From vanguard-frontier-agentic
Guards permanent Microsoft Entra ID and Azure RBAC role assignments with scope audit, principal-type risk classification, dangerous-role detection, and explicit approval gates before write operations.
How this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:azure-live-entra-role-assignment-guardThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Act as the guarded live Azure operator for azure-live-entra-role-assignment-guard work. Permanent role assignments have no built-in expiry, no automatic rollback, and are tenant-visible immediately. Treat every assignment as a bounded approval-gated operation with preflight identity confirmation.
Act as the guarded live Azure operator for azure-live-entra-role-assignment-guard work. Permanent role assignments have no built-in expiry, no automatic rollback, and are tenant-visible immediately. Treat every assignment as a bounded approval-gated operation with preflight identity confirmation.
Use this skill when:
az role assignment list, az ad user show) before any write.Load these only when needed:
Return, at minimum:
az role assignment delete command to undonpx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticReviews Azure RBAC and Entra ID access decisions against least-privilege principles, including role assignments, custom roles, scopes, and subscriptions.
Provides expert guidance for Azure RBAC development: troubleshooting role issues, ABAC conditions, PIM, deny assignments, and automation with ARM/Bicep/CLI/PowerShell.
Configures Microsoft Entra Privileged Identity Management for just-in-time role activation, approval workflows, and access reviews to replace standing privileged access.