← Inspection rules
SEC-008 / v1.2.0 / 2026-10-02
Inspect privileges enabling lateral access
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Environments where administrators, services, or CI can access production or separate data stores.
Where to look first
- IAM, roles, service identities
- Production token issuance, cross-environment access
Inspection steps
- Compare job needs with credential issuance, bulk-export, and privilege-grant capabilities.
- Document cross-environment paths available to a single compromised identity.
Remediation direction
- Propose narrower roles and environment boundaries; test impact on required workflows.
Evidence required for completion
- Record positive tests for allowed operations and negative tests for denied operations.
Limits and unverified scope
- Broad privileges do not establish compromise. Production role changes follow owner authorization.