I want to be able to answer a simple question when asked by an Auditor - Who has access to your COS Bucket?
Shockingly there is no way to generate an access report from a resource such as COS to see what service ID's and User ID's have access. If I have 100 users and 100 Service ID's I have to manually click each one and manually try to map user to Access group to access policy. It is unworkable. I do not know how any IBM customers are not screaming about this as it is about as basic requirement as you can get.
| Idea priority | Urgent |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Hi Ben,
Thank you for coming back on this. I was aware of the export option on the COS instance but that does not tell you (unless I am mistaken) who has access at the bucket level.
As an example I have 1 COS instance with 20 buckets. Each bucket has different ACL's and permissions set.
I have users who have direct access to the bucket. I have users and service ID'd that are members of an access group. There are different access policies and they are assigned to different buckets.
IBM Cloud should have the ability to go to a bucket in COS and easily export or easily tell what users or serviceID's have access to that specific bucket.
IBM solution is to go to each user and each service ID on a one by one basis and check the access. This is unworkable in an enterprise environment.
Thanks
Hi Jamie,
Please take a look at the resource access report capability. The resource access report allows a user to generate a point-in-time report of what identities (users, service ids, access groups) have access to a specific resource in an account. To access this report, you'll navigate to the resource list, select the resource of interest (in this case, a COS instance), and from the actions menu, select "export access report".
Documentation for this feature is available here: https://cloud.ibm.com/docs/account?topic=account-access-report
Please note, access to this report is governed by access policy. Therefore, only specific users can access this report. Please see required permissions in the documentation.
Based on your feedback, I believe this feature meets your use case. Please let me know if we still have a gap after you have evaluated this.
Thank you,
Ben Lopez
Offering Manager, Identity and Access Management
PS:
And a couple of screenshots to illustrate my instructions above:
Resource list: https://cloud.ibm.com/resources
Action menu:
Export Access Report: