A compromised identity has read-only access everywhere and no write anywhere — why can that still be a top-severity intrusion?
answer
- a permissions word, not an outcome word
- confidentiality needs no write
- configuration surfaces hold credentials
- grants are not the transitive closure
- the outage lens under-grades disclosure
basics
~20 sBecause severity is graded on what was reached, not on what was broken. A directory-wide, warehouse-wide reader reaches regulated records, secrets left in resource metadata, and a complete map of the estate. Confidentiality loss requires no write at all.
solid answer
~60 sRead-only is a statement about the write API surface, not about consequence. Grade the four dimensions of reach instead. **Data classification**: an identity with warehouse-wide read reaches whatever regulated tables the grants cover, and an unauthorised read of regulated records is a reportable event on its own, with no modification anywhere. **Credential and privilege reach**: read-only over configuration surfaces frequently means read over secrets — environment variables on functions, parameter and pipeline definitions, resource descriptions and tags, infrastructure state — each of which converts a reader into a writer. **Identity blast radius**: which roles this principal may assume and which groups it belongs to widen the set well beyond the grants you first enumerated. **Estate knowledge**: directory-wide read hands the intruder the map — which host, which role, which table is worth the next step. The colleague grading it low is applying an outage lens, where impact means something stopped working. An intrusion's cost here is disclosure, contractual and notification cost, and it lands without a single byte being changed.
go deeper
Know that severity for an intrusion follows what the intruder could reach, and that reading regulated records is a serious outcome even when nothing was changed or broken.
Be ready to name the dimensions — classification of reachable data, secret-bearing configuration in reach, the transitive role and group set, and regulatory exposure — and to explain how a reader becomes a writer.
Demonstrate that you enumerate the transitive reach rather than the direct grants, and that you can argue the grade down only on positive evidence you actually gathered.
Be prepared to explain why a grading standard built on service impact systematically under-grades disclosure, and what you would change in the standard so the two are not scored on one scale.
## Read-only describes an API surface, not an outcome `Read-only` is a permissions word. It says the principal cannot call the write operations. It says nothing about what the principal can learn, and learning is the entire point of most intrusions that end badly. Grading an intrusion by reach means asking what the intruder was in a position to obtain and to become — and a broad reader scores high on both. ## The four dimensions to grade **Data classification of what was reachable.** Start from the grants and join them to the classification labels on the datasets they cover. An identity holding read across a regulated warehouse reaches records whose unauthorised disclosure carries obligations independent of any modification. This is the dimension that most often drives the top grade, and it is entirely a confidentiality question. **Credential and privilege reach.** The most under-rated property of a broad reader is that configuration surfaces leak credentials. Function and task environment variables, parameter store entries the role can read, pipeline and job definitions, resource descriptions and tags, infrastructure state files, and warehouse tables loaded with a production extract for a test — all of these routinely hold API keys, connection strings and tokens. A read-only identity that reaches any of them stops being read-only in practice. When you grade, enumerate the secret-bearing surfaces in reach and treat every credential visible from them as potentially held. **Identity blast radius.** The grants you first enumerate are rarely the whole set. Which roles can this principal assume? Which groups is it in, and what do those groups confer? Does a workload identity elsewhere trust it? The graded reach is the transitive closure, not the direct grants, and the gap between the two is precisely what makes an hour-two grade provisional. **Regulatory and contractual exposure.** Some datasets carry obligations that attach on access rather than on harm. Whether those obligations are triggered is a legal assessment rather than yours to conclude, but whether the reachable data was of that class is a factual input you owe the assessment, and it belongs in the grade. ## Why 'nothing was damaged' is the wrong lens The instinct to grade a read-only compromise low comes from an availability-and-integrity model of impact: was the service down, was data corrupted, did customers notice. That model is the right one for an outage. It is the wrong one for an intrusion, where the classic worst outcome — a large disclosure of regulated records — produces no downtime, no corruption, no error rate and no customer-visible symptom at all. Reaching for damage as the grading dimension systematically under-grades exactly the intrusions that cost the most. ## Discovery and collection are steps, not the whole story There is a second reason a broad reader grades high, and it is about the future rather than the past. Directory-wide read gives the intruder an accurate inventory: naming conventions, the administrative accounts, which hosts sit in which boundary, which service holds the payment data. Every subsequent step gets cheaper and quieter, because the intruder no longer has to probe. Two identical intrusions where one has the map and one does not are not the same intrusion, and grading them the same because neither wrote anything misses it. ## What would honestly grade it down The symmetric discipline matters: you can argue the grade down, but only on positive evidence, never on the absence of a record. Legitimate arguments look like this. The grants were scoped to one non-regulated schema and the schema's contents were sampled and confirmed non-regulated. The transitive role-assumption set was enumerated and is empty. No secret-bearing configuration surface was inside the grants. The query records are complete for the window and show a bounded set of objects touched. Each of those is something you established, and each is defensible when someone asks how you know. `We saw no further activity` is not on the list. ## Saying it in an interview A strong answer names the dimensions and then makes the direction of the claim explicit: read-only bounds what the intruder could *change*, and bounds nothing about what they could *learn* or *become*. The grade follows the reach.
- Which raises the grade more: read of one small regulated table, or read across every non-regulated table in the warehouse?Usually the regulated table, because obligations attach to record classes and counts rather than to breadth. Breadth still matters, but it matters as estate knowledge and collection value rather than as disclosure exposure. Grade both dimensions rather than picking one, and say which is driving the number.
- Where do secrets typically turn up in reach of a read-only identity?Function and task environment variables, parameter store entries, pipeline and job definitions, resource descriptions and tags, infrastructure state files, and warehouse tables loaded with a production extract for testing. Each converts read-only reach into a write-capable credential, so enumerate them explicitly rather than assuming the write API surface bounds the intruder.
- How would you honestly argue this compromise down to a lower grade?With positive evidence only: the grants were scoped to one schema, its contents were sampled and confirmed non-regulated, the transitive role-assumption set was enumerated and empty, no secret-bearing configuration was in reach, and the query records for the window are complete and bounded. Quiet telemetry is not an argument.
A visitor who can open every filing cabinet but change nothing has still copied the whole company — and has read the note taped inside the door with the safe combination on it.
saying these in an interview costs you the question
- Grades on write access only and ignores confidentiality
- Says a read-only identity cannot escalate
- Assumes 'no data modified' means nothing reportable happened
- Applies an outage impact lens to an intrusion
- Enumerates direct grants and stops there