← Inspection rules

SEC-008 / v1.2.0 / 2026-10-02

Inspect privileges enabling lateral access

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Environments where administrators, services, or CI can access production or separate data stores.

Where to look first

  • IAM, roles, service identities
  • Production token issuance, cross-environment access

Inspection steps

  1. Compare job needs with credential issuance, bulk-export, and privilege-grant capabilities.
  2. Document cross-environment paths available to a single compromised identity.

Remediation direction

  • Propose narrower roles and environment boundaries; test impact on required workflows.

Evidence required for completion

  • Record positive tests for allowed operations and negative tests for denied operations.

Limits and unverified scope

  • Broad privileges do not establish compromise. Production role changes follow owner authorization.