Term Kind Topic What it is
Break-Glass Access Emergency Access, Just-in-Time Elevation practice Identity & Access Management A pre-agreed, heavily audited path to elevated privilege for emergencies, replacing standing administrative access.
Capital One 2019: From SSRF to the Metadata Endpoint IMDSv1 Breach case-study Identity & Access Management A server-side request forgery reached the cloud instance metadata service, obtained temporary credentials, and used an over-permissioned role to read a very large volume of data.
Permission Boundary concept Identity & Access Management A policy limiting the maximum permissions an identity can have, used so that the ability to create roles does not become the ability to grant unlimited privilege.
Privilege Creep Access Accumulation, Permission Sprawl concept Identity & Access Management The gradual accumulation of access as people change roles without losing prior permissions, producing long-tenured staff with far more access than anyone intended.
Usage-Based Access Review Last-Used Entitlement Review, Evidence-Based Access Recertification practice Identity & Access Management Recertifying entitlements against observed use rather than against manager approval, so unused permissions are removed by default instead of being re-approved by someone who cannot evaluate them.
Workload Identity SPIFFE, Managed Identity, Service Identity concept Identity & Access Management Giving a running workload a cryptographic identity derived from its platform context, so it can authenticate without a stored credential.