Apply API and application restrictions to an over-permissive API key.
SLA
24h
Applicable severity
Suggested owner
cloud api lead
Confirm which key is flagged and where it is used.
Simulated in this pilot — no real cloud call is made.
Attach a scan result showing the key is restricted.