Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
4 to work through
-
intermediate
Forty developers share one service account to access a partner API because the partner charges per credential. What do you do?
2 min answer -
advanced
A workforce platform holds identity, payroll and device management, and integrates with dozens of downstream systems. What is the central security risk and how is it bounded?
2 min answer -
advanced
An enterprise platform's permission model has grown to thousands of roles and profiles, and nobody can determine what access a given user actually has. What is the diagnosis and the remediation?
2 min answer -
advanced
Design the break-glass access mechanism for production. What are the requirements?
2 min answer
5 terms in this topic
Break-Glass Access
A pre-agreed, heavily audited path to elevated privilege for emergencies, replacing standing administrative access.
case-studyCapital One 2019: From SSRF to the Metadata Endpoint
A server-side request forgery reached the cloud instance metadata service, obtained temporary credentials, and used an over-permissioned role to read…
conceptPermission Boundary
A policy limiting the maximum permissions an identity can have, used so that the ability to create roles does not become the ability to grant unlimit…
conceptPrivilege Creep
The gradual accumulation of access as people change roles without losing prior permissions, producing long-tenured staff with far more access than an…
conceptWorkload Identity
Giving a running workload a cryptographic identity derived from its platform context, so it can authenticate without a stored credential.
1 artifact you would hand over
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.