Grantmesh
Resolve Kubernetes RBAC subjects, bindings, roles, wildcards, and namespace scope into an offline effective-access review.
Focused field tools
Apply subjects checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply role rules checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply bindings checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply wildcards checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply escalation checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply impersonation checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Grantmesh evaluates imported RBAC declarations and recorded assumptions. It does not query a cluster or reproduce admission, aggregated roles, impersonation, webhook authorization, or every version-specific behavior. Verify important findings with the authoritative cluster.