Edge types

Filtered: from AdministrativeBoundary to Identity - 4 of 80. Clear

Container holds child resources/objects: administrative boundaries, storage containers, data stores (SQL servers and their databases/firewall rules), secret vaults (Key Vault and its secrets/keys), management services and their artifacts.
structural
A trust/resource policy names a principal in another account (feeds CanAssume/CanEnterAccount). Produced by explicit normalization (policy artifact parsing) and by derived rules (cross-account data-resource sharing patterns like S3 bucket policy with foreign principal). Subscription targets cover Azure's account-boundary analog - a cross-subscription trust (e.g. an approved cross-subscription Private Endpoint connection, or cross-subscription VNet peering).
cross_boundary walkable
Cross-project IAM binding / SA usage. ServiceAccount targets cover a workload in one project running as (trusting) a service account owned by another project (e.g. a Vertex AI job or Workbench instance with a cross-project runtime SA) - symmetric with ServiceAccount as a source.
cross_boundary walkable
B2B/guest/multi-tenant app trust across Entra tenants.
cross_boundary walkable
move · open · esc close