{
  "id": 4804283,
  "title": "Your access tool is a vendor with a copy of your infrastructure map",
  "url": "https://urgent.news/2026/09/01/your-access-tool-is-a-vendor-with-a-copy-of-your-infrastructure-map",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T06:46:55.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/alektoreef/your-access-tool-is-a-vendor-with-a-copy-of-your-infrastructure-map-4ikb"
  },
  "original_language": "en",
  "account": "Your access tool is essentially a vendor that holds a copy of your infrastructure map. Security questionnaires often ask where customer data is processed, but access-control tools tend to receive a cursory answer, as they are perceived as merely gatekeepers rather than data processors. However, they serve both roles. A hosted access broker possesses comprehensive knowledge about your infrastructure, including your infrastructure inventory (such as hostnames, addresses, cluster endpoints, database names, and environment labels), your organizational structure (including access rights and approval processes), session content (such as commands, queries, and output), and timing (such as incident occurrences and escalation procedures). This information is crucial for an attacker, as it provides a detailed map of your estate, enabling them to determine where to focus their efforts.",
  "summary": "Disclosure: I work on Tessera, which is self-hosted. That is the position I am arguing from, and the costs of that position are in the last section. Security questionnaires ask where customer data is processed. Access-control tools tend to get a shallow answer to that question, because people think of them as gatekeepers rather than as data processors. They are both. Here is what a hosted access…",
  "key_points": [
    "Access tool is a vendor with infrastructure map copy",
    "Security questionnaires overlook access-control role",
    "Hosted access broker knows infrastructure details"
  ],
  "editors_take": "This development implies that access-control tools, previously viewed as mere gatekeepers, are now recognized as data processors that hold sensitive information about a company's infrastructure, making them a potential vulnerability.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}