Platform Access Model
How a caller proves what it is to the platform and what that proof buys it: principals, attached permissions and short-lived credentials. Probed because one over-broad grant undoes the rest.
on this pageshowhide
explore
- Principals & Policy Attachment5 questions
- Short-Lived Credentials4 questions
- External Identity Trust4 questions
- Least Privilege & Scoping5 questions
- Privilege Escalation Paths5 questions
- Human Access & Break-Glass4 questions
- Credentials from the Machine5 questions
questions
page 2 of 2Should cross-team access to a shared resource be granted on the resource itself or on each consumer's identity?
level: principalimportance: nice to knowfreq 30%
basics
~20 sCrossing an account boundary needs both sides anyway, so the real decision is where the authoritative record lives. The resource side is the only one that can enumerate its consumers, which is why shared resources are usually made authoritative there.
A partner asks your cloud platform to trust their own identity provider so their systems can call yours directly; how do you decide whether to accept?
level: principalimportance: nice to knowfreq 28%
basics
~20 sDecide it as a delegation, not a configuration. Registering their issuer makes their identity administration part of your access decision, so weigh what the grant reaches, how reversible it is, and whether the caller could instead reach a boundary you operate.
showing 31–32 of 32