azure-eventgrid-event-payload
Event data and metadata may contain secrets, personal data, or full customer records. No single Azure RBAC action authorizes the downstream destination; its own access control applies.
azurecritical
service: azure:eventgrid
emits CanReadData
Where it sits
| location | CloudEvents/Event Grid event.{data,subject,topic,eventType} |
| location kind | message_body |
| data kinds | credential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data |
| emits edge | CanReadData |
| service | Event Grid (azure:eventgrid) |
Collection recipe
| access mode | indirect_destination |
| operation | Read event at configured subscriber |
| response path | $value |
| encoding | json |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
References