Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Social media account governance: what IAM teams need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Enterprise social accounts create identity, audit, and approval risks because credentials are often shared across staff and agencies, which weakens attribution and enables misuse, according to Island. The governance failure is not the channel itself but the absence of role-bound access, step-up approval, and removal of standing credentials when account access changes.

NHIMG editorial — based on content published by Island: The Social Dilemma: How to Make Social Media Platforms Safe for the Enterprise

Questions worth separating out

Q: How should enterprises govern shared social media accounts?

A: Enterprises should treat shared social media accounts as privileged access paths with named roles, explicit approvals, and immediate offboarding.

Q: Why do social media platforms create identity governance risk for enterprises?

A: They were designed for individual users, not organisations with shared authority and compliance obligations.

Q: What breaks when departing staff keep access to company social accounts?

A: The organisation loses control over who can publish on its behalf, which creates brand, disclosure, and compliance exposure.

Practitioner guidance

  • Define posting authority as a privileged role Create explicit roles for author, approver, publisher, and auditor so social media access is no longer treated as a shared team entitlement.
  • Remove standing access at offboarding Revoke social account access immediately when employees, contractors, or agencies leave or rotate out of a campaign, and verify that shared credentials are not retained in browsers or password stores.
  • Enforce step-up approval for high-risk posts Require a second approval before any post that could disclose financial results, merger activity, legal claims, or other material information.

What's in the full article

Island's full blog post covers the operational detail this post intentionally leaves for the source:

  • Browser-enforced controls for managing login, publishing, and data movement inside social platforms.
  • Examples of how policy can block screenshots, uploads, copy-paste, and uncontrolled posting.
  • Details on session attribution and visibility for shared accounts across device, location, and network context.
  • Operational examples of RPA-style interface control for limiting who can see the publish action.

👉 Read Island's analysis of enterprise social media governance and access control →

Social media account governance: what IAM teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Social media account governance is an identity problem before it is a content problem. The article is really describing delegated public authority, not marketing workflow. Once multiple humans and external agencies share the same account, accountability becomes ambiguous and privileged access management loses its normal person-to-action mapping. Practitioners should treat public posting authority as governed enterprise access, not as a loose collaboration habit.

A few things that frame the scale:

  • 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how quickly delegated access outpaces governance.

A question worth separating out:

Q: Who is accountable when a shared social account posts sensitive information?

A: Accountability should rest with the organisation that owns the account and the process that allowed the post, not with the platform alone. Security, legal, and communications leaders all have a role because the incident usually reflects a governance gap across identity, approval, and policy enforcement rather than a single technical failure.

👉 Read our full editorial: Enterprise social media access needs stronger identity controls



   
ReplyQuote
Share: