Skip to content

Acknowledgements

The ideas here were learned from projects and publications that came first. Ideas are free to take; taking them namelessly is not how this project works. Where a lesson was taken, the source is named; where a gap remains, the documents say so.

  • Repokid (Netflix). Finding unused permissions is easy and removing them safely is the product; its staged, reversible removal shapes the action phases, and its eligibility idea became the minimum observation age.
  • Cloudsplaining (Salesforce). The single-file, risk-prioritized report as the artifact people actually share.
  • PMapper (NCC Group). The demonstration that reach through assume-role chains exceeds what policies say directly; version one states that limitation plainly as a debt to PMapper's argument.
  • Cartography (Lyft). Identity relationships as a graph with a common model across sources, the shape later providers join through.
  • ConsoleMe (Netflix). Ownership and request workflows as what turns an inventory into governance.
  • Rhino Security Labs' privilege escalation research (2018). The published catalogue of permission combinations that let a principal raise its own privilege; the escalation heuristics detect the combinations it named.
  • SkyArk (CyberArk). Shadow admin detection: privilege judged by what a policy can do, not what it is called.
  • Prowler and the credential report tradition, the check taxonomy the findings vocabulary builds on.
  • Aardvark (Netflix, archived). The adapter lesson: consume the provider's native successor rather than maintaining a scraper.
  • diagram-design (Cathryn Lavery, MIT). The working sketches follow drawing principles adapted from its editorial doctrine: the complexity budget, restraint with emphasis, and the rule that a diagram is done when nothing can be removed.
  • OWASP, whose lists shaped the design well beyond the one the findings anchor to: the Non-Human Identities Top 10 (2025) supplies the finding identifiers, and the Web Application, API Security, CI/CD Security, Kubernetes, Docker, and LLM Applications lists were each walked item by item against the design, several controls existing because that walk caught their absence.
  • PCI DSS 4.0, ISO/IEC 27002:2022, NIST SP 800-53, CIS Controls v8, and the audit practice around SOX and SOC 2, which together define the periodic, evidenced access review this tool serves; the two-way mapping is in Compliance traceability.
  • Andrew Koenig and the AntiPatterns authors, whose two-part test disciplines how this project writes down what not to do.

The tools deserve the same naming as the ideas. This repository is built, tested, and gated by open source it did not write: the application stands on FastAPI, Uvicorn, SQLAlchemy, Alembic, psycopg, bcrypt, Pydantic, Jinja, python-multipart, and PostgreSQL; the tests on pytest, Hypothesis, HTTPX, Ruff, mypy, and pip-audit; the gates on pre-commit, TruffleHog, Vale, actionlint, zizmor, lychee, OpenSSF Scorecard, CodeQL, hadolint, Trivy, GuardDog (DataDog), and ClusterFuzzLite with atheris (Google); and the local platform on Docker, Kubernetes, kind, Calico, kubeconform, and kube-linter. Each carries maintainers whose work this project consumes at no cost; two of these tools found real defects here before any human did.

Nothing here claims novelty for its parts. The parts are assembled from the projects above, the standards named, and lessons from earlier builds; what this project adds is the combination, the governance loop as open source, and the record of how it was built.