What it defends against¶
The threat model is its own document: THREAT-MODEL.md, STRIDE per component, ranked by likelihood and impact, each threat mapped to the control that answers it, with the accepted risks recorded as decisions. The premise that shapes it: this database is a map of every identity in the target account and of what each is supposed to hold, which is exactly the reconnaissance an attacker wants, so the tool that reduces identity risk is itself a concentration of it.