Score: 0

Intent-Aware Authorization for Zero Trust CI/CD

Published: April 21, 2025 | arXiv ID: 2504.14777v1

By: Surya Teja Avirneni

Potential Business Impact:

Makes computer code safe by checking who and why.

Business Areas:
Identity Management Information Technology, Privacy and Security

This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as OPA and Cedar evaluate runtime context, justification, and human approvals before issuing access credentials. The system builds on SPIFFE-based workload identity and credential brokers, and enables fine-grained, auditable authorization. This is the third paper in a series on Zero Trust CI/CD design patterns.

Page Count
13 pages

Category
Computer Science:
Cryptography and Security