Follow one dangerous mutation.

A deployment role gains one permission. The important question is what that permission makes reachable.

Observe the difference.

In the synthetic demonstration, a GitHub Actions role starts with deployment permissions. A later normalized IAM observation includes iam:CreatePolicyVersion. blakDNA compares the old and new state, preserves evidence, and records a mutation.

Deterministic analysis connects repository trust, the deployment role, policy modification, and the production account. Hermes receives the scoped context and relevant memory for a hypothesis-driven investigation, including an attempt to disprove the conclusion.

Explain the reachable path.

The demonstrated path runs from a compromised repository through Actions and the AWS deployment role to IAM policy modification and production privilege escalation. The conclusion depends on actual policy scope and effective controls; the permission name alone is not universal proof of exploitability.

A canonical event explains the mutation, path, observed risk change, confidence, evidence, owner, and recommendation. Slack, Teams, email, webhook, API, inbox, and CLI preserve the same meaning. Safe retries and delivery receipts do not create new findings.

Verify, then learn.

A human records why the permission should be removed. The risk stays active until a subsequent authoritative observation removes the permission and attack-path recalculation confirms the path is gone. The verified outcome and human explanation become immune memory.

A learned CI/CD antibody can match later changes in shadow mode. Owner approval reruns supported positive and negative historical cases before activating compiled detection. A future recurrence is recognised without granting permission to modify production controls.