CanRemoveMember

Membership removal - mostly destructive/persistence, not escalation; not walked by default.

identity_authz AUTHORIZATION nature: explicit not walkable
Identity  ── CanRemoveMember ──▸  Group, Role

Source types

Identity

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit CanRemoveMember 1

Principal with cloudidentity.groups.memberships.delete (or group Manager/Owner) can remove members from the target group, enabling member deprovisioning or audit-trail destruction.
gcpderived
move · open · esc close