Tool simulation
Risk Ranking
Trust-boundary workflow
Rank the riskiest finding first.
1.Inspect the caller, privilege path, and policy boundary.
2.Simulate how the unsafe trust edge grants access or increases blast radius.
3.Submit the risky role, control gap, or containment keyword.
AWSIAMS3EC2LambdaCloudTrailus-east-1 · lab
Security finding: user ci-deployer@acme-cloud.iam has an over-permissive identity. Inspect the highlighted principal below.
| Identity | Role / group | MFA | Key age |
|---|---|---|---|
| ci-deployer@acme-cloud.iamfinding | roles/owner | Not enabled | 2 days |
| admin-user | Admins | Enabled | 180 days |
| ci-deploy | CI | Not enabled | 90 days |
Principal / input
{
"serviceAccount": "ci-deployer@acme-cloud.iam",
"roles": ["roles/owner"]
}Policy / boundary
scope: unknown
Tool consolehelp · inspect · simulate <subject> · scope <control> · submit
Iam Sim Lab ready.
Type help for commands: help · inspect · simulate <subject> · scope <control> · submit
Quick start: inspect, simulate, scope, policy, submit.
Focus on where privilege crosses the trust boundary.