|
SaaS Agent Security detected an agent that has shown no
activity for over 30 days. Specifically, the agent has not had any
chat interactions within the last month.
A dormant agent represents an unnecessary security risk because,
although it is not being used, it might still have active tokens or
permissions to connected applications or knowledge bases. If the
agent becomes compromised, its inactivity might delay detection of
malicious use.
For example, an agent developer might have created an agent for a
specialize purpose and created a service account for it to connect
to an application. The developer leaves the company, and, although
the agent is not being used, it still has permissions to the
connected application.
You should review the identified dormant agent to determine if it's
needed. If the agent is no longer needed, you should deactivate or
remove it to reduce potential attack surfaces.
|