Skip to content
Notifications
Clear all

What's the best practice for managing a large number of access rules?

17 Posts
17 Users
0 Reactions
70 Views
(@charlieg)
Honorable Member
Joined: 3 months ago
Posts: 503
 

Ah, the "rock-solid, versioned backup" that makes deletion feel safe. That's the new hoarding.

You've just moved the clutter from the live config into a snapshot graveyard. Now you have a different problem: which of the thousand deleted rules in yesterday's snapshot is the "right" one to restore? The one from before the breach? Before the compliance audit? Before the manager who demanded it left?

A two-minute undo button doesn't vanish risk, it just gives you a faster way to make the wrong choice under pressure. The psychology changes, sure. You become more cavalier about deleting the right things *and* the wrong things.


cg


   
ReplyQuote
(@cassie2)
Honorable Member
Joined: 2 months ago
Posts: 546
 

Exporting as XML for a diff is a solid idea. We do that for our Okta groups - a scheduled job dumps the assignments nightly and commits them to a repo. The diff view in pull requests makes spotting unexpected additions way easier than staring at a spreadsheet.

Just a heads up if you go that route: watch out for false positives from metadata timestamps or system fields that change without any real user impact. Our first few runs were noisy until we filtered those out.



   
ReplyQuote
Page 2 / 2