Spoonlabs runs live audio and short-form video platforms with an engineering estate that grew the way successful products do: quickly, across more than one code host, more than one cloud, and a set of collaboration tools that everyone writes into.
That shape is what makes machine-identity risk hard. A credential pasted into a ticket, committed to a repository years ago, or left in a storage bucket is not visible from any single tool. The question was never whether something had been left behind. It was where, and which of it still worked.
The proof of concept connected six platforms at once rather than starting with code alone: object storage, two code hosts, an issue tracker, a wiki, and the messaging workspace. Credentials cross those boundaries in practice, so looking at one of them answers the wrong question.
Scanning went through commit history rather than current files, because a secret removed in a later commit is still in the history and usually still valid. Documents, tickets and messages were read the same way.
Then every finding was checked against the service that issued it. That step is what turns a detection list into a work list: it separates the credentials that still authenticate from the ones that were revoked or rotated long ago, and only the first group is worth anyone's time.
Eight days took the engagement from nothing connected to a verified picture: what exists, where it lives, which of it still works, and what to close first.
The order mattered more than the count. Credentials with direct financial or infrastructure reach were separated from the larger group of messaging and collaboration tokens, so the work started where the damage would be worst rather than where the volume was highest.
The detection curve had not flattened when the window closed, which is the honest finding: coverage was still expanding into history that had not been reached. That is the argument for continuous scanning over an audit. An audit ends, and the estate does not.