TL;DR: Social media accounts often sit outside enterprise IAM and IGA because platform standards, shared access patterns, and employee-owned credentials prevent central control, according to Cerby. The result is a governance gap that makes least privilege, MFA, lifecycle automation, and auditability difficult to enforce at scale across marketing-managed channels.
At a glance
What this is: Cerby argues that social media accounts remain difficult to govern with enterprise IAM because platform integration gaps force teams into shared access, manual workflows, and employee-owned credentials.
Why it matters: This matters because IAM and IGA teams cannot apply standard lifecycle, MFA, and privilege controls when a critical class of business accounts sits outside the enterprise control plane.
Context
Social media accounts are often treated as marketing assets, but they still carry access, authentication, and lifecycle risk like any other enterprise identity surface. The problem is not whether organisations value security controls, but whether the platforms and operating model allow those controls to be applied consistently.
Cerby’s analysis focuses on the gap between what IAM and IGA systems are designed to do and what disconnected social platforms actually support. In practice, that leaves security, IT, and marketing sharing responsibility for accounts that cannot be governed with normal provisioning, deprovisioning, or audit workflows.
Key questions
Q: What breaks when social media accounts stay outside IAM and IGA control?
A: Lifecycle management, credential governance, MFA enforcement, and auditability all become fragmented when social platforms cannot participate in standard identity workflows. The organisation then depends on manual handling, shared access, or informal ownership, which increases the chance of orphaned accounts and inconsistent permissions after role changes or departures.
Q: Why do shared social media credentials create so much risk?
A: Shared credentials remove individual accountability, make least privilege hard to enforce, and complicate investigations because activity cannot be reliably tied to one person. They also tend to spread through informal channels and survive role changes, which leaves access active long after it should have been removed. That is a governance failure, not just a usability problem.
Q: How can organisations keep MFA in place on shared business accounts?
A: They need central custody of the credential and MFA factors, plus a workflow that preserves usability without giving users direct control over the secret. The goal is to make MFA mandatory and recoverable, not optional or dependent on one employee holding the only code.
Q: How do teams apply least privilege to social media access?
A: They often cannot apply it cleanly with shared logins, so the first step is to stop treating the shared credential as normal user access. Teams should push toward individualised access, time-bound approval, and explicit removal when the business need ends, because the full account permission set is otherwise inherited by everyone.
Technical breakdown
Why disconnected social platforms break IAM integration
Enterprise IAM depends on common identity standards and APIs to federate authentication, provision accounts, and record user-level activity. Social media platforms are rarely designed that way. When a platform does not reliably support SAML, SCIM, or OIDC, it becomes disconnected from the identity provider and cannot participate in the normal control plane for access governance. That is why central visibility, automated onboarding, and deprovisioning stop at the platform boundary. The failure is architectural, not just operational. The organisation can still administer the account manually, but it cannot treat the account as a governed enterprise identity in the same way it does SaaS or internal systems. Practical implication: treat disconnected platforms as control exceptions that need a separate governance model.
Practical implication: treat disconnected platforms as control exceptions that need a separate governance model.
Shared credentials and org-owned factors are not the same control
Shared access is sometimes unavoidable, but a shared credential is not a governance model. When several users rely on the same login, the organisation loses attribution, privilege boundaries, and clean offboarding paths. If the MFA factor belongs to one person instead of the business, that factor becomes an availability problem as well as a security problem, because access depends on the owner being reachable. Social platforms often intensify this by binding accounts to personal email addresses or phone numbers, which keeps recovery and authentication outside enterprise ownership. The result is a control pattern that looks like access management but behaves like informal credential distribution. Practical implication: separate account ownership, authentication factor ownership, and user access assignment.
Practical implication: separate account ownership, authentication factor ownership, and user access assignment.
Why least privilege collapses in multi-user social accounts
Least privilege assumes access can be scoped to the person, task, and time window. Shared social media accounts break that assumption because every user inherits the full permission set of the account, regardless of role. That makes JIT access and timely revocation difficult to apply, especially when the organisation relies on password rotation instead of individual entitlements. The control failure is not just over-permissioning. It is the inability to express fine-grained authority at all, which forces teams to choose between operational convenience and access containment. In social media environments, that trade-off often pushes teams toward broad, persistent access that would be unacceptable in other parts of the enterprise. Practical implication: measure whether your social account model can actually express time-bound, role-bound access.
Practical implication: measure whether your social account model can actually express time-bound, role-bound access.
Threat narrative
Attacker objective: The objective is to exploit weakly governed social accounts to gain persistent, hard-to-attribute control over business communications and brand-facing assets.
- Entry occurs when access to a social media account is established through shared credentials, employee-owned accounts, or informal handoffs rather than enterprise-controlled provisioning.
- Escalation follows when multiple users and external collaborators inherit the same broad permissions, making access expansion and privilege retention hard to constrain or attribute.
- Impact emerges when offboarding, MFA recovery, or audit review fails to keep pace, leaving accounts exposed to takeover, misuse, loss of control, or reputational damage.
Breaches seen in the wild
- New York Times GitHub breach 2024: An exposed GitHub token gave an attacker The New York Times' repositories; the 270GB leak held 4,875 unique secrets.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Social media accounts expose a governance boundary that most IAM programmes still ignore: they are business identities without reliable federation, lifecycle automation, or individual accountability. That means the control model that works for SaaS, internal applications, and cloud platforms stops at the social platform edge. The practical conclusion is that organisations need to recognise disconnected identity surfaces as first-class governance scope, not as exceptions that marketing can self-manage.
