IAM roles, policies, trust relationships, AssumeRole chains, Identity Center, federated principals.
Every system Identrail watches today.
Service accounts, role/clusterrole bindings, pod-to-SA mapping, workload identity federation (EKS/GKE).
GitHub Actions OIDC stitching, environment trust policies, repo-level permission graphs.
Generic OIDC issuer ingestion. JWT claim resolution into target trust policies.
Plan-time analysis: identifies trust-policy diffs against the live graph before apply.
Image registry credentials, build-time identity resolution, Docker Hub OIDC.
Resource-side reachability: catalogs tables/schemas reachable through resolved identity paths.
Emits scan timing, finding counts, severity distribution, and connector health metrics.
Service accounts, workload identity federation, organisation policy resolution. Tracking issue in repo.
Managed identities, federated credentials, role assignments, conditional access for service principals.
AWS auth backend mapping, Kubernetes auth backend mapping, dynamic credential issuance into the graph.