Permission boundaries cap delegated power
A permission boundary sets a ceiling: whatever permissions somebody is granted, they cannot exceed it.
It is what makes safe delegation possible, letting a team create roles without being able to create one more powerful than their own. Without it, the ability to create roles is effectively the ability to grant yourself anything, which is a common and quiet escalation path.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
- Unused cloud permissions are latent attack pathsStill wired
