Organisation guardrails prevent dangerous local choices
Controls set at the organisation level apply regardless of what an individual account's administrator decides.
They stop a team disabling logging, leaving a region or removing a required configuration, even where they hold full rights in their own account. It is the one place a guardrail cannot be argued past locally, which is what makes it a guardrail rather than a guideline.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
- Unused cloud permissions are latent attack pathsStill wired
