Open Access

Policy-Based Automation for Secure Governance of Machine and Workload Identities in Cloud IAM

4 Department of Informatics, Indonesian Institute of Computing Research, Indonesia
4 Department of Informatics, Indonesian Institute of Computing Research, Indonesia

Abstract

The rapid expansion of cloud-native applications, automated pipelines, microservices, containers, serverless workloads, and machine-to-machine communication has increased the number and operational importance of non-human identities. Unlike conventional human accounts, machine and workload identities may be created, rotated, delegated, and terminated automatically, making their governance difficult to manage through manually administered identity and access management (IAM) processes. This research develops a policy-based automation framework for secure governance of machine and workload identities in cloud IAM. The proposed approach integrates identity lifecycle controls, policy evaluation, contextual authorization, anomaly detection, automated credential governance, continuous compliance assessment, and risk-adaptive enforcement into a unified control model. The methodology conceptually combines policy-based access control with automated decision mechanisms inspired by optimization, machine learning, authentication, and anomaly-detection techniques represented in the supplied literature. Particular attention is given to the governance requirements of non-human identities, including least privilege, identity provenance, credential rotation, workload isolation, policy consistency, and automated revocation. The analysis indicates that policy automation can reduce administrative dependency, improve consistency, accelerate detection and response, and establish measurable governance controls across dynamic cloud environments. However, automation introduces risks associated with erroneous policy decisions, excessive privileges propagated through service dependencies, model-driven false positives, and policy complexity. The study therefore positions automation not as a replacement for governance but as an enforcement mechanism operating within explicit policy boundaries. The resulting framework provides a research-oriented foundation for secure, scalable, and continuously governed machine and workload identities in cloud IAM.

Keywords

References

A. Al-Subhi, ''Dynamic Economic Load Dispatch
Using Linear Programming and Mathematical-based Models'', Mathematical Modelling of Engineering Problems, vol. 9, no. 3, pp. 606–614,
M. Abdel-Basset and L. A. Shawky, ''Flower Pollination Algorithm: A Comprehensive Review'', Artif. Intell. Rev., vol. 52, pp. 2533–2557, 2019.
T. K. Dao et al., ''A Hybridized Flower Pollination Algorithm and Its Application on Microgrid Operations Planning'', Appl. Sci., vol. 12, no. 13,
A. Das et al., ''Fitness Based Weighted Flower
Pollination Algorithm with Mutation Strategies
for Image Enhancement'', Multimed. Tools Appl.,
vol. 81, no. 20, pp. 28955–28986, 2022.
A. Dockhorn and S. Lucas, ''Choosing Representation, Mutation, and Crossover in Genetic Algorithms'', IEEE Comput. Intell. M., vol. 17, no. 4,
pp. 52–53, 2022.
H. El Bourakkadi et al., ''Enhanced Color Image
Encryption Utilizing a Novel Vigenere Method
with Pseudorandom Affine Functions'', Acadlore
Transactions on AI and Machine Learning, vol. 3,
no. 1, pp. 36–56, 2024.
X. He et al., ''Global Convergence Analysis of the
Flower Pollination Algorithm: A Discrete-time
Markov Chain Approach'', Procedia Com. Sci.,
vol. 108, pp. 1354–1363, 2017.
Y. Jia et al., ''A Flower Pollination Optimization
Algorithm Based on Cosine Cross-generation
Differential Evolution'', Sensors-basel, vol. 23,
no. 2, 2023.
H. A. Khan, ''ArraySolver: An Algorithm for
Colour-coded Graphical Display and Wilcoxon
Signed-rank Statistics for Comparing Microarray
Gene Expression Data'', Comp. Funct. Genom.,
vol. 5, no. 1, pp. 39–47, 2004.
Y. Li et al., ''Hyper-tune: Towards Efficient Hyper- parameter Tuning at Scale'', arXiv preprint
arXiv:2201.06834, 2022.
W. Liu et al., ''XGBoost Formation Thickness
Identification Based on Logging Data'', Front.
Earth Sc-switz., vol. 10, 2022.
B. Mahdad and K. Srairi, ''Security Constrained
Optimal Power Flow Solution Using New Adaptive Partitioning Flower Pollination Algorithm'', Appl. Soft Comput., vol. 46, pp. 501–522, 2016.
M. D. K. Y. Shambour et al., ''Modified Global
Flower Pollination Algorithm and Its Application
for Optimization Problems'', Interdiscip. Sci., vol.
, pp. 496–507, 2019.
D. K. Shary and H. J. Nekad, ''Position and Speed
Control for Permanent Magnet DC Motor Based
on Different Optimization Algorithms'', Journal
Européen des Systèmes Automatisés, vol. 57, no.
, pp. 1705–1711, 2024.
Z. Shen et al., ''IncreAuth: Incremental-learning-based Behavioral Biometric Authentication on Smartphones'', IEEE Internet Things, vol. 11, no. 1, pp. 1589–1603, 2023.
W. Xu and Y. Fan, ''Intrusion Detection Systems
Based on Logarithmic Autoencoder and XGBoost'', Secur Commun Netw, vol. 2022, no. 1,
Q. Yang et al., ''A Multimodal Data Set for Evaluating Continuous Authentication Performance in Smartphones'', in Proc. of the 12th ACM Conference on Embedded Network Sensor Systems, pp. 358–359, 2014.
M. Yang et al., ''Achieving Privacy-preserving
Cross-silo Anomaly Detection Using Federated XGBoost'', J. Frankin I., vol. 360, no. 9, pp 6194–6210, 2023.
X. S. Yang, ''Flower Pollination Algorithm for Global Optimization'', in Proc. of the Int. Conference on Unconventional Computing and Natural Computation, Berlin, 2012, pp. 240–249.
G. Ye et al., ''An Effective Framework for Chaotic Image Encryption Based on 3D Logistic Map'',Secur Commun Netw, vol. 2018, no. 1, 2018.
Ganapathy, S. K. (2025). Automated Governance and Protection of Non-Human Identities in Cloud IAM. Frontiers in Emerging Computer Science and Information Technology, 2(02), 08–20. Retrieved from https://irjernet.com/index.php/fecsit/article/view/cloud-iam-non-human-identities

Similar Articles

71-79 of 79

You may also start an advanced similarity search for this article.