Derivation rules
2,433 declarative match → where → emit rules
(1,787 derived, 646 explicit).
Filter by cloud, emitted edge, node type, or text.
A consumer reads a RAM-shared SecureString whose creds grant the owning account.
A consumer-account VPC with a confirmed (state==available) attachment to an owner-account Transit Gateway has L3 network reachability to subnets in the owner account (subject to TGW route table routing and L4 security group evaluation). This is a network-layer foothold (CanNetworkReach), not control-plane account entry (CanEnterAccount).
A VPC peering connection whose requester and accepter VPCs belong to different AWS accounts represents cross-account network trust. The peering connection record in the accepting account's AWS account constitutes the cross-account authorization artifact, enabling principals in the peer account to reach resources in this account if SG/routing permits.
A VPC endpoint policy (gateway or interface) granting access to principals in another AWS account enables cross-account access to the backing PaaS service via the endpoint path. The endpoint policy resource is the trust artifact (modeled as ResourcePolicy source).
A PrivateLink producer endpoint with an explicit permission granting access to a foreign account principal is exposed to cross-account consumption. This is a structural fact representing the intended cross-account data-plane exposure.
A VPC Lattice service network or service with authType NONE is accessible to any client in any associated VPC without IAM authentication - account-scoped exposure (or broader if the network is RAM-shared).
A consumer account principal with CreateServiceNetworkVpcAssociation on a RAM-shared service network can associate their VPC, gaining cross-account private reachability to owner-account services.
listKeys/action returns ADLS Gen2 account keys, bypassing all RBAC and ACLs.
An Automation Account sandbox job exposes its bound MI's token to any code it runs via the IMDS endpoint.
Code executing in an Automation Account sandbox can retrieve a bearer token for the bound MI from IMDS.
listKeys/action returns storage account keys, bypassing all Azure RBAC and network controls for all sub-services (when SharedKey auth is enabled).
Assuming/federating into a role in another account = entering it.
Federating into a Role homed in an AWS account gives the federated principal a foothold in that account.
CanEnterAccount
derived
A messaging resource policy that grants publish/subscribe to a principal in another account is cross-account trust (Pub/Sub topic IAM across projects emits CrossProjectTrust); feeds can-control's CanEnter* roll-up.
CrossAccountTrust
derived