CanDelegate

Domain-wide/OAuth delegation to act for other principals.

identity_authz AUTHORIZATION nature: both walkable weight 2
Identity, ApplicationIdentity  ── CanDelegate ──▸  Identity

Source types

Target types

Identity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureboth

Per-cloud

cloudpermissions / triggersnote
gcp -
azure -

Rules that emit CanDelegate 1

Service account with Domain-Wide Delegation can act as any active Workspace user in the domain for its configured OAuth2 scopes, without the user's knowledge or consent - a tenant-wide identity takeover primitive.
gcpderived
move · open · esc close