Find and remediate inactive GCP service accounts with Wiz

Starting promptUse this prompt as a starting point to build your workflow.

Build a scheduled workflow that queries Wiz for GCP service accounts with no activity in 90+ days. For each, create a Jira ticket with the account details and a Slack notification, plus an action that disables the account in Google Cloud on analyst confirmation. Deduplicate against existing tickets, handle false positives via approval, and paginate results. Output the inactive accounts found and tickets created.

New to Tines?Sign up free for Tines 3B Explore Edition

What this prompt builds

Surface GCP service accounts unused for 90+ days via Wiz and open Jira tickets to disable them.

The problem

Dormant GCP service accounts accumulate as projects come and go, each a standing credential an attacker can abuse. Nobody proactively hunts them, so they pile up.

Solution and impact

This workflow uses Wiz to find GCP service accounts inactive for 90+ days, raises a Jira ticket per account, and gives the analyst a one-click prompt to disable it. Stale machine identities get cleaned up systematically, shrinking the attack surface.

Find and remediate inactive GCP service accounts with Wiz | Tines 3B examples | Tines