File Upload & Scanning Pipeline · View 21 of 21 · Assurance
Decisions
- The storage account trusts only the platform's own identity; every client credential is derived from it, scoped to one object path and one verb
- No long-lived or account-wide storage key is ever handed to a client, and no credential spans two objects
- The scan plane holds a workload identity that can read the untrusted plane and write verdicts — and nothing that can change a lifecycle state
What this makes impossible
- Enumerating another tenant's objects with a leaked upload credential, because the credential names one path and grants no list
- Reading an object you uploaded but were never authorised to read, because read authorisation is evaluated at download time against current state
- Keeping access after a revocation for longer than the credential's 5 minutes
Stated assumptions
- Entra ID is the identity provider for both workforce and customer identities
- User-delegation SAS, derived from the platform's managed identity, is the credential mechanism
- Customer-managed keys available to tenants that require them