Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when unused tokens and app connections…
Governance, Ownership & Risk

What breaks when unused tokens and app connections are left in place?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

Unused tokens expand the attack surface without adding business value. They create dormant paths into core systems that attackers can reuse if exposed or stolen. They also weaken compliance posture because teams may not know which integrations are still active, which data they can reach, or who is accountable for revocation and review.

Why This Matters for Security Teams

Unused tokens and app connections are not harmless leftovers. They are still live identities with path access, trust relationships, and sometimes delegated privileges that attackers can abuse long after the original business need has ended. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls treats access maintenance and revocation as ongoing control obligations, not one-time setup tasks.

The practical risk is that unused integrations are often undocumented, forgotten during offboarding, and excluded from routine review because nobody believes they are still important. That is exactly why incidents persist: dormant access blends into the background until a token is stolen, a vendor account is compromised, or an old automation quietly reaches a high-value system. NHIMG research on the 2025 State of NHIs and Secrets in Cybersecurity reports that 91% of former employee tokens remain active after offboarding, which shows how often lifecycle controls fail in practice.

In practice, many security teams discover these dormant paths only after an external scan, a breach investigation, or a cloud audit has already exposed them.

How It Works in Practice

Unused tokens and app connections break governance in three ways. First, they expand the attack surface by leaving valid credentials or OAuth grants in place even when the business function has ended. Second, they distort accountability because access reviews may show an active integration that no team claims to own. Third, they undermine revocation discipline, since teams often assume “inactive” means “safe” when the token may still authenticate successfully.

Operationally, the fix is not just deleting obvious secrets. Teams need a full inventory of issued tokens, service accounts, OAuth grants, API keys, certificates, and application-to-application trust paths, then map each item to an owner, purpose, scope, and expiry. Where feasible, high-risk integrations should use short-lived credentials, just-in-time issuance, and automated revocation on inactivity, closure, or role change. That approach aligns with the broader control logic in NIST SP 800-53 Rev 5 Security and Privacy Controls and with lifecycle-focused guidance in Guide to the Secret Sprawl Challenge.

  • Inventory all tokens and app connections, including shadow and third-party integrations.
  • Assign a named business and technical owner to every live credential or grant.
  • Set explicit TTLs where the platform allows short-lived access.
  • Revoke on inactivity, offboarding, vendor exit, or scope change.
  • Review logs for dormant access paths that still authenticate but no longer serve a business need.

NHIMG case research on the Salesloft OAuth token breach shows how delegated access can become a durable entry point when token hygiene is weak. These controls tend to break down in SaaS-heavy environments with multiple admins, delegated app marketplaces, and no central revocation workflow because ownership becomes fragmented across teams and vendors.

Common Variations and Edge Cases

Tighter token control often increases operational overhead, requiring organisations to balance reduced exposure against integration uptime and support burden. The tradeoff is especially visible when legacy systems, vendor-managed connectors, or long-running batch jobs cannot easily support short-lived credentials.

There is no universal standard for every environment yet, but current guidance suggests treating high-risk, internet-facing, or privileged connections more aggressively than low-impact internal automations. For example, a stale read-only reporting token is not equal to an unused admin grant tied to production data. In environments with shared service accounts, machine-to-machine workflows, or embedded credentials in CI/CD, the main challenge is often not discovery but safe replacement without breaking jobs. That is where lifecycle governance and change control have to work together.

The strongest programs pair periodic recertification with event-driven revocation, especially after vendor changes, access requests, incident response, or application retirement. NHIMG breach analysis in the Vercel Context.ai OAuth Supply Chain Breach reinforces a hard lesson: app-to-app trust that is left in place too long becomes a hidden supply chain risk, not just an admin cleanup issue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Unused tokens are a lifecycle failure and need revocation control.
OWASP Agentic AI Top 10A2Autonomous apps and agents can keep using stale credentials if left active.
CSA MAESTROIAM-03MAESTRO addresses identity lifecycle and trust for machine-to-machine access.
NIST AI RMFGOVERNAI governance requires accountability for non-human access paths and their revocation.
NIST CSF 2.0PR.AC-1Access control includes removing unnecessary authenticators and connections.

Maintain least privilege by removing credentials and grants that no longer support an approved business function.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org