Organisation guardrails limit access but do not grant it
A guardrail can only take away. It never gives permission.
People are regularly confused when adding a service to the allowed list does not grant anybody access to it, because the identity still needs its own permissions. The two operate independently: one sets the maximum, the other grants within it, and both have to say yes.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
