# Change the State of Exposed Credentials

Record what you did about a leaked credential by ignoring it, accepting the risk, or marking it as resolved or as a false positive, one at a time or in bulk, and revert the change.

Source: https://docs.deepinfo.com/guide/cti/change-credential-state/

Last updated: 2026-09-26

---
When you have dealt with a leaked credential, record it by changing the credential's state: ignore it,
accept the risk, or mark it as resolved or as a false positive. The steps below are for the credentials of
your employees. Client and payment credentials have states too.

## Before You Start

- **Package:** Cyber Threat Intelligence (CTI).
- **Role:** Admin or Member.
- You need at least one exposed credential on the
  [EXPOSED CREDENTIALS](/guide/cti/credential-exposures/) tab.

## Where to Find It

**Sidebar:** **CYBER THREAT INTELLIGENCE** › **COMPROMISED EMPLOYEE DATA** · **Tab:** **EXPOSED CREDENTIALS** · https://platform.deepinfo.com/app/cti/compromised-employee-data/credential-exposures

The state of a credential appears in these places:

| Where | What you can do there |
|---|---|
| **EXPOSED CREDENTIALS** tab | Select a **STATE** chip, or select rows for a bulk change. **SHOW INACTIVES** includes inactive credentials |
| Credential drawer (select a row on **EXPOSED CREDENTIALS**) | **⋮** › **CHANGE STATE** |
| Employee's page, **CREDENTIALS** tab | **STATE** column and a header checkbox to select rows; **SHOW INACTIVES** |
| Employee drawer, **CREDENTIALS** tab | **STATE** column; **SHOW INACTIVES** |
| **COMPROMISED CLIENTS** tab of [Compromised Client Credentials](/guide/cti/compromised-client-credentials/) | **STATE** column; **SHOW INACTIVES** |
| **COMPROMISED PAYMENTS** tab of [Compromised Payment Credentials](/guide/cti/compromised-payment-credentials/) | **STATE** column |

## Change One Credential From Its State Chip

1. On the **EXPOSED CREDENTIALS** tab, find the credential. Tick **SHOW INACTIVES** if it is already inactive.
2. Select its **STATE** chip, for example **ACTIVE · UNRESOLVED**.
3. A menu headed **CHANGE STATUS** opens. Select **IGNORE**, **ACCEPT RISK**, **MARK AS RESOLVED** or
   **MARK AS FALSE POSITIVE**.
4. If the platform asks you to confirm, confirm the change.

To close the menu without a change, select **CANCEL**.

![The CHANGE STATUS menu open on a STATE chip in the EXPOSED CREDENTIALS list.](/img/guide/cti/change-credential-state-01.png)

## Change One Credential From Its Drawer

1. On the **EXPOSED CREDENTIALS** tab, select the credential's row to open its drawer.
2. Open the **⋮** menu and select **CHANGE STATE**.
3. The **Change State** window shows **CURRENT STATE:**, for example "ACTIVE - UNRESOLVED", and a
   **MARK AS:** list with **IGNORED**, **RISK ACCEPTED**, **MARKED AS RESOLVED** and
   **MARKED AS FALSE POSITIVE**. Choose the new state.
4. Select **CHANGE**. **CANCEL** closes the window without a change.

> [!IMPORTANT]
> **MARK AS:** is already set to **IGNORED** when the window opens. Check it before you select **CHANGE**,
> or the credential is ignored.

![The Change State window with CURRENT STATE, the MARK AS list, CANCEL and CHANGE.](/img/guide/cti/change-credential-state-02.png)

## Change Several Credentials at Once

1. Tick the rows you want to change. The checkbox in the header has a menu with **SELECT THIS PAGE**,
   **SELECT ALL RESULTS** and **CLEAR SELECTION**.
2. Select **CHANGE ALL STATES**.
3. Under **TO:**, choose the new state.
4. If the platform asks you to confirm, confirm the change.

You can do this on the **EXPOSED CREDENTIALS** tab and on the **CREDENTIALS** tab of an employee's page.

> [!WARNING]
> **SELECT ALL RESULTS** selects every result, on every page, not only the rows you can see, and the state
> you choose next applies to all of them. Use it only when you mean to change every result. Otherwise, tick
> the rows or use **SELECT THIS PAGE**, so that you can see each credential you change.

