The ThoughtWorks Technology Radar (April 2026) flagged something under "Caution" that describes one instance of a problem we encountered from a completely different direction — implementing S3 bucket takeover findings from HackerOne triage work:

When the spreadsheet that quietly runs the business evolves into customized agentic workflows that lack governance, it introduces significant security risks and a proliferation of competing solutions to similar problems.

The problem ThoughtWorks describes is about the lifecycle of cloud resources. That lifecycle has been producing ungovernered risk long before AI workflow tools existed.

When we triaged S3 bucket takeover reports on HackerOne, the pattern was clear: a team creates a bucket, uses it, stops using it, deletes it — but the DNS record, the CloudFront distribution, or the application code still references the old bucket name. An attacker creates a new bucket with the same name and takes over the traffic. The resource was deleted. The references were not deleted. The lifecycle wasn't governed.

This is the same structural problem at every phase: