skip to content

Platform Access Model

How a caller proves what it is to the platform and what that proof buys it: principals, attached permissions and short-lived credentials. Probed because one over-broad grant undoes the rest.

on this pageshow

questions

page 2 of 2

Should cross-team access to a shared resource be granted on the resource itself or on each consumer's identity?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Crossing an account boundary needs both sides anyway, so the real decision is where the authoritative record lives. The resource side is the only one that can enumerate its consumers, which is why shared resources are usually made authoritative there.

open as a page

A partner asks your cloud platform to trust their own identity provider so their systems can call yours directly; how do you decide whether to accept?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Decide it as a delegation, not a configuration. Registering their issuer makes their identity administration part of your access decision, so weigh what the grant reaches, how reversible it is, and whether the caller could instead reach a boundary you operate.

open as a page

showing 31–32 of 32