Skip to content

Improve access review effective entitlement expansion gates#1408

Open
MAUROCERON wants to merge 1 commit into
UnitOneAI:mainfrom
MAUROCERON:improve/access-effective-entitlements-1404
Open

Improve access review effective entitlement expansion gates#1408
MAUROCERON wants to merge 1 commit into
UnitOneAI:mainfrom
MAUROCERON:improve/access-effective-entitlements-1404

Conversation

@MAUROCERON

Copy link
Copy Markdown

Implements #1404.

Summary

  • Adds an effective entitlement expansion gate before access certification decisions.
  • Requires direct entitlement, transitive path, dynamic/birthright source, effective permission, source of authority, certifier visibility, and Not Evaluable handling.
  • Adds edge-case fixtures for nested groups, dynamic group rules, inherited cloud IAM bindings, application-local roles, and complete expanded evidence.

Validation

  • Markdown fence balance check for touched files.
  • Marker checks for AR-EFF rules, transitive path, dynamic/birthright source, effective permission, certifier visibility, Not Evaluable, and the effective entitlement expansion matrix.
  • Reference URL checks for Microsoft Graph transitive memberOf, Google Cloud Policy Analyzer, and AWS IAM Access Analyzer unused access.
  • Private payment details were not included in files or public issue/PR text.

Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant