The latest Salesloft breach is another reminder that identity management isn’t just about employees.

According to their advisory, the attacker who compromised Salesloft’s GitHub was able to:

  1. Download code from multiple repositories
  2. Add a guest user
  3. Establish workflows

That second point should make everyone pause. If a guest account can be added without approvals, monitoring, or alerts, it’s a clear gap in identity governance.

Guest users often fly under the radar — no proper lifecycle process (joiner/mover/leaver), no certifications, and sometimes broad privileges they shouldn’t have.

Identity governance isn’t a checkbox — it’s the guardrail that prevents small oversights from turning into massive supply chain risks.


Source: Salesloft security advisory