Start with the resource and work backwards
Choose a critical resource and identify every human, external and workload identity that can reach it. Then trace the device, authentication, Conditional Access, PIM, application permission and logging dependencies for each route.
Record threat, control, evidence and failure
A useful trust-path review does not stop at the intended design. For every step, it records the threat, expected control, validation evidence, owner and failure scenario.
- standing administrative privilege
- policy exclusions and emergency access
- service principals and application permissions
- guest and partner access
- missing or unreviewed security evidence
Turn architecture into remediation
The output should help a CTO or CISO decide what to fix first, who owns it and which evidence will demonstrate improvement. A diagram without a risk-ranked action plan is documentation, not an assessment result.
Primary sources
These links support the external market signal. The recommendations above are Enki Tech's practical interpretation for cloud decision-makers.
