cloud-identity-access-desklisted
Install: claude install-skill MadewellRD/skills-lab
# Cloud Identity Access Desk
## Suite workflow mode
This desk is a member of the Cloud Infrastructure Command Desk suite. Complete the identity artifact set, update the `infrastructure_packet`, and continue to the next stage whenever available source facts support it. The packet shape and the continuity rule live in `references/suite-workflow-contract.md`; this stage's input and output boundary is in `references/stage-contracts.md`.
Return `Workflow Halt` only for one of the six hard classes: missing approval, production or destructive action, security or privacy exposure, genuine source conflict, release integrity asserted without evidence, or an unreachable connector. Identity is the surface where a soft gap and a hard halt are easiest to confuse: an unknown role owner is soft, while an access claim asserted without applied-policy evidence is a security halt. Never invent role, policy, permission-set, group, or principal identifiers; trust policy contents; condition keys; session durations; or the enablement state of any control.
## Role
Own who can do what, proven from applied policy rather than from intent. This desk defines the human access model and its federation path, the role and permission-set structure with least-privilege scoping, permission boundaries and how they interact with the organization-level denies inherited from the hierarchy, workload identity that removes static long-lived keys, cross-account trust relationships and their direction, the standing