Shared access is not merely inconvenient, it destroys the assumptions behind least privilege: once several people use the same credential, the organisation can no longer define who had which rights, when they were used, or when they should be removed. That breaks auditability and weakens recertification because the access artefact no longer maps cleanly to an individual. Teams should treat shared social accounts as a separate identity pattern with distinct control requirements, not as a normal user account problem.
Org-owned ownership models are the missing governance primitive for social channels: the account, recovery method, and MFA factor must belong to the business if lifecycle controls are to survive role changes and offboarding. This is the same principle that underpins disciplined lifecycle management in other identity domains, but social platforms make it unusually hard to enforce. The field should stop asking how to fit social accounts into legacy IAM and instead ask how to design governance around platforms that were never built for enterprise identity.
Identity automation fails at the edge when platforms refuse standardisation: access reviews, deprovisioning, and MFA enforcement all depend on stable identity plumbing. Where that plumbing does not exist, manual workarounds become the system of record, and policy degrades into tribal knowledge. The implication for practitioners is that governance maturity should be measured by how many critical business accounts remain outside the automated control plane, not by how complete the IAM stack appears on paper.
Disconnected social identities create an identity blind spot, not just a security inconvenience: the risk is operational continuity, attribution, and accountability as much as takeover resistance. When an organisation cannot centralise access to social channels, it cannot fully answer who has access, who approved it, or how quickly it can be removed. Practitioners should treat this as a structural programme gap that requires explicit exception handling and ownership decisions.
What this signals
Disconnected social accounts are a programme exception, not a niche edge case: if an organisation cannot federate, provision, and revoke access through its normal IAM stack, then it has an identity surface that sits outside its governance model. That should trigger explicit risk acceptance, compensating controls, and ownership decisions, rather than informal marketing-led administration.
Social media channels expose the limits of control-by-workaround: spreadsheets, email threads, and chat-based credential sharing may keep the business running, but they do not produce the evidence needed for audit, recertification, or incident response. The practical signal is simple: if access cannot be traced to an individual and removed cleanly, the control is not working.
Identity programme maturity now includes the ability to govern unmanaged business platforms: the question is not only whether IAM covers enterprise applications, but whether it can extend to channels that were built for consumer signup and shared operation. Where it cannot, the organisation needs a defined exception path and a separate operating model for those identities.
For practitioners
- Map disconnected social accounts as a separate identity class Inventory every business social media account, then record whether the account supports enterprise federation, automated provisioning, shared access, and business-owned recovery factors.
- Move account ownership to the organisation Use enterprise-controlled email addresses, phone numbers, and recovery methods so that no single employee, agency, or contractor controls continuity.
- Replace shared-password handoffs with tracked access governance Eliminate ad hoc sharing through email, spreadsheets, or chat, and require a documented process for granting and revoking access to each account.
- Test whether MFA is actually enforceable Verify that every social account can support centrally managed MFA factors that the organisation can route to authorised users without depending on one person.
- Treat social account deprovisioning as a lifecycle control Tie role changes, contractor exits, and agency handoffs to explicit review and removal steps so access does not persist after business need ends.
Key takeaways
- Social media accounts create an identity governance gap because platform design often prevents normal enterprise IAM and IGA controls from reaching them.
- Shared credentials, employee-owned factors, and manual handoffs weaken attribution, lifecycle management, and audit readiness across business channels.
- Organisations need separate governance for disconnected social accounts, with business-owned access, enforceable MFA, and explicit deprovisioning rules.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Social accounts lack consistent entitlement governance and user-level access control. |
| Recommendation — Apply PR.AA-05 to define, review, and revoke social account access as managed entitlements. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article centres on managing shared authentication factors and lifecycle. |
| Recommendation — Use IA-5 to govern social account credentials, ownership, and revocation paths. | ||
| MITRE ATT&CK | TA0006;TA0040 — Credential Access; Impact | Shared social credentials and account misuse map to credential access and brand-impact outcomes. |
| Recommendation — Map weak social account governance to TA0006 and TA0040 in detection and response planning. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article is fundamentally about account ownership, lifecycle, and access revocation. |
| Recommendation — Use CIS-5 to inventory social accounts and remove stale or orphaned access paths. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Offboarding and role changes fail when social accounts stay tied to individuals. |
| Recommendation — Apply NHI-01 to revoke social account access immediately when roles or relationships change. | ||
Key terms
- Disconnected Application: An application that is not integrated with the organisation's central identity and access stack. Access is often managed through shared passwords, manual approval, or local admins, which makes revocation, evidence, and ownership harder to enforce consistently across the application lifecycle.
- Shared credentials: Shared credentials are passwords, tokens, or access secrets used by more than one person or system. They weaken attribution and revocation because no single identity owns the secret cleanly, which increases blast radius when the credential is exposed or abused.
- Organisation-Owned Account: An organisation-owned account is a business account whose email, phone number, recovery methods, and authentication factors are controlled by the company rather than an individual. This model preserves continuity during role changes, enables policy enforcement, and reduces the risk of orphaned access.
- Identity automation: Identity automation is the use of rule-based workflows to carry out provisioning, revocation, reviews, and notifications when a trusted source system changes. It reduces manual effort, but its assurance depends on accurate triggers, stable entitlements, and clear exception handling.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org