Service Accounts
Identity for the systems that aren't people
Automated systems need to access Metorial too, but they shouldn't run on a person's login. Service accounts give scripts, pipelines, and backend services their own identity, scoped to what they need and governed like any other actor.
- 01
Separate machines from people.
Give automation its own service account instead of sharing a person's credentials. Access stays clear and attributable.
- 02
Scope access precisely.
Cover the whole organization or limit a service account to a specific project, sandbox, or environment, with policies to match.
- 03
Govern and log it.
Service accounts run under full access control and audit logging, like any other actor.
What service accounts cover
Governed identity for automation
- ScopeOrganization, project, or environment
- API keys with custom scopesSupported
- Access control and policiesFull
- Audit loggingEvery action
Give automation its own identity. Scope it to one project. Govern what it can do. Log every action.
FAQ
Answers to common questions about service accounts and how they fit into governed AI agent infrastructure.
What is a service account?
A service account is an identity for an automated system rather than a person. Scripts, pipelines, and backend services use it to access Metorial without borrowing a user's credentials.Can I limit a service account's scope?
Yes. It can span the whole organization or be limited to a specific project, sandbox, or environment, with policies to match.How do service accounts authenticate?
With API keys for the Metorial API, using custom policies and scopes per key.Are service accounts governed?
Yes. The same policies and access control apply. They only do what they're allowed to.Is service account activity logged?
Yes. Every action a service account takes appears in audit logs.How are service accounts different from agent identities?
Agent identification is about identifying AI agents and the users behind them. Service accounts are identities for automated systems and integrations, used mainly for API access.