The job to be done
Find risky paths through cloud resources and fix the conditions that make them possible.
What goes in
- Cloud configuration and audit data
- Identity permissions
- Workload and deployment information
What should come out
- Exposure and entitlement findings
- Workload detections
- Preventive checks in delivery workflows
Questions worth asking
- Which accounts, regions, services, and workload types are covered?
- What permissions does the platform itself require?
- Can the team trace a finding back to the responsible infrastructure change?
A useful evaluation exercise
Model an intentionally public test resource, an overbroad role, and a sensitive data path. Explain how the conditions combine, then remove one.