A managed service often writes to a bucket, publishes to a topic, or uses an encryption key on behalf of a configured customer resource. Granting the service principal alone can leave a confused-deputy path: another party might configure that service to target your resource. Where supported, constrain the service call by the source resource identifier and source account, and confirm that the service actually sends those context keys for the operation.
Service-principal trust: bind the caller to the intended source
Operational decision
A central audit bucket accepts log delivery from a named trail in a member account. Its resource policy allows the exact delivery action and destination prefix for the logging service, with a source-account condition and a source-resource condition tied to the approved trail. Build the policy in a disposable account and verify that the approved trail can deliver a test event. Then configure a second trail outside the approved source and confirm its delivery is denied. Check the service's documented ARN shape and policy requirements; some services call auxiliary actions before writing, and a condition copied from another service can break legitimate delivery. Review organization-wide policies separately, because a guardrail may deny a call that the bucket policy permits. If the source identifier cannot be specified at creation time, use a narrow transitional condition with a short review deadline, then replace it once the identifier is known. Capture denied request IDs and delivery health. A policy that blocks attackers but silently stops the audit trail defeats the reason it was installed.
Audit delivery resource-policy review
Principal: logging service only
Action: required bucket check and object write only
Destination: dedicated trail prefix
Source account: approved member account
Source resource: named trail identifier
Positive test: approved delivery visible
Negative test: unapproved trail cannot deliverCost and verification
Evaluating N configured source resources requires an inventory of N identifiers and at least a sample of positive and negative delivery tests. A broad principal-only allow is easier to deploy but widens the destination's exposure. Measure denied foreign-source attempts, time since last valid delivery, and policy exceptions awaiting removal. A new source trail needs an intentional policy change; that review cost is part of the security control.
Common Mistakes
- Do not assume a service principal identifies your account's configuration.
- Do not add source conditions without testing the service's actual call path.
- Do not accept stopped audit delivery as a successful security rollout.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Cloud policy decisions: trace every authorization layer
- Log pipelines: preserve incident evidence without ingesting secrets
- Immutable backup retention: protect recovery copies from deletion
- Policy exceptions: make a temporary bypass expire and prove its scope
