Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure

Credential context graph

Trace one credential through its evidence.

Start with a detected key. Its graph links the locations where it appeared, who authored those source records, the current owner status, and any available permission or incident context. Each link answers a different question.

Relationships around one credential

An editorial map of graph edge types, not a product screenshot or a claim that every link exists for every key.

CENTRAL RECORD

Masked credential

A verification result appears when the credential type supports it.

FOUND_IN

Detected location

A connected source record where the credential was found.

AUTHORED_BY

Source author

The person or account recorded on a location; not necessarily today’s owner.

OWNED_BY

Owner status

A suggested candidate or an explicit assignment; check which one you have.

CAN_ACCESS

Permission context

Available principal or API-target data from supported analysis, when present.

RELATED_INCIDENT

Linked response

An incident connected to the credential, if one exists.

Read the links before making a decision

The graph groups clues for an investigation. It does not replace issuer records or a confirmed service owner.

Where was the credential found?
Open the connected source location and note its visibility and observation time. A source author describes that record; it may not identify who runs the dependent service.
Who is responsible now?
Distinguish an inferred owner from a person explicitly assigned to the credential. If the record is unassigned or points to an inactive account, confirm the current responder.
What access is supported by evidence?
For AWS access keys and GCP API keys, inspect available permission analysis with the required integration. Resource nodes may describe a principal or an API target; issuer logs are needed to establish actual use.
What happens after review?
If a sensitive key is clearly exposed, contain it at the issuer without waiting for a complete graph. Assign the response, update dependent services, record the action and recheck supported validity results.

What the graph does not prove

A relationship view is bounded by its underlying findings and analysis.

  • The graph includes connected-source findings. A missing location does not prove that a credential was never copied elsewhere.
  • The owner link may be a source-derived candidate, not a confirmed operator. A vault node can also represent no match, not proof of storage.
  • Permission context is available only where supported analysis and integration data exist. It does not by itself prove that a key accessed a resource or that an application depends on it.
  • Large graphs are bounded and may be marked truncated. Use the source and issuer records for a fuller investigation; Cremit does not rotate or revoke keys at their issuers.