Credential context graph
Trace one credential through its evidence.
Start with a detected key. Its graph links the locations where it appeared, who authored those source records, the current owner status, and any available permission or incident context. Each link answers a different question.
An editorial map of graph edge types, not a product screenshot or a claim that every link exists for every key.
CENTRAL RECORD
Masked credential
A verification result appears when the credential type supports it.
- FOUND_IN
Detected location
A connected source record where the credential was found.
- AUTHORED_BY
Source author
The person or account recorded on a location; not necessarily today’s owner.
- OWNED_BY
Owner status
A suggested candidate or an explicit assignment; check which one you have.
- CAN_ACCESS
Permission context
Available principal or API-target data from supported analysis, when present.
- RELATED_INCIDENT
Linked response
An incident connected to the credential, if one exists.
Read the links before making a decision
The graph groups clues for an investigation. It does not replace issuer records or a confirmed service owner.
- Where was the credential found?
- Open the connected source location and note its visibility and observation time. A source author describes that record; it may not identify who runs the dependent service.
- Who is responsible now?
- Distinguish an inferred owner from a person explicitly assigned to the credential. If the record is unassigned or points to an inactive account, confirm the current responder.
- What access is supported by evidence?
- For AWS access keys and GCP API keys, inspect available permission analysis with the required integration. Resource nodes may describe a principal or an API target; issuer logs are needed to establish actual use.
- What happens after review?
- If a sensitive key is clearly exposed, contain it at the issuer without waiting for a complete graph. Assign the response, update dependent services, record the action and recheck supported validity results.
What the graph does not prove
A relationship view is bounded by its underlying findings and analysis.
- The graph includes connected-source findings. A missing location does not prove that a credential was never copied elsewhere.
- The owner link may be a source-derived candidate, not a confirmed operator. A vault node can also represent no match, not proof of storage.
- Permission context is available only where supported analysis and integration data exist. It does not by itself prove that a key accessed a resource or that an application depends on it.
- Large graphs are bounded and may be marked truncated. Use the source and issuer records for a fuller investigation; Cremit does not rotate or revoke keys at their issuers.