Intel Report 023: Credential Exhaustion

SUMMARY: Credential exhaustion is the fatigue created when access depends on too many accounts, prompts, proofs, and recovery paths.

Modern systems ask users to remember passwords, rotate tokens, preserve backup codes, maintain devices, prove identity, answer risk checks, and recover through channels that may themselves require recovery.

Security improves when credentials are deliberate. Security decays when the credential layer becomes so noisy that people stop knowing which prompts are normal, which are urgent, and which are hostile.

Failure Modes

Prompt blindness: repeated checks train users to approve access requests without inspection.

Recovery sprawl: old emails, devices, phone numbers, and backup methods remain attached long after their trust has expired.

Role confusion: accounts keep privileges because nobody remembers which surface still depends on them.

Emergency drift: shortcuts created during incidents become permanent access paths.

Countermeasure

Pair credential review with access review and credential sovereignty. Reduce the number of paths, label the remaining paths, and test recovery before it is needed.

Operator Rule

Every credential should have an owner, a purpose, and a recovery path that still works.

Field assessment: access fails quietly before it fails completely.