OpenSourceOM identity blast radius
Starting from one identity, which nodes can you reach by following CAN_ACCESS and
ASSUMES? The walk is capped at depth 6. Other edge types are not followed.
How teams use blast radius on IAM is in
Blast radius analysis for cloud IAM.
./om identity blast-radius --name AdminRole
./om identity blast-radius --id 'aws:123456789012:global:identity:AdminRole' --json
Provide --id or --name. A name lookup uses
FindIdentityByName, which returns the identity node with that name. If two clouds
reuse a display name, pass the node id.
API
GET /v1/identity/blast-radius?name=AdminRole
GET /v1/identity/blast-radius?identity_id=aws:123456789012:global:identity:AdminRole The JSON body:
{
"identity": { "id": "...", "type": "Identity", "name": "AdminRole" },
"reachable": [],
"edge_count": 0,
"max_depth": 6,
"summary": "..."
} reachable is the set of nodes discovered, not a single path. The console loads
this when you select an identity in the graph explorer.
What the walk includes
The walk is outgoing only. It does not follow an edge backward to its source. Depth starts
at 1 on the identity’s direct targets and stops before the next hop once depth reaches 6.
At most 200 distinct nodes are returned, ordered by type then name. The identity itself is
not listed in reachable. edge_count is present in the JSON and is
not filled by this version.
On AWS, Azure, and GCP, ASSUMES points from the workload to the identity, and
CAN_ACCESS points from the identity to a datastore. Starting at the identity
therefore reaches datastores the collector linked, and does not walk backward to the
workload. Starting at a Kubernetes service account follows ASSUMES toward the
pods that reference it, because that collector stores the service account as the source.
Azure links come from role-assignment scope. GCP links come from project and bucket IAM. Conditional assignments and bindings are omitted. Blast radius repeats those edges. It is not a cloud IAM policy simulator.
Questions
What does OpenSourceOM count as an identity’s blast radius?
The nodes reached by walking outgoing CAN_ACCESS and ASSUMES edges from that identity, up to depth 6. Other edge types are skipped.
How do I check blast radius for a role?
Run om identity blast-radius --name RoleName, or select the identity in the web console. Pass --id when two identities share a display name.
Related reading
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.