GenericPolicy
class: Policy derivation-only - no collection recipe
Realizing resources
This type has no collection recipe - it appears only as the endpoint of derived edges.
As edge target
Exposure sites
None.
Rules that touch GenericPolicy 8
memorydb:CreateUser + memorydb:UpdateAcl creates a privileged ACL user and adds them to a cluster's ACL; with VPC reach, principal can then read all cluster data.
aws
CanReadDatamemorydb:CreateUser + memorydb:UpdateAcl creates a privileged ACL user; with VPC reach, principal can then write all cluster data.
aws
CanWriteDataA principal with IdentityProvider.ReadWrite.All or Global Admin can inject a malicious external IdP into a B2C user flow.
azure
CanModifyConfigurationAn Event Grid topic exposes its access key to any principal who can call listKeys/action; the key is a long-lived publish credential for the topic.
azure
ExposesCredentialA principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
azure
CanModifyPolicyclouddeploy.deployPolicies.override bypasses a Cloud Deploy time-window restriction, enabling rollouts during governance freeze windows.
gcp
CanModifyPolicy