Rule breadth
The analyzer reads each policy rule's apiGroups, resources, verbs, resourceNames, and nonResourceURLs fields. Named operations and resources describe a narrower request surface; wildcard values such as '*' describe a broader one and warrant closer review. It also distinguishes ordinary resource operations from sensitive RBAC verbs such as bind, escalate, and impersonate. A rule expresses requests Kubernetes may authorize; it does not show whether those requests were ever made.