or code repository. If a support desk, change process, or asset record can carry secret material, then access controls, retention rules, search, notifications, integrations, and exports all become part of the exposure path.

That is why systems such as ServiceNow are often discussed in this context. They are designed for operational coordination, but once users place secrets into tickets or attachments, the platform can inadvertently preserve, index, replicate, or disclose those values far beyond the original need.

For practical secrets handling, the right question is whether the workflow ever needs the secret itself or only needs a controlled action around it. NHIMG’s Secrets Management Guide explains the shift from ad hoc secret sharing to centralised control, while the Guide to the Secret Sprawl Challenge shows how fast secrets spread once normal workflows start carrying them.

Why secret-bearing workflows are dangerous

Once credentials enter a workflow, they are rarely confined to one person or one moment. They may be visible to support staff, copied into related records, sent through notifications, retained in archives, or exposed through search and reporting, which turns routine process friction into a confidentiality problem.

Secret-bearing workflows also weaken accountability. A team may think the secret lives in an application or vault, when in reality it has been duplicated across a ticket thread, a file attachment, and an audit export. That makes cleanup, rotation, and investigation much harder after a suspected exposure.

Internal incident patterns illustrate the scale of the problem, including ticketing and workflow paths that can become a secondary storage layer for credentials. NHIMG’s 52 NHI Breaches Report and 17,000+ Secrets Exposed in Public GitLab Repositories both reinforce the same lesson: once secret material is copied into a workflow, exposure paths multiply quickly.

How organisations should think about control boundaries

Secret-bearing workflows should be treated as sensitive secret-adjacent systems, even when they are not the authoritative secret store. The important boundary is whether the workflow can receive, persist, or surface credential material, not whether it was built for identity security in the first place.

That boundary should shape how teams design support procedures, record templates, integrations, and retention settings. A workflow that may receive secrets needs tighter handling than a normal business record because its content can become directly usable by an attacker or accidentally available to too many insiders.

For broader governance and lifecycle context, NHIMG’s Top 10 NHI Issues provides a useful view of overprivilege, visibility gaps, and credential hygiene. When secret-bearing workflows also involve machine or service credentials, the Ultimate Guide to NHIs, Key Challenges and Risks is a strong companion reference.

Practical meaning for security and operations teams

A secret-bearing workflow is a warning that the organisation has allowed sensitive authentication material to cross into ordinary business operations. The presence of that material changes the workflow’s risk profile, its retention burden, and the way access should be reviewed.

Teams should think in terms of reduction of secret carriage, not just better recordkeeping. If a workflow repeatedly needs users to paste credentials into tickets or attachments, the process design is compensating for a missing secure handoff path, and the workflow will continue to generate avoidable exposure.

For implementation patterns, the OWASP Non-Human Identity Top 10 is a useful external reference for understanding secret sprawl, overprivilege, and insecure secret handling around non-human access paths. OWASP Cheat Sheet Series also helps when practitioners need a control-oriented view of authentication and secrets handling.

Risk and Threat Considerations

Secret-bearing workflows create a direct confidentiality risk because ordinary operational records can become accidental repositories for credentials. Once a secret is pasted into a workflow, it may be retained, replicated, indexed, forwarded, or exported in ways the original owner never intended.

Failure mechanism: Users place secrets into tickets, KBs, attachments, or CMDB fields to move work forward, then the platform distributes that content through search, notifications, integrations, backups, or access by broad support roles.

Impact: Attackers or unauthorised insiders can recover usable credentials from routine business records, enabling account takeover, lateral movement, and delayed secret rotation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-02 — Secret Leakage Secret-bearing workflows create secret leakage through support records and attachments.
NHI-07 — Long-Lived Secrets Workflow persistence can prolong the lifetime of secrets stored in business systems.
Recommendation — Prevent secret leakage by stopping credentials from entering tickets, KBs, and attachments. Shorten secret lifetime and rotate any credential that entered a workflow record.
NIST SP 800-53 Rev 5 AU-9 — Protection of Audit Information Workflow logs and records can expose sensitive credential-bearing content in audit trails.
AC-6 — Least Privilege Restrict who can view secret-bearing records, attachments, and workflow artifacts.
Recommendation — Protect audit records so secret-bearing workflow content is not broadly exposed. Limit access to workflow records that may contain credentials to the smallest viable set.
ISO/IEC 27001:2022 A.5.15 — Access control Secret-bearing workflows require controlled access to records that may contain credentials.
A.8.24 — Use of cryptography Secret-bearing workflows often reflect the need to protect sensitive authentication material.
Recommendation — Apply access control to records and attachments that can carry secrets. Use cryptographic protection for secret material that must transit or persist in operational systems.

Practitioner Guidance

Why practitioners should care: The operational problem is usually not a single breach, but an entrenched habit of using business workflows as a substitute secret channel. That habit is hard to see until a review, incident, or audit reveals how many records contain live credentials.

Common misunderstanding: Teams often assume a ticketing or ITSM platform is safe because it is internal and permissioned. Internal access does not make secret storage acceptable when the workflow was never designed to minimise exposure, retention, or secondary replication of credentials.

Practitioner takeaway: Treat any workflow that can carry secrets as part of the secret-management control plane, and remove the need to paste secrets into it wherever possible.