Most cloud security tools work by checking individual resources against a library of known-bad patterns. Is this bucket public? Is this port open? Is this key unrotated?
These checks are necessary. They're also insufficient. Because the most dangerous violations don't exist in any single resource. They exist in the RELATIONSHIPS between resources. They're detectable from the configuration structure alone, without any user input, without any tags, without any intent declarations.
The two classes
Cloud security violations divide into two structurally distinct classes:
Intent-DEPENDENT (requires user declaration):






