CanAssume

Source can obtain the target identity's credentials/session (role assumption).

identity_authz AUTHORIZATION nature: both walkable weight 1 high value
Identity  ── CanAssume ──▸  Role, MachineIdentity, ServiceAccount

Source types

Identity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureboth
conditionstrust_relationship iam_permission condition_expression scp_or_org_policy

Per-cloud

cloudpermissions / triggersnote
aws sts:AssumeRole sts:AssumeRoleWithWebIdentity sts:AssumeRoleWithSAML Requires role trust policy to allow source.
gcp iam.serviceAccounts.getAccessToken iam.serviceAccounts.getOpenIdToken iam.serviceAccounts.signJwt Short-lived credential minting = de facto assume.
azure - No direct STS analog; approximate via MI assignment / SP credential add. Prefer CanCreateCredentialFor. Do not equate to AWS AssumeRole.

Rules that emit CanAssume 3

awsderived
move · open · esc close