azure-eventgrid-event-payload

Event data and metadata may contain secrets, personal data, or full customer records. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurecritical service: azure:eventgrid emits CanReadData

Where it sits

locationCloudEvents/Event Grid event.{data,subject,topic,eventType}
location kindmessage_body
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceEvent Grid (azure:eventgrid)

Collection recipe

access modeindirect_destination
operationRead event at configured subscriber
response path$value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close