How untrusted access becomes a finding
Plerion evaluates every grant in the resource access grants inventory. When a resource has one or more grants to anUntrusted external principal, Plerion:
- Sets the Grants external access context on the affected asset.
- Raises a finding against that asset.
Severity
Untrusted external access findings carry a severity level like any other finding, so you can prioritize them alongside the rest of your posture. Plerion rates each finding from the access the grant actually allows:- A grant that allows broad or destructive actions scores higher than one limited to reading.
- Access to a resource holding classified data, or to a role that carries administrative or privilege-escalation rights, raises the score further.
- Conditions that restrict when the grant applies lower it.
Finding untrusted external access
Open the Findings dashboard
Go to the Findings dashboard.
Understanding the finding detail
Select a finding to open its detail view. Alongside the standard finding summary, remediation guidance, and primary asset, the Overview shows an external access graph for the asset. The graph maps each external principal that holds a grant and labels it with its trust status, so you can see at a glance which principals areUntrusted, Trusted, or Unclassified.

Resolving a finding
You have two ways to resolve an untrusted external access finding:- Trust the principal: If the access is expected, add the principal to your trusted principals. The grant is reclassified and the finding clears on the next scan.
- Remove or restrict the access: If the access is not expected, change the resource policy or trust policy in AWS to remove the principal or tighten its conditions.
Related pages
- Resource access grants: The full inventory of grants to principals.
- External access: The grants that reach outside your organization.
- Trusted principals: Confirm expected access so it stops raising findings.
