Edge types

Filtered: category cross_boundary - 13 of 80. Clear

Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary walkable
Source can obtain a principal/session inside the target AWS account.
cross_boundary walkable high value
Source reaches org-level control (management account, org policy admin).
cross_boundary walkable high value
Source can gain access within the target GCP project.
cross_boundary walkable high value
Source can gain control-plane access within the target subscription.
cross_boundary walkable high value
Source can obtain a principal in the target Entra tenant (guest, multi-tenant app, B2B).
cross_boundary walkable high value
A credential harvested in one environment authenticates to another (cross-cloud/SaaS).
cross_boundary walkable
A trust/resource policy names a principal in another account (feeds CanAssume/CanEnterAccount). Produced by explicit normalization (policy artifact parsing) and by derived rules (cross-account data-resource sharing patterns like S3 bucket policy with foreign principal). Subscription targets cover Azure's account-boundary analog - a cross-subscription trust (e.g. an approved cross-subscription Private Endpoint connection, or cross-subscription VNet peering).
cross_boundary walkable
Cross-project IAM binding / SA usage. ServiceAccount targets cover a workload in one project running as (trusting) a service account owned by another project (e.g. a Vertex AI job or Workbench instance with a cross-project runtime SA) - symmetric with ServiceAccount as a source.
cross_boundary walkable
B2B/guest/multi-tenant app trust across Entra tenants.
cross_boundary walkable
An external/workload identity resolves to a concrete internal principal (guest->member, IdP subject->role, k8s SA->IAM role).
cross_boundary walkable
Identity in provider A is trusted to obtain an identity in provider B (OIDC/SAML/WIF). Enables cross-cloud paths.
cross_boundary walkable high value
Target trusts an external/federated/workload principal - inbound cross-boundary access (incl. k8s IRSA/WI federation). Source can be an identity (principal), a resource policy, or a policy document (e.g., B2C trust policy) that declares the trust.
cross_boundary walkable
move · open · esc close