## Revert a Change

The states you set can be reverted. When the current state allows it, the **Change State** window
shows a **REVERT STATE** link. Reverting returns the credential to its previous, active state.

> [!CAUTION]
> Select **REVERT STATE** only when you mean to revert. It can take effect as soon as you select it, without
> asking you to confirm.

## The States

A credential's state is shown as a two-part chip: the group, then the state, for example
**ACTIVE · UNRESOLVED**.

| Group | State | Set by | Action that sets it |
|---|---|---|---|
| **ACTIVE** | **NEWLY DETECTED** | the platform | None |
| **ACTIVE** | **UNRESOLVED** | the platform | None |
| **INACTIVE** | **NOT APPLICABLE** | the platform | None |
| **INACTIVE** | **VERIFIED RESOLVED** | the platform | None |
| **INACTIVE** | **IGNORED** | you | **IGNORE** |
| **INACTIVE** | **RISK ACCEPTED** | you | **ACCEPT RISK** |
| **INACTIVE** | **MARKED AS RESOLVED** | you | **MARK AS RESOLVED** |
| **INACTIVE** | **MARKED AS FALSE POSITIVE** | you | **MARK AS FALSE POSITIVE** |

Only the states you set (**IGNORED**, **RISK ACCEPTED**, **MARKED AS RESOLVED** and **MARKED AS FALSE
POSITIVE**) can be reverted. States set by the platform cannot.

Issues and vulnerabilities in External Attack Surface Management (EASM) use a similar set of states; see
[Change the state of issues and vulnerabilities](/guide/easm/change-issue-state/).

## Good to Know

- **Inactive credentials leave the list.** The states you set are inactive, so the credential drops
  out of lists that show active credentials only. Tick **SHOW INACTIVES** to see it again.
- **Changes take a few seconds.** The new state can take a few seconds to show. Wait for the list to refresh
  before you check the result.
- **Follow-up.** The **CREDENTIAL STATUS STATS** card on the [CTI dashboard](/guide/cti/dashboard/) and
  **STATUS STATS** on the [overview](/guide/cti/compromised-employee-data/) count active and inactive
  credentials. On the **COMPROMISED EMPLOYEES** tab, the **STATE** filter chip finds employees by the states
  of their credentials, for example by **Unresolved Credential Count**.

## Do This With the API

Employee credentials:

- [Compromised Employee Credential Ignore](/reference/cti/compromised-employee-credential-ignore/)
- [Compromised Employee Credential Accept Risk](/reference/cti/compromised-employee-credential-accept-risk/)
- [Compromised Employee Credential Mark Resolved](/reference/cti/compromised-employee-credential-mark-resolved/)
- [Compromised Employee Credential Mark False Positive](/reference/cti/compromised-employee-credential-mark-false-positive/)
- [Compromised Employee Credential Revert](/reference/cti/compromised-employee-credential-revert/)

Client credentials:

- [Compromised Client Credential Ignore](/reference/cti/compromised-client-credential-ignore/)
- [Compromised Client Credential Accept Risk](/reference/cti/compromised-client-credential-accept-risk/)
- [Compromised Client Credential Mark Resolved](/reference/cti/compromised-client-credential-mark-resolved/)
- [Compromised Client Credential Mark False Positive](/reference/cti/compromised-client-credential-mark-false-positive/)
- [Compromised Client Credential Revert](/reference/cti/compromised-client-credential-revert/)

Payment credentials:

- [Compromised Payment Credential Ignore](/reference/cti/compromised-payment-credential-ignore/)
- [Compromised Payment Credential Accept Risk](/reference/cti/compromised-payment-credential-accept-risk/)
- [Compromised Payment Credential Mark Resolved](/reference/cti/compromised-payment-credential-mark-resolved/)
- [Compromised Payment Credential Mark False Positive](/reference/cti/compromised-payment-credential-mark-false-positive/)
- [Compromised Payment Credential Revert](/reference/cti/compromised-payment-credential-revert/)

> [!WARNING]
> These endpoints change every record that matches the filter you send, and an empty filter matches all
> records. Always send a filter.
