Skip to main content

Deactivation

Deactivation recommends removing or disabling a secret that is unused or has never been used within a 60-day period, based on upstream provider logs.

Supported Integrations

The following integrations support secret deactivation:

Ledger recommends deactivation for a long-lived secret when usage logs in the upstream platform show that it has not been used within a 60-day period.

Ledger also does not recommend any cleanup actions for workloads that have the unused secret in their configuration.

What does the workflow look like?

Ledger walks you through the following steps, providing detailed guidance based on the target upstream provider:

  1. Review the target secret and usage information.
  2. Remove or disable the secret in the upstream provider.

Ledger automatically closes the remediation workflow when the secret is deactivated, but you may need to re-run an integration scan to refresh the inventory for latest secret status.

Outcome

The secret is disabled or deleted in the upstream provider, and is no longer an available attack vector.