Skip to content

entitlement-problems: three access designs that leak a privilege through composition - #4

Merged
1 commit merged into
mainfrom
entitlement-problems
Oct 3, 2026
Merged

1 commit merged into
mainfrom
entitlement-problems

Conversation

@sajonaro

@sajonaro sajonaro commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Adds entitlement-problems/: three access-control designs, each a safe model and a shortcut asked the same .claims. This is the IAM prototype the recommendations ask for first.

problem the shortcut's mistake what writ reports
separation-of-duties/ grants checked against a table of group names; the conflict lives in a role 2 grants: alice-joins-requesters, alice-also-joins-finance-leads; a = alice; derive conflict gives the two groups
scp-escalation/ prod moved into an OU built from the sandbox SCP template compare: dev-can-deploy preserved, dev-never-edits-cloudtrail LOST, sec-can-always-audit LOST; derive escalation gives dev power prod-acct workloads
joiner-mover-leaver/ offboarding removes group membership only a leaver keeps prod-admin (assigned directly) after 4 steps, and nothing left in the plan can remove it

Each failing property names a (show …) query, so the verdict says who is affected. Each .rules file prints the privilege path as a table.

While I was writing joiner-mover-leaver, writ found a bug in the first draft of the safe plan: approve → leave → provision. The README for that problem tells the story, and both files carry the fix.

Notes

  • compare reports properties LOST for all three pairs. The plan assumed otherwise. It also reports a violated equation as preserved, because laws are compared by declaration; entitlement-problems/README.md says so.
  • The cross-check goes from 31 to 41 properties (never 3 → 7). It only runs the safe models. I ran derive against each shortcut by hand and the counts matched writ check, but no test asserts that.
  • ./run-tests.sh all: 257 checks, 0 failed (222 before). The new tests and the cross-check also come out green in Docker (writ:latest, built from the v0.3.0 tag commit).

🤖 Generated with Claude Code

…ugh composition

separation-of-duties: a toxic-combination table checked by group name, and a
role added later that approves; two grants, neither listed, make a conflict.
scp-escalation: moving prod into an OU built from the sandbox template; compare
reports the CloudTrail guardrail and the security team's audit read LOST.
joiner-mover-leaver: group-based offboarding and the direct permission set it
cannot see; a trap, not a delay. Writing it, writ found a second bug in the
first draft of the safe plan (approve, leave, provision) and the README keeps it.

Each failing property names a (show …) query, and each .rules file prints the
privilege path. Cross-check 31 -> 41 properties (never: 3 -> 7); 257 checks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sajonaro sajonaro closed this pull request by merging all changes into main in c716317 Oct 3, 2026
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
@sajonaro
sajonaro deleted the entitlement-problems branch October 3, 2026 17:52
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant