Reading the identity graph
CIEM writes identity relationships into Onam's security graph, so "who can reach this role?" becomes a graph question.
Edges CIEM writes
| Edge | From → to | Cloud |
|---|---|---|
| has-policy | User or role → managed policy | AWS |
| member-of | User → group | AWS |
| assumes | Trusted principal → role (marked when it crosses accounts) | AWS |
| can-access | Identity → a specific resource named in its policy | AWS |
| runs-as | Compute instance → service account; pod → Kubernetes service account | GCP, Kubernetes |
| uses-identity | Virtual machine → managed identity | Azure |
On Kubernetes, workload-identity annotations (EKS IRSA, GKE Workload Identity, AKS Workload Identity) link a service account to the cloud identity it maps to.
Where you read it
There is no separate identity-graph screen. The graph shows up in four places:
- Effective Access panel (IAM Security screen) — one identity's resolved access, with where each grant was inherited from.
- Escalation findings (CIEM screen) — the assume-role chain behind an escalation via assume-role chain finding is a path through the assumes edges; the finding names the start and the admin role it reaches.
- Blast radius (CIEM Identities table) — the number of resources with open high or critical findings that an identity can reach within a few hops of assumes and has-policy edges.
- Attack Path — identity edges join network and data edges, so a path can run from an internet-exposed workload through the identity it runs as to the data that identity can read.
Reading an escalation chain
For an assume-role chain finding, read it left to right:
- Start identity — the identity that holds the first trust relationship.
- Hops — each role it can assume in turn. Service, wildcard and federated principals are not followed as hops; they are reported as trust findings instead.
- End — a role holding an admin policy or admin-equivalent actions.
To break the chain, remove the cheapest hop: usually the trust relationship on an intermediate role, or an unused sts:AssumeRole grant on the start identity.