Join our Newsletter — 33% off our NHI Course

Access path queries: are your reviews keeping up with inherited access?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Opal Security says access path queries now trace every person's and agent's access back to its source, including inherited access through nested groups, so teams can move straight from a query result into a campaign or audit binder. The underlying problem is that access graphs have outgrown manual tracing, and agent access makes that governance gap harder to ignore.

Editorial analysis by NHI Mgmt Group, based on content published by Opal Security: “Introducing Access Path Queries: Trace every person's and agent's access to its source”.

Key questions

Q: What breaks when access reviews ignore inherited paths?

A: Reviews lose the ability to explain why access exists, which means inherited privilege, nested groups, and hidden upstream grants can slip past governance.

Q: Why do path-based access queries matter for SoD controls?

A: They let teams test conflicting access conditions against the real authority chain instead of a flat entitlement list.

Q: How can security teams prove how a user or agent reached a sensitive system?

A: By preserving the full source-to-asset chain, including nested groups, inherited roles, and any intermediary entitlements that contributed to effective access.

Practitioner guidance

  • Define path-based review scopes Scope access reviews to principal-to-asset paths instead of whole groups or entire applications, so reviewers assess only the reach that matters.
  • Preserve access lineage in audit evidence Export the full chain behind each effective permission, including nested groups and inherited edges, so auditors can see why access exists.
  • Apply the same query standard to agents Treat AI agents and service accounts as first-class principals in access queries, and trace any excess reach back to the upstream grant or group.

Bottom line: Access governance fails when teams can see only the endpoint permission and not the chain that produced it.

What's in the full announcement

Opal Security's full post covers the operational detail this post intentionally leaves for the source:

  • How access path queries are constructed in OpalQuery using principal and asset filters
  • How natural language input is translated into access graph queries and then validated against the underlying filters
  • How access campaigns are expected to consume query results once that workflow is available
  • How Risk Center findings map into the same query-driven access review workflow

👉 Read Opal Security's introduction to access path queries and graph-based access review →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Access path visibility is now a governance requirement, not a reporting enhancement. Flat entitlement views are no longer enough when effective access is assembled through multiple inheritance layers. The practical consequence is that identity teams must treat path lineage as first-class evidence for reviews, audits, and investigations.

A question worth separating out:

Q: Should organisations govern agents and humans with the same access lineage rules?

A: Yes, because the governance problem is the path to reach, not the biology of the principal. If an agent, service account, or employee can reach a sensitive asset, teams need the same lineage evidence and the same review logic to decide whether that access is justified.

👉 Read our full editorial: Access path queries expose how agents inherit reach through graphs



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.