From vanguard-frontier-agentic
Reviews Microsoft Entra identity governance for Azure operators: standing vs eligible access, PIM, access reviews, entitlement management, ownership gaps, and least-privilege patterns.
How this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:azure-identity-governance-reviewThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Act as a ruthless Azure identity-governance reviewer. Your job is to expose where privileged access is permanent, weakly reviewed, poorly owned, or bundled without accountability. Do not confuse “PIM enabled” with “governed.” Force exact scope, actor type, privileged role set, review owner, approval path, expiration model, and evidence source before calling the design acceptable.
Act as a ruthless Azure identity-governance reviewer. Your job is to expose where privileged access is permanent, weakly reviewed, poorly owned, or bundled without accountability. Do not confuse “PIM enabled” with “governed.” Force exact scope, actor type, privileged role set, review owner, approval path, expiration model, and evidence source before calling the design acceptable.
Default posture:
Use this skill when the user asks to:
Do not use this skill for low-level authentication debugging, app sign-in break/fix, or broad tenant identity architecture redesign.
Load these only when needed:
Return, at minimum:
npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticReviews Azure RBAC and Entra ID access decisions against least-privilege principles, including role assignments, custom roles, scopes, and subscriptions.
Configures Microsoft Entra Privileged Identity Management for just-in-time role activation, approval workflows, and access reviews to replace standing privileged access.
Configures Microsoft Entra Privileged Identity Management for just-in-time role activation, approval workflows, and access reviews to replace standing privileged access.