{
  "slug": "shared-account-attribution",
  "title": "The audit log says admin. Which human was that?",
  "summary": "Shared credentials make audit logs complete and useless. You cannot delete every shared account. You can make consequential actions carry a personal signature.",
  "lede": "Six people know the password to the account that exported the customer table. The log is complete, timestamped, and names a credential rather than a person. Deleting shared accounts is not achievable everywhere, so the achievable goal is different: let the credential stay shared and make the action personal.",
  "date": "2026-09-20",
  "reading_time": "13 min read",
  "category": "Security",
  "tags": [
    "shared accounts",
    "audit attribution",
    "PCI DSS",
    "privileged access",
    "break glass",
    "compliance"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Shared%20Account%20Attribution/1200_630/blog.jpg",
  "url": "/blog/shared-account-attribution.html",
  "wordcount": 5293,
  "related": [
    "audit-trail-design",
    "who-approved-this-deploy",
    "offboarding-orphaned-authority"
  ],
  "schema": "Article"
}