Every large organization should assume that they have been breached. The goal of attackers is not to impersonate people. The goal is to get to something. Data of some kind can be used to make money (mostly) or obtain some kind of information advantage, or even operation privileges, simply to cause havoc in the network. Human accounts should only be used by a single automated process, with granular privilege levels that manage them. Step beyond those that just detect malicious behaviour from non-humans.”]
Source: https://informationsecuritybuzz.com/articles/privileged-humans-arent-security-problem/