arXiv · 2504.14777
Intent-Aware Authorization for Zero Trust CI/CD
Abstract
This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as OPA and Cedar evaluate runtime context, justification, and human approvals before issuing access credentials. The system builds on SPIFFE-based workload identity and credential brokers, and enables fine-grained, auditable authorization. This is the third paper in a series on Zero Trust CI/CD design patterns.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Surya Teja Avirneni. 2025-04-21. Intent-Aware Authorization for Zero Trust CI/CD. https://arxiv.org/abs/2504.14777
Cite the original work for its findings. Save a collection to share your selection of sources.