KeyHorizon
A non-human credential lifecycle actuator that inventories metadata without secrets, builds an evidence-backed dependency graph, stages expiry or revocation plans, and executes only approved provider-supported actions with health readback and recovery.
Enterprise authorization grants, service accounts and agent keys can outlive their owners and intended purpose. The research confirms an enterprise lifecycle incumbent and a broad connector substrate, but no reviewed product combining blast-radius evidence with a mid-market revocation actuator. Connector availability does not prove that required lifecycle actions or rollback exist.
KeyHorizon should separate credential identity and metadata from secret value, issuer and provider, owner and purpose, creation and last verified use, expiry and rotation support, permissions and reachable resources, dependency observation and uncertainty, blast-radius evidence, stale candidate, owner attestation, canary and maintenance window, revocation or rotation plan, security approval, exact command, provider acknowledgment, service health readback, incident, replacement or restore plan, reconciliation and outcome.
Many revocations are irreversible. The product must never promise un-revocation, expose or copy secret material, revoke from absence of observed use alone, infer ownership, execute automatically in production, bypass provider controls or present a blast-radius score as proof of compromise, misuse or safe removal.
Enterprise identity, platform-security and service-ownership teams responsible for non-human credentials and stale authorization grants.
A reusable evidence and provider-action layer can scale across supported credentials.
Fast credential retirement must coexist with incomplete dependency evidence, irreversible provider semantics and production availability.
The record does not prove which actuation or trust barrier recently changed.
A clear non-human identity problem, confirmed enterprise lifecycle tooling and an actuation gap make a staged retirement workflow testable.
Required providers, action and rollback semantics, dependency coverage, enterprise trust, buyer budget, liability and differentiation need validation.
Discussion
No comments yet — be the first to weigh in.
