Every external identity currently able to authenticate as this actor. This is the
answer to "which workloads can act as this principal", which is the question an
incident asks first.
The canonical issuer URL is reported beside the issuer id, because the id alone forces the reader to resolve it against a registry that may since have changed.
An actor with no bindings answers an empty array. That is a complete answer, not a missing one: an actor may authenticate through a credential this feature knows nothing about.
The ROOT tenant is a valid target for this READ, unlike on the write. A read creates no row and emits no audit, so the ROOT-target refusal has nothing to protect.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||