Get started

OpenSourceOM identity blast radius

Starting from one identity, which nodes can you reach by following CAN_ACCESS and ASSUMES? The walk is capped at depth 6. Other edge types are not followed. How teams use blast radius on IAM is in Blast radius analysis for cloud IAM.

./om identity blast-radius --name AdminRole
./om identity blast-radius --id 'aws:123456789012:global:identity:AdminRole' --json

Provide --id or --name. A name lookup uses FindIdentityByName, which returns the identity node with that name. If two clouds reuse a display name, pass the node id.

API

GET /v1/identity/blast-radius?name=AdminRole
GET /v1/identity/blast-radius?identity_id=aws:123456789012:global:identity:AdminRole

The JSON body:

{
  "identity": { "id": "...", "type": "Identity", "name": "AdminRole" },
  "reachable": [],
  "edge_count": 0,
  "max_depth": 6,
  "summary": "..."
}

reachable is the set of nodes discovered, not a single path. The console loads this when you select an identity in the graph explorer.

What the walk includes

The walk is outgoing only. It does not follow an edge backward to its source. Depth starts at 1 on the identity’s direct targets and stops before the next hop once depth reaches 6. At most 200 distinct nodes are returned, ordered by type then name. The identity itself is not listed in reachable. edge_count is present in the JSON and is not filled by this version.

On AWS, Azure, and GCP, ASSUMES points from the workload to the identity, and CAN_ACCESS points from the identity to a datastore. Starting at the identity therefore reaches datastores the collector linked, and does not walk backward to the workload. Starting at a Kubernetes service account follows ASSUMES toward the pods that reference it, because that collector stores the service account as the source.

Azure links come from role-assignment scope. GCP links come from project and bucket IAM. Conditional assignments and bindings are omitted. Blast radius repeats those edges. It is not a cloud IAM policy simulator.

Questions

What does OpenSourceOM count as an identity’s blast radius?

The nodes reached by walking outgoing CAN_ACCESS and ASSUMES edges from that identity, up to depth 6. Other edge types are skipped.

How do I check blast radius for a role?

Run om identity blast-radius --name RoleName, or select the identity in the web console. Pass --id when two identities share a display name.

Related reading