Cross-account trust expands the identity perimeter
Letting another account assume a role in yours extends your identity perimeter to include everybody who can assume it there.
The trust is often written broadly during setup and never narrowed. Whoever compromises the other account inherits that path. Trust relationships deserve the same review as user permissions and almost never receive it, because they are configured once and forgotten.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Console access and workload access are different pathsTwo doors, one room
- Unused cloud permissions are latent attack pathsStill wired
