Cloudflare API token creation and scope management
Looks up permission group ids by name and mints or rescopes an account API token from them; builds least-privilege tokens without hardcoding UUIDs.
Looks up permission group ids by name and mints or rescopes an account API token from them; builds least-privilege tokens without hardcoding UUIDs.
Lists the principals assigned to a Databricks workspace with their permission level, resolving users, groups and service principals into one view.
Lists IAM service accounts in one project with email, display name and unique id; the workload principal inventory for a privilege audit.
Lists a user's access keys with their age in days; keys older than the rotation window are the finding.
Inventories the SAML and OIDC identity providers registered in the account; the trusted federation surface behind assumable roles.
Lists IAM roles whose trust policy admits principals from other AWS accounts, flagging external id and federation use; the cross-account exposure surface.
Enumerates IAM users in the account; IAM is global and always served from us-east-1, so the query takes no parameters.
Lists IAM users alongside whether they have a virtual MFA device registered; console-capable users without MFA are the finding.