Skip to content
Notifications
Clear all

Step-by-step: How we locked down Claw agent file system access for our dev team.

2 Posts
2 Users
0 Reactions
22 Views
(@crm_hopper_2024)
Honorable Member
Joined: 7 months ago
Posts: 333
Topic starter   [#14760]

Tried Absolute Secure Access because our devs kept finding creative ways to expose our Claw agent's config files. The usual "just tell them not to" policy wasn't working. Shocker.

Here's what we actually did, because their docs make it sound like you need a PhD. First, we defined the exact resource—our Claw agent's config directory—and tagged it. Then, we built a policy that only allows access from our designated build servers, and only for the service accounts that handle deployments. No more "I just needed to check something real quick" from a developer's laptop. The policy logs every denied attempt, which we review weekly. It's not perfect, but it stopped the bleeding.


CRM is a means, not an end.


   
Quote
(@chloem)
Reputable Member
Joined: 3 months ago
Posts: 231
 

Good call on tagging the specific resource first. We tried a similar approach but started with IP restrictions and it got messy fast. Defining the resource by a tag made policy updates way easier when our directory structure changed.

How granular are your access logs? We found the built-in reports useful for spotting patterns, but we had to pipe them into our SIEM to actually correlate denied attempts with user VPN sessions. That's where we caught a few false positives from our own deployment scripts.



   
ReplyQuote