> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/gcp-identities/principals.md).

# Principals

The **Principals** page provides a list of enumerated Principals in GCP. A Principal represents an identity (or set of identities) that can be granted IAM roles, such as a federated user, service account, or a principal set matched via a workforce/workload identity pool.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-9073af455a6463ebb96b9cff7b60f77a07e420a8%2FGCPPrincipalListPage.png?alt=media" alt=""><figcaption><p>Principals</p></figcaption></figure>

### Principals Details

The Details page includes the **`Details`** tab, and a **`Graph »`** button for enhanced navigation and analysis.

{% hint style="info" %}
You can analyze objects in the `Graph module` by clicking the **`Graph »`** button on the upper right side.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-85a9621bc9f1608e8ba03964b09593cc4b509013%2FGCPPrincipalDetailPage.png?alt=media" alt=""><figcaption><p>GCP Principal Details</p></figcaption></figure>

The Details tab contains attributes about the Principal. The page also includes an **Issues** panel that lists any security findings related to the principal, along with a Risk score and Exposure Point.

### Information

| Attribute      | Description                                                                                                                                     |
| -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| Parent Pool    | The workforce or workload identity pool this principal belongs to (e.g., `workforce-pool-test-2`).                                              |
| Principal Type | The classification of the principal (e.g., `principalSet`).                                                                                     |
| Subject        | The fully-qualified subject identifier of the principal (e.g., `//iam.googleapis.com/locations/global/workforcePools/workforce-pool-test-2/*`). |

#### **Issues**

Lists security findings associated with the principal (e.g., *Role Assigned to Entire Federated Identity Pool*), each tagged with relevant categories such as Least Privilege or Privilege Escalation, and a severity rating (e.g., High).
