Edge types
Filtered:
category identity_authz
- 14 of 80.
Clear
Source can add a principal (itself) to a group/role and inherit its permissions.
identity_authz
walkable
high value
Source can obtain the target identity's credentials/session (role assumption).
identity_authz
walkable
high value
Domain-wide/OAuth delegation to act for other principals.
identity_authz
walkable
External/workload identity is trusted to federate into a CSP identity (OIDC/SAML/Workload Identity).
identity_authz
walkable
high value
Source can assign a role/permission to a principal (incl. itself) - privilege escalation primitive.
identity_authz
walkable
high value
Source acts as target without holding long-lived creds (GCP SA impersonation, act-on-behalf-of).
identity_authz
walkable
high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz
walkable
high value
Source can rewrite who may assume/impersonate the target - self-grant assumption.
identity_authz
walkable
high value
Source may attach/pass the target identity to a NEW or existing workload (prereq for CanExecuteAs).
identity_authz
walkable
high value
Membership removal - mostly destructive/persistence, not escalation; not walked by default.
identity_authz
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz
walkable
A policy artifact is attached to a principal/resource. Feeds the permission evaluator; not walked directly.
identity_authz
Principal is directly granted a role (Entra role, GCP role binding, IAM role attachment).
identity_authz
walkable
Source inherits the target's permissions via membership.
identity_authz
walkable
high value