From 6d94f5a891be1eb642eee42d6d598526a997cda7 Mon Sep 17 00:00:00 2001 From: rivassec Date: Sat, 10 Oct 2026 07:36:01 -0700 Subject: [PATCH] IAM Blast Radius post: rephrase the closing "not X, it promises Y" line The conclusion used the antithesis construct the paradigm-shift check and the blog-review job flag as an LLM tell. Same meaning, stated directly; matches the wording already used in the LinkedIn post. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01JoTNmbmc8o4TJDUGG2gd3P --- content/iam-blast-radius-github-action.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/content/iam-blast-radius-github-action.md b/content/iam-blast-radius-github-action.md index 5b374d36..9f6a9dc0 100644 --- a/content/iam-blast-radius-github-action.md +++ b/content/iam-blast-radius-github-action.md @@ -1,6 +1,6 @@ Title: IAM Blast Radius in CI: Designing a Gate That Fails Closed Date: 2026-10-09 -Modified: 2026-10-09 +Modified: 2026-10-10 Author: Oliver Rivas Category: DevSecOps Tags: aws, iam, github-actions, ci-cd, devsecops, cloud-security @@ -133,7 +133,7 @@ Turning on a blocking check across an estate on day one is how security tooling This does not replace the architecture work. As I argued in [IAM Blast Radius Is an Architecture Problem, Not a Policy Problem](iam-blast-radius-architecture-problem.html), most of the risk is decided before anyone opens a JSON file: account boundaries, trust relationships, which pipeline can reach production. A policy gate cannot fix a flat account structure. -What it can do is hold the line on drift, in the place where drift happens. It does not promise that every passing policy is safe, and it cannot guarantee that every risky change is detected. It promises something narrower and more useful: an enforceable, auditable check that names potential permission risk during review, and refuses to approve what it could not analyze. +What it can do is hold the line on drift, in the place where drift happens. The promise is deliberately narrow: an enforceable, auditable check that names potential permission risk during review, and refuses to approve what it could not analyze. It does not certify that a passing policy is safe, or that every risky change gets caught. ## Try it