Technical Concepts

Resource identity and fingerprinting

How resources are identified for action, and how the same identity is reduced to a fingerprint so a stored snapshot names nothing.

Currentengine 9.0.0Verified 2026-08-30

Two different needs

For action, a resource must be named exactly, so you can open it. For comparison, only identity across two assessments is needed, and a name would be a stored customer identifier.

In the Evidence Register

Full identifiers, unmasked, in the register that is available on request. You own the account and cannot act on a masked identifier. The board pack shortens them instead, because the pack is the document that circulates.

In the snapshot

Fingerprints. Resource identity is carried as a derived value, and the account identifier is fingerprinted too. The snapshot therefore names no resource and no account, which is what makes retaining it for 90 days defensible when the raw evidence expires in one.

What is parsed from an identifier

The region and the service, and whether the control governs the account as a whole. Those feed reach and materiality.

Truncation

A bounded number of identifiers is tracked per control, and the register states explicitly whether the list is complete.

What it does not mean

A fingerprint is not reversible into a resource name, and the snapshot is never delivered to anyone.