Safeguard
Tag

iam

Safeguard articles tagged "iam" — guides, analysis, and best practices for software supply chain and application security.

47 articles

Security

AWS Permission Boundary: How to Cap IAM Privileges Safely

An AWS permission boundary sets the maximum permissions an IAM identity can ever have. Here is how boundaries work, when to use them, and the mistakes that quietly defeat them.

May 5, 20265 min read
Security

How to Secure the Public Cloud: A Practical Guide

The public cloud can be secured well, and often more securely than a self-run data center. The catch is the shared responsibility model, where most breaches actually originate.

May 5, 20265 min read
Security

AWS Hack: How Attackers Break Into AWS and How to Stop Them

Most AWS breaches don't start with a clever exploit. They start with a leaked key or a misconfigured bucket. Here is how an AWS hack actually unfolds and how to shut down each step.

May 3, 20266 min read
Application Security

Serverless security implications from infra to OWASP

Serverless shrinks the OS attack surface but expands the IAM and dependency one. Here's how the OWASP Serverless Top 10 maps to real 2021-era incidents.

Apr 27, 20266 min read
Security

Public Cloud Protection: Securing Workloads Across AWS, Azure, and GCP

Public cloud protection starts with the shared responsibility model and ends with the boring controls that stop most breaches: identity, configuration, and visibility.

Apr 20, 20266 min read
Vulnerability Management

AWS Service-Linked Role Abuse Techniques, 2025

Service-linked roles are the soft underbelly of AWS IAM. We catalogue the 2024-2025 abuse primitives and the detection queries that catch them.

Apr 20, 20265 min read
Security

How to Secure Cloud Applications: A Practical Guide

Securing cloud applications means protecting the code, the dependencies, the identities, and the runtime together. Here is a practical way to think about all four.

Apr 7, 20266 min read
Security

AWS DevOps Security Best Practices: A Practical Guide

The AWS DevOps security best practices that matter most are least-privilege IAM, immutable pipelines, and shifting scanning left into CI. Here is how to apply them without slowing delivery.

Apr 5, 20266 min read
Security

Public Cloud Security: A Practical Guide to Protecting Workloads

Public cloud security is a shared responsibility, and most breaches trace back to the customer's half of that split rather than a failure by the cloud provider.

Mar 29, 20266 min read
Best Practices

AWS IAM Roles Anywhere and the Supply Chain

IAM Roles Anywhere lets workloads outside AWS assume IAM roles using X.509 certificates. It is also becoming the authentication layer for supply chain tools. Here is what the threat model looks like.

Mar 14, 20268 min read
Cloud Security

What is IAM (Identity and Access Management)

IAM defines who and what can access your systems, and getting it wrong is a root cause behind breaches at Capital One, Toyota, Uber, and CircleCI.

Mar 13, 20268 min read
Best Practices

AWS Step Functions Workflow Security

Step Functions workflows orchestrate everything from data pipelines to security automations. The workflow IAM role is almost always the most powerful thing in the stack. Here is how to lock it down.

Mar 6, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

iam (Page 3) — Safeguard Blog