Just finished a side project that saved our security team a ton of manual work. We use Absolute Secure Access, and I built a simple script to cross-reference our deployed Claw agent permissions against our internal security policy JSON.
It flags any agent config drift in seconds. Found three agents with outdated permission sets that we missed in the last audit! 🚨
Hereβs the core part that does the comparison:
```python
def check_policy_compliance(agent_perms, policy_file):
with open(policy_file) as f:
baseline = json.load(f)
non_compliant = []
for agent, perms in agent_perms.items():
if not perms.issubset(baseline['allowed_permissions']):
non_compliant.append(agent)
return non_compliant
```
Runs daily via a Lambda, posts findings to a Slack channel. Thinking of open-sourcing it if there's interest. Anyone else automating their Secure Access reviews?
#savings