| Name | Stable human-readable identity for the integration. | Include the system or workload purpose, not a person's name. |
| Description | Operational ownership and intended use. | State where the token is consumed and who is responsible for rotation. |
| Token expiry | Optional end time for the issued token. | Prefer explicit expiry where the integration can rotate predictably. |
| Active token | The current token may authenticate until expiry, rotation, revocation or archive. | Monitor last-use evidence and rotate according to the owning process. |
| Revoked | Existing tokens can no longer authenticate. | Reactivate only after confirming the integration and target environment are trusted. |
| Archived | The machine identity is retired from normal administration. | Create a new identity rather than attempting to reuse an archived one. |