Independent research for the cloud control plane.
Research report · Identity & access
The permission path you didn’t review
Cross-account trust rarely fails at the obvious policy. The risk lives in the path between identities, conditions, and inherited access.
Horizontal bars show direct policies at 91 percent, trust conditions at 78 percent, inherited paths at 44 percent, and session context at 31 percent.
| Domain | Controls observed |
|---|---|
| Direct policies | 91% |
| Trust conditions | 78% |
| Inherited paths | 44% |
| Session context | 31% |
The illustrative review sees most direct policies but less than half of inherited paths and session context.
- 01Research reportIdentity & accessThe permission path you didn’t review
- 02Visual briefDetection & responseCloud logs that never reach the SIEM
- 03Technical guideIdentity & accessWhat changes when static keys disappear
- 04Field noteDetection & responseFive Kubernetes events your cloud trail will not explain
- 05Research noteAI systemsThreat-model the system around the model
Signals / Illustrative
What the desk is watching
Compact observations from the demonstration research set. These figures show the publication format, not measured industry benchmarks.
Research index
Follow a control boundary
Trust is a path, not a policy.
A detection is only as complete as its evidence path.
Runtime context decides whether a control matters.
AI risk begins before the model endpoint.
Recovery starts with an independent control path.
Visual brief
Cloud logs that never reach the SIEM
A dashboard can be healthy while the evidence behind it is incomplete. Coverage needs to be tested from event creation to searchable record.
Open the complete briefIllustrative event delivery by stage
The synthetic dataset loses 18 percentage points between event creation and searchable evidence.
Bars decline from 100 percent generated to 97 percent routed, 91 percent transformed, and 82 percent searchable.
Chart loads as it approaches the viewport.
View accessible data table
| Category | Events retained |
|---|---|
| Generated | 100% |
| Routed | 97% |
| Transformed | 91% |
| Searchable | 82% |
Source Cloud Security Desk demonstration dataset
Method Fictional rates for 1,000 generated canary events. The figures illustrate an assurance method and are not provider benchmarks.
Download source data (CSV) ↓How we work
Evidence before assurance.
Every figure names its source, method, accessible description, and downloadable data status. Demonstration material is labeled at the claim, not buried in a disclaimer.
Read our methodologyFollow the evidence, not an inbox.
New research, technical guides, visual briefs, and corrections through an open RSS feed. No tracking form and no email collection.
Follow via RSS