Shared admin accounts still show up in finance platforms
Why shared break-glass and admin logins keep surviving access reviews — and what evidence actually proves they are controlled.
Shared admin logins survive because they feel practical during incidents. On finance platforms they also create unowned privilege: nobody can say who used the console last, and leavers sometimes keep the password in a personal vault.
In access control audits we treat shared accounts as privileged paths, not footnotes. We ask for the account inventory, the approval trail for each use, the logging destination, and the rotation schedule. Missing any of those four usually means the control is aspirational.
If your next review only counts MFA coverage, add a dedicated pass on shared and break-glass accounts. Fund-moving consoles deserve named humans, timed grants, and evidence you can show without reconstructing chat history.