Onam Security

Reading the identity graph

CIEM writes identity relationships into Onam's security graph, so "who can reach this role?" becomes a graph question.

Edges CIEM writes

EdgeFrom → toCloud
has-policyUser or role → managed policyAWS
member-ofUser → groupAWS
assumesTrusted principal → role (marked when it crosses accounts)AWS
can-accessIdentity → a specific resource named in its policyAWS
runs-asCompute instance → service account; pod → Kubernetes service accountGCP, Kubernetes
uses-identityVirtual machine → managed identityAzure

On Kubernetes, workload-identity annotations (EKS IRSA, GKE Workload Identity, AKS Workload Identity) link a service account to the cloud identity it maps to.

Where you read it

There is no separate identity-graph screen. The graph shows up in four places:

  1. Effective Access panel (IAM Security screen) — one identity's resolved access, with where each grant was inherited from.
  2. Escalation findings (CIEM screen) — the assume-role chain behind an escalation via assume-role chain finding is a path through the assumes edges; the finding names the start and the admin role it reaches.
  3. Blast radius (CIEM Identities table) — the number of resources with open high or critical findings that an identity can reach within a few hops of assumes and has-policy edges.
  4. Attack Path — identity edges join network and data edges, so a path can run from an internet-exposed workload through the identity it runs as to the data that identity can read.

Reading an escalation chain

For an assume-role chain finding, read it left to right:

  • Start identity — the identity that holds the first trust relationship.
  • Hops — each role it can assume in turn. Service, wildcard and federated principals are not followed as hops; they are reported as trust findings instead.
  • End — a role holding an admin policy or admin-equivalent actions.

To break the chain, remove the cheapest hop: usually the trust relationship on an intermediate role, or an unused sts:AssumeRole grant on the start identity.