Capstone: an authorization decision that holds

P56.cloud-iam.02 · Audience: guest, it-ml, language-pro · Prerequisites: AuthZ models: RBAC, ABAC, ReBAC, Policy evaluation & least privilege

Real LLM grading for this pageLLM grading (this page):

Every request a production system accepts runs one gauntlet before anything else happens: is this caller allowed to do this, to this resource, right now? This capstone closes the P54–P56 Authentication & Identity arc by having you build that gauntlet whole — an RBAC role gate, a policy evaluation with explicit-deny precedence and wildcards, and a least-privilege guard, composed into a single decision. The hidden suite plays the attacker — privilege escalation, a missing-deny bypass, a wildcard over-reach, and an over-provisioned unused permission — and every attempt must come back denied.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Capstone — compose RBAC + policy + least privilege

Loading exercise…

My notes on this module

Loading your notes...

Where next?

Capstone: an authorization decision that holds — TransformerLab